ConfiantIntel Profile picture
@WeAreConfiant Threat Intelligence feeds account, fighting malvertisers since 2013 ⚔️
Jan 19, 2021 8 tweets 5 min read
New backdoor dubbed WizardUpdate, delivered via .PKG file Notarized by @Apple 😟👾 The Apple Developer ID is: Fiona Torok (M9S7M3WX5P). The .PKG hash is: 47fea0cf1eb04b5b0d7aba8c93646d8b63aae11783f629405cb7f93134dd6f86 delivered through ITW Browser Push Notifications .PKG have post/pre install scripts that downloads & execute a dummy WebView based app, browsing to get[.]adobe[.]com, the App is : ae0fac3473e2d29cc06e425dbe72801504a63fbbd92c0f5546f18304b09fc9b8 DLVPlayer.app/Contents/MacOS… signed by the same developer cert.