Published: September 4, 2025
1
11
31

1/7: Huge kudos to Mosyle for the original catch and to @9to5mac for spreading the word (http://bit.ly/4lZHfK2). Our Lab couldn't help but hunt related JSCoreRunner activity, and we (sadly) saw multiple hits among our users. Our heat map shows the most impact in the US and UK.

Image in tweet by Moonlock Lab

@9to5mac 2/7: While digging, our engine flagged a new JSCoreRunner sample with 0 detections on VirusTotal (as of 2025-09-02). It reuses the same playbook: benign-looking Stage-1 installer -> pulling Stage-2 -> launching payload. Let’s break it down 👇

Image in tweet by Moonlock Lab

@9to5mac 3/7: The Stage-1 package installs a benign http://ManualsFinder.app and immediately opens it to sell the illusion of a legitimate tool. No malicious logic is embedded in the app itself. What actually matters is the postinstall script.

Image in tweet by Moonlock Lab
Image in tweet by Moonlock Lab

@9to5mac 4/7: The postinstall script launches a decoy app, fetches Stage-2 from themanualfinder[.]com while attaching a unique host identifier, and installs Stage-2 to the current user’s directory. Installing to user scope is key: it lowers friction and typically avoids an admin

Image in tweet by Moonlock Lab

@9to5mac 5/7: On to Stage-2: a tidy PKG RosettaUpdateAuto-component.pkg (3508...abed). Before anything flashy, the preinstall script sends a JSON beacon to C2 to confirm the chain is live: ({"event":"preinstall"}) -> hxxps://themanualfinder[.]com/pxlpkg.

Image in tweet by Moonlock Lab
Image in tweet by Moonlock Lab

@9to5mac 6/7: Then the Stage-2 postinstall script removes a quarantine attribute recursively (xattr -rc), launches the malicious RossetaInfra binary from the package, and sends installation logs to C2 at themanualfinder[.]com.

Image in tweet by Moonlock Lab
Image in tweet by Moonlock Lab

@9to5mac 7/7: As for the payload itself (RossetaInfra Mach-O), its behavior overlaps with JSCoreRunner described by 9to5Mac - Chrome profile tampering (default search + new tab). Reused URL templates include: https://%s/nt?utn=%s https://%s/search?utn=%s&q...

Image in tweet by Moonlock Lab

@9to5mac 🧙IOC Section URLs: themanualfinder[.]com/RosettaUpdateAuto.pkg themanualfinder[.]com/pxlpkg Filenames: ManualsFinder\.app RossetaInfra Stage-1 (PKG): 9fe25221834537c56e3514460f2c42ae0415ca40449ca7b71cebd8bd0445eefd Stage-1 (postinstall):

COLDRIVER Group's ClickFix https://www.zscaler.com/blogs/...

Image in tweet by Moonlock Lab

Seeing a new PowerShell-based stealer that shares many resemblances to #KoiLoader, and is possibly a new tool for the threat group. Tracking it as #KoiStealerPS. Screenshots below show the HTTP POST request format exfiltrating stolen data/system information. The "enc" key stores

Image in tweet by Moonlock Lab
Image in tweet by Moonlock Lab
Image in tweet by Moonlock Lab

🏆 Unit 42 research wins the Péter Szőr Award at #VB2025! The development of our Attribution Framework by Andy Piazza, Kyle Wilhoit, Robert Falcone and David Fuertes is recognized as outstanding technical security research. Read it here: https://bit.ly/46nvHvB

Image in tweet by Moonlock Lab

The Splunk Threat Research Team has analyzed the LAMEHUG malware, revealing its tactics to aid SOC analysts and blue teamers in identifying and responding to cyber intrusions. #CyberSecurity #MalwareAnalysis https://www.splunk.com/en_us/b...

Share this thread

Read on Twitter

View original thread

Navigate thread

1/13