![macos malware used runonly to detection macos malware used runonly to detection](https://thecyberpost.com/wp-content/uploads/2021/01/macos-malware-used-run-only-applescripts-to-avoid-detection-for-five-years_5ffdca15085ac.jpeg)
In January 2021, Intezer reported on Operation ElectroRAT, a campaign that had been running throughout 2020 targeting cryptocurrency users. "Run-only AppleScripts are surprisingly rare in the MacOS malware world, but both the longevity of and the lack of attention to the MacOS.OSAMiner campaign, which has likely been running for at least 5 years, shows exactly how powerful run-only AppleScripts can be for evasion and anti-analysis," Stokes concluded in his report yesterday. Top 10 In-the-Wild macOS Malware Discoveries 2021.
![macos malware used runonly to detection macos malware used runonly to detection](https://2.bp.blogspot.com/-ubAdNApEXNY/XMXYY9zK6yI/AAAAAAAAOu4/8gvUF8aTZokEDfdoA3cSB66Xivh6afxAgCLcBGAs/s1600/Flerken_4_intro-animation.gif)
![macos malware used runonly to detection macos malware used runonly to detection](https://i1.wp.com/macossoftware.net/wp-content/uploads/2018/03/Malwarebytes-Anti-Malware-3.2.35-Full-Crack-Mac.jpg)
MACOS MALWARE USED RUNONLY TO DETECTION SOFTWARE
Stokes and the SentinelOne team hope that by finally cracking the mystery surrounding this campaign and by publishing IOCs, other MacOS security software providers would now be able to detect OSAMiner attacks and help protect MacOS users. Yesterday, Stokes published the full-chain of this attack, along with indicators of compromise (IOCs) of past and newer OSAMiner campaigns. Since "run-only" AppleScript come in a compiled state where the source code isn't human-readable, this made analysis harder for security researchers. MacOS users have been the target of a sneaky malware operation for more than five years that used a clever trick to avoid detection and hijack infected. As users installed the pirated software, the boobytrapped installers would download and run a run-only AppleScript, which would download and run a second run-only AppleScript, and then another final third run-only AppleScript.