XProtect 5358 adds detection rules for Dubrobber and ShadyShoelace

Apple's weekly macOS signature refresh lands at version 5358 with six new YARA rules split between the Dubrobber family and the newer ShadyShoelace strain.

AppleThreat Staff
1 Min Read

Apple’s built-in macOS malware detector moved to version 5358 overnight, reaching every supported edition of the operating system. The refresh adds six YARA rules: four expand coverage of ShadyShoelace, a family only recently on Apple’s radar, under MACOS.SHADYSHOELACE.OSLOSTA, MACOS.SHADYSHOELACE.OSLODL, MACOS.SHADYSHOELACE.LODLSYDEAR and MACOS.SHADYSHOELACE.LODLSYDEX8, with MACOS.DUBROBBER.SAINDY and MACOS.DUBROBBER.CHREIM extending the older Dubrobber detections. As with every drop in the series, no notes explained what triggered it.

The AppleScript side of the scanner changed too. MACOS.ANGRYORB.JXPL and MACOS.OSASCRIPT.DUEXKE joined the XPScripts rule set, the SYPR detection was tightened, and MACOS.OSASCRIPT.ANMA came out.

Sequoia and newer versions pull the data from iCloud with nothing required of users. The update appears under Installations in System Information as XProtectPlistConfigData_10_15-5358; sudo xprotect update forces it, while the sudo xprotect check command still misbehaves on macOS 27.

Version 5357 landed a week earlier with ten rules aimed at AmnesiaStealer, keeping the near-weekly rhythm of automatic signature refreshes that quietly stack new protections on defenses for older Mac malware.

Share This Article