Skip to Content
Blue Fox
book

Blue Fox

by Maria Markstedter
April 2023
Intermediate to advanced
480 pages
12h 14m
English
Wiley
Content preview from Blue Fox

CHAPTER 12Reversing arm64 macOS Malware

Until recently, any Mac had an Intel‐based processor at its core. Now, all new Macs instead contain “Apple Silicon.” Starting with the M1, these system on chips (SoC) use the Arm instruction set. To maintain native compatibility with these new Apple systems, malware authors have begun distributing their malicious creations compiled as Arm 64‐bit binaries.

For Mac malware analysts, the presence of such Arm 64‐bit binaries may present some challenges. Most notably, these binaries disassemble not into the traditionally more familiar Intel‐based instructions but rather into the A64 instruction set.

At this point in the book, you're already armed with a foundational understanding of this instruction set. In this chapter, we'll build upon this knowledge and provide the information you'll need to be well on the road to becoming a proficient analyst of arm64 malware, targeting macOS.

This chapter starts with a few introductory topics such as methods of identifying native arm64 macOS binaries. This knowledge will aid us when hunting for arm64 macOS malware and was in fact used to uncover the very first malware natively compatible with Apple Silicon. The remainder of this chapter focuses on tools and techniques to analyze such malware, specifically focusing on the anti‐analysis logic that aims to thwart overall analysis efforts.

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Black Hat Go

Black Hat Go

Tom Steele, Chris Patten, Dan Kottmann
The Ghidra Book

The Ghidra Book

Chris Eagle
Storytelling with You

Storytelling with You

Cole Nussbaumer Knaflic
Extreme C

Extreme C

Kamran Amini

Publisher Resources

ISBN: 9781119745303Purchase Link