⚔️ See how SentinelOne kills and quarantines macOS.Macma. macOS.Macma is a suspected Chinese-backed APT malware used against Hong Kong-based activists in 2021. The threat was propagated in two distinct ways: a trojan installer app called „SafariFlashActivity“ and via a web-based watering hole campaign that leveraged a remote code execution in WebKit and a local privilege escalation in the XNU kernel.
The malware, once installed, spies on users via a keylogger and AV captures of the user’s on-screen Windows. Other functionality includes device fingerprinting, file downloads and exfiltration.
Despite being a novel malware with no previous signature, the SentinelOne agent catches macOS.Macma as it tries to execute thanks to the agent’s behavioral AI.
Read more at: https://www.sentinelone.com/blog/backdoor-macos-macma-spies-on-activists-but-cant-hide-from-behavioral-detection/
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
Erfahren Sie, wie unsere intelligente, autonome Cybersecurity Plattform Ihr Unternehmen heute und morgen schützt.