Chilly Mac Malware & OAuth Phishing: Detection Tricks, No Treats

Chilly Mac Malware & OAuth Phishing: Detection Tricks, No Treats

Source: YouTube · VMRay · published Oct 23, 2025 · 47:21

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

VMRay’s October Detection Highlights webinar details critical updates to Virtual Thread Identifiers (VTI) and YARA rules, with a significant focus on enhanced Mac OS threat detection and advanced malware analysis techniques.

Key Takeaways:
• A new VTI targets TOSS modular malware by detecting its efficient IP blacklisting behavior, mapped to the Impact tactic rather than Command and Control. 1:44
• Detection efforts now heavily target Mac OS threats, specifically Atomic Stealer and the notarized ChiliHell backdoor, reflecting a growing trend in macOS malware. 3:15
• Patrick Stapman demonstrates SteelC v2’s use of APC injection to stealthily inject code into browser processes, enabling the theft of sensitive web data and cookies. 4:00

These updates provide analysts with deeper visibility into emerging threats, particularly the increasing sophistication of Mac-targeted malware and complex evasion techniques like sleep and APC injection.

Sources:

  • 1:44 Introduction to VTI and YARA rule updates for threat detection.
  • 3:15 Overview of Mac OS threat landscape including Atomic Stealer.
  • 4:00 Demo of SteelC v2 configuration extraction and APC injection.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. Let's wait for a minute for people to join. Then we will get started. All right, I think we can get started. Hey everyone, uh welcome to the October edition of detection highlights webinar series. I'm R2. I do product marketing here at VMRA and I'm joined today by my dear colleague Patrick Stapman team >> thread analysis. Hi Patrick. >> Hi. >> Um so always great to have you. Um so if you're new here every month we share highlights from the labs team the updates uh new VMray thread identifiers. uh we use the acronym VTI and Y rules uh new config extractors and kind of things that help catch new emerging threats faster. Um that said, we only have time to go through the top highlights. So if you're interested in the full change log, definitely check out the monthly blog post f…