⚔️ See how SentinelOne remediates macOS.Macma. macOS.Macma is a suspected Chinese-backed APT malware used against Hong Kong-based activists in 2021. The threat was propagated in two distinct ways: a trojan installer app called “SafariFlashActivity” and via a web-based watering hole campaign that leveraged a remote code execution in WebKit and a local privilege escalation in the XNU kernel.
The malware, once installed, spies on users via a keylogger and AV captures of the user’s on-screen Windows. Other functionality includes device fingerprinting, file downloads and exfiltration.
Despite being a novel malware with no previous signature, the SentinelOne agent catches macOS.Macma as it tries to execute thanks to the agent’s behavioral AI.
Read more at: https://www.sentinelone.com/blog/backdoor-macos-macma-spies-on-activists-but-cant-hide-from-behavioral-detection/
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
See how our intelligent, autonomous cybersecurity platform harnesses the power of data and AI to protect your organization now and into the future.