Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New ReaderUpdate Malware Variants Target macOS Users: A Comprehensive Analysis


New ReaderUpdate malware variants have been discovered targeting macOS users, with the latest versions written in Crystal, Nim, Rust, and Go. The malicious software can be used to deliver ransomware or other types of malicious software, making it essential for security professionals to stay informed about this emerging threat.

  • The new ReaderUpdate malware variants target macOS users and have been written in various programming languages, including Crystal, Nim, Rust, and Go.
  • The malware collects system information for malicious purposes such as espionage or ransomware attacks.
  • Threat actors can use ReaderUpdate as a tool for offering Pay-Per-Install (PPI) or Malware-as-a-Service (MaaS).
  • The Go variant of the malware hides in the ~/Library/Application Support/ directory and collects system hardware information.
  • The malware variants are obfuscated, making it challenging for security researchers to understand their inner workings.
  • The ReaderUpdate malware is limited to Intel x86 architectures, which may make it less detectable by antivirus software.



  • In recent months, a new wave of malware variants has emerged, specifically targeting macOS users. The malicious software, known as ReaderUpdate, was first identified in 2020 and was previously associated with the delivery of adware. However, the latest variants have been written in various programming languages, including Crystal, Nim, Rust, and Go, making them more sophisticated and difficult to detect.

    According to a report by SentinelOne, researchers have identified multiple versions of the ReaderUpdate malware, each with its own unique characteristics. The malware is designed to load on macOS systems and collect system information, which can be used for malicious purposes such as espionage or ransomware attacks. The variants are spread through older infections and third-party downloads, often via trojanized apps like "DragonDrop".

    One of the most significant concerns surrounding ReaderUpdate is its potential use by threat actors as a tool for offering Pay-Per-Install (PPI) or Malware-as-a-Service (MaaS). This means that malicious actors can purchase access to the malware and use it to infect other systems, generating revenue based on the number of infections.

    The Go variant of the malware is particularly noteworthy, as it has been observed collecting system hardware information for unique victim IDs and hiding in the ~/Library/Application Support/ directory. The malware maintains persistence via a .plist file and executes remote C2 commands, suggesting that it may be used to deliver ransomware or other types of malicious software.

    The ReaderUpdate malware variants are also notable for their obfuscation techniques, which involve using functions that assemble characters on the stack or run simple character substitution algorithms to evade analysis. This makes it challenging for security researchers to understand the inner workings of the malware and develop effective countermeasures.

    Despite its sophistication, the ReaderUpdate malware variants have several characteristics that make them vulnerable to detection. For example, all versions are Intel x86-only, requiring Rosetta 2 on Apple Silicon. This limitation means that the malware is less likely to be detected by antivirus software designed for other architectures.

    Researchers have also identified nine samples of the Go variant linked to seven domains tied to broader malware infrastructure. This suggests that ReaderUpdate may be part of a larger campaign to infect systems and deliver malicious payloads.

    In conclusion, the emergence of new ReaderUpdate malware variants targeting macOS users highlights the ongoing threat landscape in the world of cybersecurity. As malicious actors continue to evolve and improve their tactics, it is essential for security researchers and professionals to stay vigilant and develop effective countermeasures to detect and mitigate these threats.

    New ReaderUpdate malware variants have been discovered targeting macOS users, with the latest versions written in Crystal, Nim, Rust, and Go. The malicious software can be used to deliver ransomware or other types of malicious software, making it essential for security professionals to stay informed about this emerging threat.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-ReaderUpdate-Malware-Variants-Target-macOS-Users-A-Comprehensive-Analysis-ehn.shtml

  • https://securityaffairs.com/175891/malware/readerupdate-malware-variants-targets-macos.html


  • Published: Wed Mar 26 18:10:55 2025 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us