SentinelLabs Logo RGB WhitePurp
ABOUT
CONTACT
VISIT SENTINELONE.COM

Phil Stokes

Phil Stokes is a Research Engineer at SentinelOne, specializing in macOS threat intelligence, platform vulnerabilities and malware analysis. He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform. Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.
Eliezer Pujols 1196680 Unsplash 1600x900
labs

How Malware Can Easily Defeat Apple’s macOS Security

Phil Stokes / December 3, 2018

or the one where we argue why your business really needs antivirus protection

Read More
Brad Pouncey 1377685 Unsplash 1600x900
labs

The Dangers of a Fake macOS CryptoWallet Keylogger

Phil Stokes / November 27, 2018

We investigate a macOS keylogger targeting Exodus cryptocurrency asset manager. Learn what to look out for and how to avoid similar spyware attacks

Read More
9. Modifying Detection
labs

Inside SearchPageInstaller | macOS Malware Deploys a MITM Attack

Phil Stokes / November 5, 2018

We take a closer look at SPI adware, which leverages open-source mitmproxy to intercept traffic and inject ads

Read More
Sharon Mccutcheon 665638 Unsplash 1 1 1600x900
labs

Crypto Mining On Mac: How macOS Malware is on the Rise

Phil Stokes / October 30, 2018

A review of the most recent Cryptojacking threats affecting Apple Mac users

Read More
Post Default
labs

Inside Safari Extensions | Malicious Plugins Remain on Mojave

Phil Stokes / October 23, 2018

In Part 2, we explore the pros and cons of Apple's new architecture and what it means for macOS malware & adware

Read More
Daniel Korpai 1318726 Unsplash 1600x900
labs

Inside Safari Extensions | Malware’s Golden Key to User Data

Phil Stokes / October 18, 2018

A 2-part series looking at the technology behind macOS extensions and how malicious add-ons can steal passwords, banking details and other sensitive data

Read More
Akash Rajendra 1284185 Unsplash 1600x900
labs

5 “Safe Computing” Practices for macOS and Why They Aren’t Enough

Phil Stokes / October 4, 2018

Phishing scams, trojans and ransomware are all live threats on Apple’s platform. Is it time for the macOS community to embrace Next Gen AV software?

Read More
Nikolay Tarashchenko 1327004 Unsplash
labs

Mojave Security Can Be Bypassed With SSH Keygen Wrapper

Phil Stokes / September 25, 2018

Any local or remote user can bypass Apple’s new Full Disk Access requirement using ssh. Find out how to stay safe

Read More
Fernand De Canne 1290695 Unsplash 1600x900
labs

On the Trail of OSX.FairyTale | Adware Playing at Malware

Phil Stokes / September 20, 2018

An adware installer tries its best to avoid detection, but leaves behind more clues than intended

Read More
1. Inside Fruitfly
labs

OSX.Fruitfly recycled | macOS still vulnerable to ‘old’ Perl script

Phil Stokes / August 23, 2018

13-years in the wild and counting? macOS is still vulnerable to OSX.Fruitfly, which can easily be repurposed by other bad actors

Read More
Previous
1 … 17 18 19 20
Next

SentinelLabs

In the era of interconnectivity, when markets, geographies, and jurisdictions merge in the melting pot of the digital domain, the perils of the threat ecosystem become unparalleled. Crimeware families achieve an unparalleled level of technical sophistication, APT groups are competing in fully-fledged cyber warfare, while once decentralized and scattered threat actors are forming adamant alliances of operating as elite corporate espionage teams.

Recent Posts

  • LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine
    LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine
    June 2, 2026
  • LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout
    LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout
    May 14, 2026
  • PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
    PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
    May 7, 2026

Sign Up

Get notified when we post new content.

Thanks! Keep an eye out for new content!

  • Twitter
  • LinkedIn
©2026 SentinelOne, All Rights Reserved.