Mosyle identifies two new macOS threats invisible to antivirus engines

Mosyle has discovered two sophisticated macOS threats—Phoenix Worm and ShadeStager—that evade all major antivirus engines by using modular, behavioral-based attack chains designed for persistence and credential theft rather than immediate payload delivery. This discovery underscores a critical security gap: traditional signature-based antivirus protection is insufficient for modern macOS environments, requiring IT organizations to shift toward behavioral detection and real-time visibility as baseline security controls. For CIOs managing Apple infrastructure, this represents an urgent need to reassess macOS security posture, particularly regarding developer environments and cloud credential exposure.

9to5Mac2 min read
Read full article
Mosyle identifies two new macOS threats invisible to antivirus engines
After exclusively sharing details with 9to5Mac last September on ModStealer, a cross-platform infostealer invisible to every major antivirus engine at the time, Mosyle, a leader in Apple device management and security, is back with two more macOS threats that are flying completely under the radar. In new details again shared with 9to5Mac, the Mosyle Security Research Team says it has identified two previously undetected samples: Phoenix Worm, a cross-platform stager, and ShadeStager, a modular macOS implant built for credential theft. The two aren’t directly connected in how they work, but together show just how sophisticated Mac malware is getting. more…