Geacon Mac Malware
Summary
While Geacon and Cobalt Strike were originally designed as legitimate utilities used by organizations to test their network security through simulated attacks, evil-minded actors have increasingly exploited them for various nefarious activities. Once this has been confirmed, the file proceeds to retrieve an unsigned payload known as Geacon Plus from the attackers Command-and-Control (C2) server, which has an IP address originating from China. Prior to initiating its beaconing activity, the payload employs a deceptive tactic to mislead victims by displaying a decoy PDF file. The displayed document masquerades as a resume belonging to an individual named Xy Yiqing, aiming to divert the victims attention from the threatening actions that the malware is performing in the background. Naturally, this necessitates increased vigilance from Mac users and the implementation of sufficient security measures to protect their devices from malware infections.