Explore the advanced capabilities of APT28's XAgent malware for macOS in this 19-minute conference talk from Security BSides San Francisco. Delve into the newly discovered macOS version of XAgent, which expands the malware's reach beyond Windows, Linux, and iOS. Learn about its enhanced spying features, including key-logging, screen grabbing, and file exfiltration. Discover how this variant can steal iOS backups from Mac computers, accessing sensitive data such as messages, contacts, voicemail, call history, notes, calendar, and Safari information. Gain insights into why this macOS version is considered the most sophisticated iteration of APT28 in terms of cyber espionage capabilities.
Overview
Syllabus
BSidesSF 2018 - Deconstructing APT28's XAgent for OSX (Tiberius Axinte)
Taught by
Security BSides San Francisco