Reversing arm64 macOS Malware
Maria Markstedter · 2023
This chapter starts with a few introductory topics such as methods of identifying native arm64 macOS binaries. This knowledge will aid us when hunting for arm64 macOS malware and was in fact used to uncover the very first malware natively compatible with Apple Silicon. The chapter focuses on tools and techniques to analyze such malware, specifically focusing on the anti-analysis logic that aims to thwart overall analysis efforts. It discusses the discovery of the first malware compiled to natively target Apple Silicon. Dynamic analysis involves executing a binary, such as malware, to observe its actions. Malware authors are well aware of common malware analysis techniques and thus may implement what is aptly termed “anti-analysis” logic to attempt to thwart or complicate any analysis efforts. The chapter looks at anti-debugging logic found within GoS-earch22 that leverages the ptrace system call.