DEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac Destruction @HackersOnBoard
DEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac Destruction  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 1 hour ago
Whenever a new Mac malware specimen is uncovered, it provides a unique insight into the offensive Mac capabilities of hackers or nation-state adversaries. Better yet, such discoveries provide fully-functional capabilities that may be weaponized for our own surreptitious purposes! I mean, life is short, why write your own?

We'll begin this talk by discussing the methodology of subverting existing malware for "personal use", highlighting both the challenges and benefits of such an approach.

Next, we'll walk-thru the weaponization of various Mac malware specimens, including an interactive backdoor, a file-exfiltration implant, ransomware, and yes, even adware. Customizations include various runtime binary modifications that will coerce such malware to accept tasking from our own C&C servers, and/or automatically perform actions on our behalf.

Of course, in their pristine state, such samples are currently detected by AV products. As such we'll also walk-thru subtle modifications that will ensure our modified tools remains undetected by traditional detection approaches.

In conclusion, we'll highlight novel heuristic methods that can generically detect such threats to ensure Mac users remain protected even from such weaponized threats.
DEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac DestructionDEF CON 27 - How You Can Buy ATandT T-Mobile and Sprint Real-Time Location Data on the Black MarketDEF CON 27 - Pedro Cabrera Camara - SDR Against Smart TVs URL and Channel Injection AttacksBlack Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient LivesEdge Side Include Injection Abusing Caching Servers into SSRF and Transparent Session HijackingEfail Breaking S MIME and OpenPGP Email Encryption using Exfiltration ChannelsBlack Hat USA 2018 - Exploitation of a Modern Smartphone BasebandBlack Hat USA 2018 - A Deep Dive into macOS MDM and How it can be CompromisedDEF CON 27 - Douglas McKee - HVACking Understand the Delta Between Security and RealityDEF CON 27 - Kyle Gwinnup - Next Generation Process Emulation with BineeBlockchain Autopsies - Analyzing Ethereum Smart Contract DeathsMiasm Reverse Engineering Framework
HackersOnBoard |

DEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac Destruction

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER