PULSE NAME
Banshee: The Stealer That "Stole Code" From MacOS XProtect
WHITE Banshee AlienVault 2025-01-09 Modified: 2025-02-08
25
IOCs
MEDIUM VOLUME
A new version of the Banshee macOS stealer, linked to Russian-speaking cybercriminals, has been monitored since September. This version went undetected for over two months, using a string encryption algorithm identical to Apple's XProtect antivirus engine. The malware targets browser credentials, cryptocurrency wallets, and sensitive information. It was distributed through malicious GitHub repositories and phishing websites, often masquerading as popular software. The Banshee stealer-as-a-service operation, priced at $3,000, was advertised on Telegram and dark web forums before shutting down in November 2024 due to source code leakage. Despite this, threat actors continue to distribute updated versions, highlighting the growing trend of targeting macOS users.
Indicators of Compromise (25)
All FileHash-SHA256 YARA domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 00c68fb8bcb44581f15cb4f888b4dec8cd6d528cacb287dc1bdeeb34299b8c93 2025-01-09
FileHash-SHA256 1dcf3b607d2c9e181643dd6bf1fd85e39d3dc4f95b6992e5a435d0d900333416 2025-01-09
FileHash-SHA256 3bcd41e8da4cf68bb38d9ef97789ec069d393306a5d1ea5846f0c4dc0d5beaab 2025-01-09
FileHash-SHA256 b978c70331fc81804dea11bf0b334aa324d94a2540a285ba266dd5bbfbcbc114 2025-01-09
FileHash-SHA256 cdfbcb3d850713c49d451b3e80fb8507f86ba4ad9385e083c2a2bf8d11adc4fb 2025-01-09
FileHash-SHA256 ce371a92e905d12cb16b5c273429ae91d6ff5485dda04bfedf002d2006856038 2025-01-09
FileHash-SHA256 d04f71711e7749a4ff193843ae9ce852c581e55eaf29b8eec5b36c4b9c8699c2 2025-01-09
FileHash-SHA256 d8ecc92571b3bcd935dcab9cdbeda7c2ebda3021dda013920ace35d294db07be 2025-01-09
YARA 1498aff611e5021d140ffc4c61424fe3d674011a 2025-01-09
domain alden.io 2025-01-09
domain api7.cfd 2025-01-09
domain authorisev.site 2025-01-09
domain coincapy.com 2025-01-09
domain contemteny.site 2025-01-09
domain data.country 2025-01-09
domain dilemmadu.site 2025-01-09
domain faulteyotk.site 2025-01-09
domain forbidstow.site 2025-01-09
domain fotor.software 2025-01-09
domain goalyfeastz.site 2025-01-09
domain opposezmny.site 2025-01-09
domain oxygen.solutions 2025-01-09
domain seallysl.site 2025-01-09
domain servicedny.site 2025-01-09
domain westar.io 2025-01-09