
Chrome-Impersonating Mach-O Binaries Hit Government Macs With 0/76 AV Detections
Two universal Mach-O binaries signed with a Google LLC Apple Developer certificate but missing the Info.plist bundle component required for full Gatekeeper validation are circulating against government-sector macOS targets with zero detections across 76 antivirus engines. The campaign pairs Chrome-identity spoofing with DNS-over-HTTPS C2 beaconing, Cloudflare-proxied command infrastructure, and a separately tiered AWS-backed exfiltration endpoint. A tracked-URL delivery framework fingerprints individual victims before any payload executes.
Two universal Mach-O binaries impersonating Google Chrome — signed with a valid Apple Developer-issued certificate bearing the Google LLC identity, yet carrying a MissingPlist code-signing verdict that defeats Gatekeeper's full bundle validation — are circulating against government-sector macOS targets with zero detections across 76 antivirus engines.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read