
FunkSec macOS Implant Evades 76 AV Engines via Fake Chrome Signing
Two Mach-O binaries posing as a Chrome subprocess carry a structurally invalid Google LLC certificate that passes casual inspection while failing Gatekeeper's full validation. The campaign achieves zero detections across all 76 VirusTotal engines and operates a multi-tier C2 infrastructure built to survive takedown.
Two Mach-O universal binaries named com.google.Chrome.helper — each 166 kilobytes, each signed with a structurally present but functionally invalid Google LLC code-signing certificate, each returning zero detections across all 76 antivirus engines on VirusTotal — are circulating as part of a campaign CTX Team has attributed to FunkSec, targeting engineering and government sector organisations operating macOS endpoints.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read