APTMembers
APT

Chrome-Impersonating Mach-O Binaries Hit Government Macs With 0/76 AV Detections

Two universal Mach-O binaries signed with a Google LLC Apple Developer certificate but missing the Info.plist bundle component required for full Gatekeeper validation are circulating against government-sector macOS targets with zero detections across 76 antivirus engines. The campaign pairs Chrome-identity spoofing with DNS-over-HTTPS C2 beaconing, Cloudflare-proxied command infrastructure, and a separately tiered AWS-backed exfiltration endpoint. A tracked-URL delivery framework fingerprints individual victims before any payload executes.

May 30, 2026, 10:44 (UTC+9)Last seenMay 31, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC12MITRE5

Two universal Mach-O binaries impersonating Google Chrome — signed with a valid Apple Developer-issued certificate bearing the Google LLC identity, yet carrying a MissingPlist code-signing verdict that defeats Gatekeeper's full bundle validation — are circulating against government-sector macOS targets with zero detections across 76 antivirus engines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence