APTMembers
APT

FunkSec macOS Implant Evades 76 AV Engines via Fake Chrome Signing

Two Mach-O binaries posing as a Chrome subprocess carry a structurally invalid Google LLC certificate that passes casual inspection while failing Gatekeeper's full validation. The campaign achieves zero detections across all 76 VirusTotal engines and operates a multi-tier C2 infrastructure built to survive takedown.

May 26, 2026, 22:24 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorFunkSecIOC92MITRE8

Two Mach-O universal binaries named com.google.Chrome.helper — each 166 kilobytes, each signed with a structurally present but functionally invalid Google LLC code-signing certificate, each returning zero detections across all 76 antivirus engines on VirusTotal — are circulating as part of a campaign CTX Team has attributed to FunkSec, targeting engineering and government sector organisations operating macOS endpoints.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence