PULSE NAME
Melting Pot of macOS Malware Adds Go to Crystal, Nim and Rust Variants
WHITE AlienVault 2025-03-26 Modified: 2025-03-26
26
IOCs
MEDIUM VOLUME
ReaderUpdate, a macOS malware loader platform active since 2020, has evolved to include variants written in Crystal, Nim, Rust, and now Go programming languages. Originally a compiled Python binary, the malware has been largely dormant until late 2024. The loader is capable of executing remote commands, potentially offering Pay-Per-Install or Malware-as-a-Service. It collects system information, creates persistence mechanisms, and communicates with command and control servers. The Go variant, less common than others, uses string obfuscation techniques to hinder analysis. While currently associated with adware delivery, the loader's capabilities pose a potential threat for more malicious payloads in the future.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ReaderUpdate Genieo DOLITTLE WizardUpdate UpdateAgent Silver Toucan
Indicators of Compromise (1 / 26 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 9a804487c9685096286d9c033b2eae40 2025-03-26