Hello Friends, Been a While. Anyone have some guidance on macOS Malware Analysis?

So, basically the title of the post. Recently took on a full-time position on a threat research/hunt team and have become interested in filling a gap in macOS reverse engineering/Malware Analysis expertise. Zero2Auto and these forums and Discord are huge part in why I have this position so I thought I should ask the community.

Any guidance? Some initial searches have turned up some decent-looking information but I haven’t found any books specifically focused on the architecture and or OS.

Would be much appreciated!

4 Likes

idk man this is what i got, i hope you will find some help:

2 Likes

hi there,
yup there isn’t as much info on mac malware stuff vs Windows or *nix. but the best you can turn to are the following:

https://objective-see.com/about.html

https://www.amazon.com/Jonathan-Levin/e/B008ZF7ZKK/ref=dp_byline_cont_book_1

always start with the basics learning the OSX file types and internals of OSX.

1 Like

I came across the MacOS Internals triology a few days ago, they aim to be the equivalent of Windows Internals books for MacOS. No idea how good they are though.

2 Likes

True but they are expensive. Have you taken a look at The Art of Mac Malware? I think it’s still free: https://taomm.org/

2 Likes

This website has a workshop on macos Dylib injection , its awasome you should defenitly check it…

4 Likes

Wow this is a good resource, thanks for posting

1 Like

check out the vx-underground papers on MacOS malware
https://vx-underground.org/papers.html
the analysing of the MacOS Rootkits paper is a great read, and I 100% recommend checking it out

1 Like

This topic was automatically closed after 121 days. New replies are no longer allowed.