Back to Resources

SentinelOne Vs. macOS.Macma – Remediation

⚔️ See how SentinelOne remediates macOS.Macma. macOS.Macma is a suspected Chinese-backed APT malware used against Hong Kong-based activists in 2021. The threat was propagated in two distinct ways: a trojan installer app called « SafariFlashActivity » and via a web-based watering hole campaign that leveraged a remote code execution in WebKit and a local privilege escalation in the XNU kernel.

The malware, once installed, spies on users via a keylogger and AV captures of the user’s on-screen Windows. Other functionality includes device fingerprinting, file downloads and exfiltration.

Despite being a novel malware with no previous signature, the SentinelOne agent catches macOS.Macma as it tries to execute thanks to the agent’s behavioral AI.

Read more at: https://www.sentinelone.com/blog/backdoor-macos-macma-spies-on-activists-but-cant-hide-from-behavioral-detection/

Lisez maintenant

Découvrez la plateforme de cybersécurité la plus avancée au monde

Observez comment notre plateforme de cybersécurité intelligente et autonome peut protéger votre entreprise contre les menaces actuelles et futures.