XProtect 5363 targets two unfamiliar Mac malware families

Apple's silent XProtect refresh brings the Mac malware scanner to build 5363 and adds eight rules across two families it has never named in public.

AppleThreat Staff
2 Min Read

A quiet signature refresh has landed on Macs with no prompt, no dialog and no restart notice, the kind of background change that only becomes visible if you go looking at version numbers stored on disk.

The update lifts XProtect, the malware scanner Apple ships inside every macOS install, to build 5363. It adds eight YARA rules spread across two families the vendor has never described in public guidance, tracked as BRUSQUEBARNACLE and GRABBYGREMLIN.

Five more rules were amended, covering SOMA, ADLOAD, BONZAIBANANA and SHADYSHOELACE, and the Osascript file that watches for script-based attacks gained one new entry plus a revision to an existing one.

None of it arrives with an advisory or a CVE. Apple has never explained what its rules hunt for, so the only account of what changed is the file comparison Howard Oakley publishes at The Eclectic Light Company.

Reach is limited. Sequoia, Tahoe and Golden Gate received the signatures through Apple’s iCloud path, and the packaged build carries a Sequoia-and-later label, consigning older releases to the legacy route. Build 5363 also followed 5362 by a single day, and 5362 itself reached some Sequoia machines late.

For certainty, read System Information under Software and Installations, or run SilentKnight, instead of trusting a version string a Mac reports elsewhere.

Share This Article