Skip Navigation
Get a Demo
 
 
 
 
 
 
 
 
 
Resources Videos
Security operations

SecOps Weekly: Episode 76 – Mac malware AMA!

SecOps Weekly | 08.11.26

Mac malware AMA!

Senior Malware Analyst Tony Lambert answered questions on all things Mac malware, discussed Phexia’s novel use of EtherHiding, and gave tips for defenders on how to identify adversarial behavior on macOS.

SHOW NOTES

In this episode of SecOps Weekly, Phil Hagen and Tony Lambert discuss the evolving landscape of macOS malware. The presenters debunk the myth that Macs are immune to viruses, citing statistics that show increased activity from threats like MacSync Stealer and Phexia. They explore technical delivery methods, including the use of ClickFix for social engineering tactics and AppleScript for fileless execution. The discussion covers detection strategies via EDR and the use of Apple’s Endpoint Security Framework, as well as prevention methods like the open-source Santa application control tool. The episode concludes with advice on managing Mac fleets within an enterprise environment.

TIMESTAMPS

  • 00:00: Welcome to SecOps Weekly!
  • 01:58: The myth
  • 03:19: Top Mac malware threats
  • 07:10: A look at Phexia
  • 12:20: What can defenders do about Mac malware?
  • 27:04: The obfuscation evolution

Security gaps? We got you.

Sign up for our monthly email newsletter for expert insights on MDR, threat intel, and security ops—straight to your inbox.


 
 
Back to Top