home.social

#choziosiloader — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #choziosiloader, aggregated by home.social.

  1. Day 1️⃣​0️⃣​ of #100DaysOfYara: MacOS Browser Hijacker Scripts🍎​
    🔗​ github.com/colincowie/100DaysO

    Background on these MacOS malware scripts used by #ChromeLoader aka #ChoziosiLoader:
    📖​ redcanary.com/blog/chromeloade
    📖​ blogs.vmware.com/security/2022
    📖​ th3protocol.com/2022/Choziosi-

    Todays rule did a nice job of detecting the historical ChromeLoader scripts. A more generic yara rule for identifying .command script abuse would potentially be pretty interesting!