staff macOS security researcher @jamfsoftware views are my own

Toronto
Ferdous Saljooki retweeted
Jamf Threat Labs uncovered a macOS campaign using a fake Zoom installer to deliver Overlord RAT. The downloader (ZoomMeetings) is a self-contained .NET 10 Mach-O binary, unusual for macOS malware. Because .NET is cross-platform, the same codebase also targets Windows. jamf.com/blog/fake-zoom-inst… #malware #macOS #reverseengineering #RAT
9
34
3,396
Ferdous Saljooki retweeted
Join us at DEF CON where we'll talk about how mac malware could bypass entitlements and encryption to dump all the icloud passkeys, passwords, +more on a mac, no privileges required (CVE-2026-28860) "Grabbing the Keys to the iCloud Kingdom" co-presented with @jbradley89
2
15
67
6,802
Ferdous Saljooki retweeted
ClickFix techniques are evolving. Instead of copy and paste instructions to Terminal, newer variants are using Script Editor to execute payloads on macOS. Read more about this delivery technique in our latest blog post. jamf.com/blog/clickfix-macos… #clickfix #malware #threathunting
1
14
44
20,881
Ferdous Saljooki retweeted
Apple (copied BlockBlock 👀) and added ClickFix protections… but kept the good stuff private 😤 Reversed xprotectd to see how it really works and emerged with enough detail to build your own (kinda)! Read: No Paste for You! objective-see.org/blog/blog_…
7
33
207
20,620
Apple added another layer of ClickFix paste protection in macOS Tahoe that went mostly unnoticed. This one runs inside the XProtect daemon, scans what you actually paste, and checks domains against Safari's Safe Browsing Service in real time. Here's how it works 🧵
6
35
285
25,357
xprotectd also monitors command execution. If a flagged domain is obfuscated in the paste to bypass the content check, xprotectd catches it at execution time when the command resolves and shows a separate prompt: "Malicious Script Blocked" with only a "Done" button. The process is killed. This only triggers when the content was originally pasted from one of the listed browsers.
1
1
11
1,322
There is a lot more that I haven't covered here. Perhaps I'll leave that for a future talk or blog.
1
6
1,032
In macOS Tahoe 26.4 Apple added a new security feature to Terminal that warns users of potentially malicious pastes with a "Possible malware, Paste blocked" prompt. Here how it actually works 🧵
14
91
732
114,275
So think about who actually passes all checks: no dev tools installed, hasn't opened Terminal in over 30 days, and is now pasting something copied from a web browser. Apple doesn't need to analyze the command when the behavior is suspicious.
3
1
64
5,607
If you're looking to trigger this on a test machine running macOS 26.4: 1. /Library/Developer must not exist and no dev tools should be installed 2. /var/db/.AppleSetupDone must be older than 24 hours. On a fresh install backdate it: sudo touch -t 202603200000 /var/db/.AppleSetupDone 3. Clear Terminal's state: defaults delete com.apple.Terminal LastTerminalStartTime and defaults delete com.apple.Terminal UserAcknowledgedPasteWarning 4. Quit Terminal completely and relaunch 5. Copy ANY text from Safari and paste into Terminal
1
2
57
5,247