1/7: Huge kudos to Mosyle for the original catch and to @9to5mac for spreading the word (http://bit.ly/4lZHfK2). Our Lab couldn't help but hunt related JSCoreRunner activity, and we (sadly) saw multiple hits among our users. Our heat map shows the most impact in the US and UK.
@9to5mac 2/7: While digging, our engine flagged a new JSCoreRunner sample with 0 detections on VirusTotal (as of 2025-09-02). It reuses the same playbook: benign-looking Stage-1 installer -> pulling Stage-2 -> launching payload. Let’s break it down 👇
@9to5mac 3/7: The Stage-1 package installs a benign http://ManualsFinder.app and immediately opens it to sell the illusion of a legitimate tool. No malicious logic is embedded in the app itself. What actually matters is the postinstall script.
@9to5mac 4/7: The postinstall script launches a decoy app, fetches Stage-2 from themanualfinder[.]com while attaching a unique host identifier, and installs Stage-2 to the current user’s directory. Installing to user scope is key: it lowers friction and typically avoids an admin
@9to5mac 5/7: On to Stage-2: a tidy PKG RosettaUpdateAuto-component.pkg (3508...abed). Before anything flashy, the preinstall script sends a JSON beacon to C2 to confirm the chain is live: ({"event":"preinstall"}) -> hxxps://themanualfinder[.]com/pxlpkg.
@9to5mac 6/7: Then the Stage-2 postinstall script removes a quarantine attribute recursively (xattr -rc), launches the malicious RossetaInfra binary from the package, and sends installation logs to C2 at themanualfinder[.]com.
@9to5mac 7/7: As for the payload itself (RossetaInfra Mach-O), its behavior overlaps with JSCoreRunner described by 9to5Mac - Chrome profile tampering (default search + new tab). Reused URL templates include: https://%s/nt?utn=%s https://%s/search?utn=%s&q...
@9to5mac 🧙IOC Section URLs: themanualfinder[.]com/RosettaUpdateAuto.pkg themanualfinder[.]com/pxlpkg Filenames: ManualsFinder\.app RossetaInfra Stage-1 (PKG): 9fe25221834537c56e3514460f2c42ae0415ca40449ca7b71cebd8bd0445eefd Stage-1 (postinstall):
COLDRIVER Group's ClickFix https://www.zscaler.com/blogs/...
Seeing a new PowerShell-based stealer that shares many resemblances to #KoiLoader, and is possibly a new tool for the threat group. Tracking it as #KoiStealerPS. Screenshots below show the HTTP POST request format exfiltrating stolen data/system information. The "enc" key stores
🏆 Unit 42 research wins the Péter Szőr Award at #VB2025! The development of our Attribution Framework by Andy Piazza, Kyle Wilhoit, Robert Falcone and David Fuertes is recognized as outstanding technical security research. Read it here: https://bit.ly/46nvHvB
The Splunk Threat Research Team has analyzed the LAMEHUG malware, revealing its tactics to aid SOC analysts and blue teamers in identifying and responding to cyber intrusions. #CyberSecurity #MalwareAnalysis https://www.splunk.com/en_us/b...















