XProtect 5357 flags AmnesiaStealer in ten new detection rules

Apple's weekly macOS signature refresh adds ten rules and retunes two as AmnesiaStealer detection expands.

AppleThreat Staff
1 Min Read

Apple’s built-in macOS malware scanner has rolled to a new signature build that widens detection across several families, including a Chromium-hijacking stealer that security firms have tied to fake download lures.

The weekly refresh brought XProtect to version 5357, delivered through iCloud to Macs on Sequoia and later. Eclectic Light Company’s Howard Oakley documented the update, which loads five new YARA rules covering the families he tracks as CROOKEDCRUSTACEAN.IMPLANT.A, MACOS.ODYSSEY.XOOB and three SHADYSHOELACE variants. It also revises the existing MACOS.BONZAIBONANZA.VACA rule.

Oakley confirmed reader observations that the SHADYSHOELACE signatures target AmnesiaStealer, the multi-stage Rust-based infostealer that hijacks Chromium browsers. The build adds a parallel set of five AppleScript detection rules for the MACOS.OSASCRIPT cluster, named TITEST, TIPAHA, TIKEGR, TISASH and TIINCO, and amends MACOS.OSASCRIPT.SYPR.

Apple ships no changelog for signature drops, so the trigger for each rule stays opaque. The release carries the label XProtectPlistConfigData_10_15-5357, and users who have not received it can force the install with the sudo xprotect update command, with the current version listed under System Information, Software, Installations.

Share This Article