
Ferdous Saljooki
@malwarezoo
macOS Threat and Detections Research @JamfSoftware Opinions are my own.
ID: 870794599085879298
03-06-2017 00:09:45
393 Tweet
706 Followers
394 Following



Great find and fantastic write-up by my friends Ferdous Saljooki and Jaron Bradley over Jamf. Go check it out. Very interesting, signed and notarized at the time they were active, similar to the samples found by the team at SentinelLabs (blog also linked below). DPRK is




I had an amazing time at #obts catching up with old friends and meeting new ones. The talks were all fantastic and this community is truly one of a kind. Huge thanks to Andy Rozenberg and Patrick Wardle for hosting yet another successful conference. Looking forward to Ibiza next





Jamf Threat Labs uncovered a new variant of the Odyssey Infostealer — signed and notarized at the time of discovery. This variant includes backdoor functionality and techniques that align with recent Atomic Stealer research by Moonlock Lab. More here: jamf.com/blog/signed-an…
