The Art of Mac Malware: The Guide to Analyzing Malicious Software

  • 5h
  • Patrick Wardle
  • No Starch Press
  • 2022

Defenders must fully understand how malicious software works if they hope to stay ahead of the increasingly sophisticated threats facing Apple products today. The Art of Mac Malware: The Guide to Analyzing Malicious Software is a comprehensive handbook to cracking open these malicious programs and seeing what’s inside.

Discover the secrets of nation state backdoors, destructive ransomware, and subversive cryptocurrency miners as you uncover their infection methods, persistence strategies, and insidious capabilities. Then work with and extend foundational reverse-engineering tools to extract and decrypt embedded strings, unpack protected Mach-O malware, and even reconstruct binary code. Next, using a debugger, you’ll execute the malware, instruction by instruction, to discover exactly how it operates. In the book’s final section, you’ll put these lessons into practice by analyzing a complex Mac malware specimen on your own.

You’ll learn to:

  • Recognize common infections vectors, persistence mechanisms, and payloads leveraged by Mac malware
  • Triage unknown samples in order to quickly classify them as benign or malicious
  • Work with static analysis tools, including disassemblers, in order to study malicious scripts and compiled binaries
  • Leverage dynamical analysis tools, such as monitoring tools and debuggers, to gain further insight into sophisticated threats
  • Quickly identify and bypass anti-analysis techniques aimed at thwarting your analysis attempts

A former NSA hacker and current leader in the field of macOS threat analysis, Patrick Wardle uses real-world examples pulled from his original research. The Art of Mac Malware: The Guide to Analyzing Malicious Software is the definitive resource to battling these ever more prevalent and insidious Apple-focused threats.

About the Author

Patrick Wardle is the creator of the Mac security website and tool suite Objective-See. Having worked at NASA and the NSA, as well as presented at countless security conferences, he is intimately familiar with aliens, spies, and talking nerdy. Patrick is passionate about all things related to macOS security and thus spends his days finding Apple 0days, analyzing macOS malware, and writing free open-source security tools to protect Mac users.

In this Book

  • Foreword
  • Introduction
  • Infection Vectors
  • Persistence
  • Capabilities
  • Nonbinary Analysis
  • Binary Triage
  • Disassembly and Decompilation
  • Dynamic Analysis Tools
  • Debugging
  • Anti-Analysis
  • EvilQuest’s Infection, Triage, and Deobfuscation
  • EvilQuest’s Persistence and Core Functionality Analysis
SHOW MORE
FREE ACCESS

YOU MIGHT ALSO LIKE

Rating 4.5 of 112 users Rating 4.5 of 112 users (112)
Rating 5.0 of 1 users Rating 5.0 of 1 users (1)