PULSE NAME
Melting Pot of macOS Malware Adds Go to Crystal, Nim and Rust Variants
WHITE AlienVault 2025-03-26 Modified: 2025-03-26
26
IOCs
MEDIUM VOLUME
ReaderUpdate, a macOS malware loader platform active since 2020, has evolved to include variants written in Crystal, Nim, Rust, and now Go programming languages. Originally a compiled Python binary, the malware has been largely dormant until late 2024. The loader is capable of executing remote commands, potentially offering Pay-Per-Install or Malware-as-a-Service. It collects system information, creates persistence mechanisms, and communicates with command and control servers. The Go variant, less common than others, uses string obfuscation techniques to hinder analysis. While currently associated with adware delivery, the loader's capabilities pose a potential threat for more malicious payloads in the future.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ReaderUpdate Genieo DOLITTLE WizardUpdate UpdateAgent Silver Toucan
Indicators of Compromise (26)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 9a804487c9685096286d9c033b2eae40 2025-03-26
FileHash-SHA1 01e762ef8a10bbcda639ed62ef93b784268d925a 2025-03-26
FileHash-SHA1 0b689c5677445729c609e284e91c7048a1d8bc11 2025-03-26
FileHash-SHA1 1f6d6c9f3841d0477d8b38a64935e0b58e57605f 2025-03-26
FileHash-SHA1 21a2ec703a68382b23ce9ff03ff62dae07374222 2025-03-26
FileHash-SHA1 36ecc371e0ef7ae46f25c137aa0498dfd4ff70b3 2025-03-26
FileHash-SHA1 6461ec3154bec2f4dac27b84951ab28e1287d8c9 2025-03-26
FileHash-SHA1 7aa028fd7350193be167dc772a7eb486c9fa1c17 2025-03-26
FileHash-SHA1 86431ce246b54ec3372f08c7739cd1719715b824 2025-03-26
FileHash-SHA1 9b7590c4313159810443efcc6648837519b061d6 2025-03-26
FileHash-SHA1 b0bbe83895647a1efe6843d1c619059b00f72cf3 2025-03-26
FileHash-SHA1 d25eae2de64bb604987db27085d60f3ddf7ca473 2025-03-26
FileHash-SHA1 fe9ca39a8c3261a4a81d3da55c02ef3ee2b8863f 2025-03-26
FileHash-SHA1 ff6d99505c87876b613d511d8734a9379b826e1a 2025-03-26
FileHash-SHA256 9f2fb463fa521e401118d033459034a0353f510f250095e9ee18ed5c38738825 2025-03-26
domain airconditionersontop.com 2025-03-26
domain lakesandinnovations.com 2025-03-26
domain limitedavailability-show.com 2025-03-26
domain livingscontinuations.com 2025-03-26
domain motorcyclesincyprus.com 2025-03-26
domain simulators-and-cars.com 2025-03-26
domain slothingpressing.com 2025-03-26
domain small-inches.com 2025-03-26
domain strawberriesandmangos.com 2025-03-26
domain streamingleaksnow.com 2025-03-26
hostname www.entryway.world 2025-03-26