{"id":49992,"date":"2023-01-05T00:00:00","date_gmt":"2023-01-05T00:00:00","guid":{"rendered":"urn:uuid:bc09f2e7-2fdd-81da-b161-f0ecafa97ca8"},"modified":"2023-01-05T00:00:00","modified_gmt":"2023-01-05T00:00:00","slug":"dridex-returns-targets-macos-using-new-entry-method","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/","title":{"rendered":"Dridex Returns, Targets MacOS Using New Entry Method"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/dridex-returns-macos-641.png\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"The Dridex variant we analyzed targets MacOS platforms with a new technique to deliver documents embedded with malicious macros to users.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"malware,endpoints,research,articles, news, reports\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2023-01-05\"> <meta property=\"article:tag\" content=\"malware\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/a\/-dridex-targets-macos-using-new-entry-method.html\"> <title>Dridex Returns, Targets MacOS Using New Entry Method<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/a\/-dridex-targets-macos-using-new-entry-method.html\"><br \/>\n<meta property=\"og:title\" content=\"Dridex Returns, Targets MacOS Using New Entry Method\"><br \/>\n<meta property=\"og:description\" content=\"The Dridex variant we analyzed targets MacOS platforms with a new technique to deliver documents embedded with malicious macros to users.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/dridex-returns-macos-641.png\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Dridex Returns, Targets MacOS Using New Entry Method\"><br \/>\n<meta name=\"twitter:description\" content=\"The Dridex variant we analyzed targets MacOS platforms with a new technique to deliver documents embedded with malicious macros to users.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/dridex-returns-macos-641.png\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"50.651998692953\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1567129991\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"7.7542662116041\">\n<div class=\"article-details\" role=\"heading\" readability=\"34.894197952218\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Malware<\/p>\n<p class=\"article-details__description\">The Dridex variant we analyzed targets MacOS platforms with a new technique to deliver documents embedded with malicious macros to users.<\/p>\n<p class=\"article-details__author-by\">By: Armando Nathaniel Pedragoza <time class=\"article-details__date\">January 05, 2023<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"38.338235294118\">\n<div readability=\"22.609728506787\">\n<p>Normally, documents containing malicious macros enter a user\u2019s system via email attachments posing as normal document files. However, while this might be the primary method of arrival, malicious actors have other ways of entering a victim\u2019s system.<\/p>\n<p>This blog entry primarily <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/web-attack\/3147\/dealing-with-the-mess-of-dridex\">concerns Dridex<\/a>, an online banking malware that has been active for years. The variant we analyzed has made its way into the MacOS platform and has adopted a new technique to deliver documents embedded with malicious macros to users without having to pretend to be invoices or other business-related files.<\/p>\n<p>The Dridex sample we investigated arrived as a Mach-o executable file: <i>a.out <\/i>(which we detected as<i> <\/i>Trojan.MacOS.DRIDEX.MANP). The first submission for this in Virus Total (VT) dates to 2019, where it was tagged as malicious by security vendors with no specific detection names.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"5ec231\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-1.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-1.png\" alt=\"Figure 1. Mach-o regions which contain the header, load commands, and segments of the file\"> <\/a><figcaption>Figure 1. Mach-o regions which contain the header, load commands, and segments of the file<\/figcaption><\/figure>\n<\/p><\/div>\n<div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"ed42a0\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-2.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-2.png\" alt=\"Figure 2. Detections of a.out from April 2019 to December 2022\"> <\/a><figcaption>Figure 2. Detections of a.out from April 2019 to December 2022<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p><span class=\"body-subhead-title\"><\/span>The data segment of the sample contains the malicious embedded document and is used by the _payload_doc variable. The disassembly in Figure 5 shows that the malware performs a loop where the content of _payload_doc is copied until the counter reaches _payload_doc_len, the size of the malicious code. This is in preparation for the overwriting routine.<span class=\"body-subhead-title\"><\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"01c748\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-3.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-3.png\" alt=\"Figure 3. Disassembly of the __DATA__data segment\"> <\/a><figcaption>Figure 3. Disassembly of the __DATA__data segment<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>The data segment of the sample contains the malicious embedded document and is used by the _payload_doc variable. The disassembly in Figure 5 shows that the malware performs a loop where the content of _payload_doc is copied until the counter reaches _payload_doc_len, the size of the malicious code. This is in preparation for the overwriting routine.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"2b21cd\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-4.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-4.png\" alt=\"Figure 4. Disassembly of how the sample writes data onto the target files\"> <\/a><figcaption>Figure 4. Disassembly of how the sample writes data onto the target files<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"39\">\n<div readability=\"23\">\n<p>Once the malicious code is ready, the cstring segment plays a role in overwriting the code to the target files. This segment contains the following bash script command:<\/p>\n<p><i><span class=\"blockquote\">for i in $(find ~ -name \u201c*.doc\u201d); do echo \u2018%s\u2019 | xxd -r -p &gt; $i; done<\/span><\/i><\/p>\n<p>First, the malware searches for files in the current user (~\/User\/{user name}) directory that use the .doc file extension using the <i>find ~ -name \u201c*.doc\u201d <\/i>command. It then traverses through each document file (<i>i<\/i>) using <i>for<\/i> loop, and then writes the malicious code via the <i>echo \u2018%s\u2019<\/i> command (where <i>%s<\/i> is the malicious code from the data segment).<\/p>\n<p>Adding <i>xxd -r -p<\/i> to the script means that the malicious code will be written in plain hexadecimal dump, and not the actual content. The <i>&gt; $i <\/i>part of the script implies that the output will be printed on each document file.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"5d64ab\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-5.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-5.png\" alt=\"Figure 5. Disassembly of the __DATA__cstring segment\"> <\/a><figcaption>Figure 5. Disassembly of the __DATA__cstring segment<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>The disassembly in Figure 6 shows the value of <i>%s<\/i> that will be written on the document files. &nbsp;The malicious code it overwrites has a D0CF file format signature as seen the image, which implies that it is a Microsoft document file.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"3c30bf\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-6b.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-6b.png\" alt=\"Figure 6. Disassembly of the sample that shows the search and overwriting commands\"> <\/a><figcaption>Figure 6. Disassembly of the sample that shows the search and overwriting commands<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.782828282828\">\n<div readability=\"15.676767676768\">\n<p>The malicious embedded document was first detected in the wild in 2015 with the following information:<\/p>\n<p><b>SHA256: 70c7bf63bfe1fb83420905db6e65946d721e171db219034a52b27116795ae53e<br \/>Filename: pmB3A6.doc<br \/>Detection name: W2KM_DRIDEX.SPB<\/b><\/p>\n<p>Using <a href=\"https:\/\/github.com\/decalage2\/oletools\">oletools<\/a>, a python package used to analyze OLE and Microsoft files, we observed that the affected .doc files now contain macros.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"4e1f95\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-7.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-7.png\" alt=\"Figure 7. Text prompt showing that this document file contains macros\"> <\/a><figcaption>Figure 7. Text prompt showing that this document file contains macros<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"80e99e\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-8.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-8.png\" alt=\"Figure 8. Macros contained in the overwritten .doc file that were extracted using oletools\"> <\/a><figcaption>Figure 8. Macros contained in the overwritten .doc file that were extracted using oletools<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"36.5\">\n<div readability=\"18\">\n<p>Based on the extracted macros, the .doc file contains suspicious components. To elaborate, here are the VBA components of the overwritten documents:<\/p>\n<p><b>ThisDocument<\/b> is an object that includes the autoopen macro which calls the malicious functions. These functions use normal-looking names to pose as regular functions. For instance, CreatePicture and CreateColor are normally used to create image-related objects, but in this VBA project, they perform malicious tasks.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"ef8285\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-9.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-9.png\" alt=\"Figure 9. Code snippet from the autoopen macro\"> <\/a><figcaption>Figure 9. Code snippet from the autoopen macro<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p><b>Module1<\/b> Creates an executable file in the temporary (TEMP) folder and then runs it. The malware uses string concatenation as a method for obfuscating the name of the executable file it creates.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"864edc\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-10.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-10.png\" alt=\"Figure 10. Code snippet from Module1 that shows how the malware creates and executes an executable file \"> <\/a><figcaption>Figure 10. Code snippet from Module1 that shows how the malware creates and executes an executable file <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p><b>Module2<\/b> contains the routine that decrypts a set of strings, which is a URL, and then connects to it to retrieve a file using the GET command. The malware uses basic string encryption to hide the malicious URL it connects to. It calls the RuBik() function to perform the decryption routine.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"32b63e\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-11.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-11.png\" alt=\"Figure 11. Code snippet from Module2 showing the decryption routine to connect to the encrypted URL\"> <\/a><figcaption>Figure 11. Code snippet from Module2 showing the decryption routine to connect to the encrypted URL<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p><b>Module3 <\/b>writes the content of the file retrieved in Module2 to the executable file created in Module1.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"66a4b7\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-12.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-12.png\" alt=\"Figure 12. Code snippet from Module3 showing where the malware writes to the executable file\"> <\/a><figcaption>Figure 12. Code snippet from Module3 showing where the malware writes to the executable file<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"42.5\">\n<div readability=\"30\">\n<p>In this section, we will analyze the payload dropped by the malware. Note that since it is an exe file, it will not run in a MacOS environment. It is possible that the variant we analyzed is still in the testing stages and has not yet been fully converted to work in MacOS-based machines.<\/p>\n<p>When the document is opened and the macro is enabled, the malware connects to the URL decrypted in Module2 to retrieve a file (87i4g3d2d2.exe) using the GET command:<\/p>\n<p><span class=\"blockquote\">hxxp:\/\/pr-clanky[.]kvalitne[.]cz\/65y3fd23d\/87i4g3d2d2[.]exe<\/span><\/p>\n<p>While the macro feature in Microsoft Word is disabled by default, the malware will overwrite all the document files for the current user, including the clean files. This makes it more difficult for the user to determine whether the file is malicious since it doesn\u2019t come from an external source.<\/p>\n<p>After connecting to the domain, the content of the portable executable (PE) file is written to trume1.exe (aa6873a6002e152669f54c80801ca7d500ee8c00d5a6a8c223203303b1cbaf50) as analyzed in Module1, 2, and 3. The file trume1.exe will then be executed.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"b6255a\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-13.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-13.png\" alt=\"Figure 13. Network activity from the sample that shows the details of the URL it connects to\"> <\/a><figcaption>Figure 13. Network activity from the sample that shows the details of the URL it connects to<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"a3f41d\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-14.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-14.png\" alt=\"Figure 14. Payload of the sample when the macro-enabled document is opened\"> <\/a><figcaption>Figure 14. Payload of the sample when the macro-enabled document is opened<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>The content of the dropped executable file is in an HTML format instead of a PE file format since the URL that it is trying to access is already down. The PE file that it tries to download is the Dridex loader.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"505edd\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-15.png\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/dridex-returns-macos-15.png\" alt=\"Figure 15. Content of the executable file dropped by the malware\"> <\/a><figcaption>Figure 15. Content of the executable file dropped by the malware<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"39.240412979351\">\n<div readability=\"27.699115044248\">\n<h2><span class=\"body-subhead-title\">Conclusion<\/span><\/h2>\n<p>Dridex is not a new malware \u2014 it has been observed in the wild for years now. Despite its age, it continues to be used, and in fact has even seen <a href=\"https:\/\/www.google.com\/search?q=dridex+evolution&amp;oq=dridex+evolution&amp;aqs=edge..69i57j0i546l3j0i30i546j69i64.3424j0j1&amp;sourceid=chrome&amp;ie=UTF-8\">many enhancements over the years<\/a>. Its entry point into the user\u2019s system has traditionally been through email attachments, but this blog entry illustrates that the malicious actors using Dridex are also trying to find new targets and more efficient methods of entry.<\/p>\n<p>Currently, the impact on MacOS users for this Dridex variant is minimized since the payload is an exe file (and therefore not compatible with MacOS environments). However, it still overwrites document files which are now the carriers of Dridex\u2019s malicious macros. Furthermore, it\u2019s possible that the threat actors behind this variant will implement further modifications that will make it compatible with MacOS.<\/p>\n<p>We encourage users to avoid being infected by attacks that use social engineering and malicious documents by refraining from clicking links or opening attachments and embedded documents in emails. Furthermore, organizations can consider using security technologies such as <a href=\"https:\/\/www.trendmicro.com\/en_us\/small-business\/worry-free-services-suites.html\">Trend Micro\u2122 Worry-Free\u2122 Business Security<\/a>, which supports Mac and is ideal for small and medium-sized companies, and <a href=\"https:\/\/www.trendmicro.com\/en_ph\/business\/products\/user-protection\/sps\/endpoint.html\">Trend Micro\u2122 Apex One\u2122<\/a>, which is a powerful security solution for enterprise businesses.<\/p>\n<p><span class=\"body-subhead-title\">Indicators of Compromise<\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"29.1\">\n<div class=\"responsive-table-wrap\" readability=\"9.7\">\n<p>The indicators of compromise for this entry can be found in <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/-dridex-returns,-targets-macos-using-new-entry-method\/iocs-dridex-returns-targets-macos-using-new-entry-method.txt\">this document<\/a>.<\/p>\n<p><span class=\"body-subhead-title\">MITRE Tools, Tactics, and Procedures<\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" height=\"15%\">\n<tbody readability=\"10.821629213483\">\n<tr>\n<td>\n<p><b>Tactic<\/b><\/p>\n<\/td>\n<td width=\"85\">\n<p><b>ID<\/b><\/p>\n<\/td>\n<td width=\"227\">\n<p><b>Name<\/b><\/p>\n<\/td>\n<td width=\"223\">\n<p><b>Description<\/b><\/p>\n<\/td>\n<\/tr>\n<tr readability=\"7.2641509433962\">\n<td width=\"96\" valign=\"top\">\n<p>Discovery<\/p>\n<\/td>\n<td width=\"85\" valign=\"top\">\n<p><a href=\"https:\/\/attack.mitre.org\/techniques\/T1083\">T1083<\/a><\/p>\n<\/td>\n<td width=\"227\" valign=\"top\" readability=\"5\">\n<p>File and Directory Discovery<\/p>\n<\/td>\n<td width=\"223\" valign=\"top\" readability=\"6\">\n<p>Uses the <i>find<\/i> command to search for specific files within the file system and runs <i>echo<\/i> command to overwrite files<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5.46\">\n<td width=\"96\" valign=\"top\">\n<p>Execution<\/p>\n<\/td>\n<td width=\"85\" valign=\"top\">\n<p><a href=\"https:\/\/attack.mitre.org\/techniques\/T1204\/002\/\">T1204.002<\/a><u><\/u><\/p>\n<\/td>\n<td width=\"227\" valign=\"top\" readability=\"5\">\n<p>User Execution: Malicious File<\/p>\n<\/td>\n<td width=\"223\" valign=\"top\" readability=\"5\">\n<p>Requires the victim to run the malware .out file.<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5.7222222222222\">\n<td width=\"96\" valign=\"top\">\n<p>Execution<\/p>\n<\/td>\n<td width=\"85\" valign=\"top\">\n<p><a href=\"https:\/\/attack.mitre.org\/techniques\/T1027\">T1027<\/a><\/p>\n<\/td>\n<td width=\"227\" valign=\"top\" readability=\"5\">\n<p>Obfuscated Files or Information<\/p>\n<\/td>\n<td width=\"223\" valign=\"top\" readability=\"5\">\n<p>Portions of files are encoded to hide the plain-text strings<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5.4545454545455\">\n<td width=\"96\" valign=\"top\">\n<p>Execution<\/p>\n<\/td>\n<td width=\"85\" valign=\"top\">\n<p><a href=\"https:\/\/attack.mitre.org\/techniques\/T1059\/005\/\">T1059.005<\/a><\/p>\n<\/td>\n<td width=\"227\" valign=\"top\" readability=\"5\">\n<p>Command and Scripting Interpreter: Visual Basic<\/p>\n<\/td>\n<td width=\"223\" valign=\"top\" readability=\"5\">\n<p>Uses macros to execute payloads<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5.6197183098592\">\n<td width=\"96\" valign=\"top\">\n<p>Command and Control<\/p>\n<\/td>\n<td width=\"85\" valign=\"top\">\n<p><a href=\"https:\/\/attack.mitre.org\/techniques\/T1071\/001\/\">T1071.001<\/a><u><\/u><\/p>\n<\/td>\n<td width=\"227\" valign=\"top\" readability=\"5\">\n<p>Application Layer Protocol: Web Protocols<\/p>\n<\/td>\n<td width=\"223\" valign=\"top\" readability=\"5\">\n<p>Uses HTTP GET requests to contact the command-and-control (C&amp;C) server<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"2.7916666666667\">\n<td width=\"96\" valign=\"top\">\n<p>Exfiltration<\/p>\n<\/td>\n<td width=\"85\" valign=\"top\">\n<p><a href=\"https:\/\/attack.mitre.org\/techniques\/T1041\/\">T1041<\/a><\/p>\n<\/td>\n<td width=\"227\" valign=\"top\" readability=\"5\">\n<p>Exfiltration Over C2 Channel<\/p>\n<\/td>\n<td width=\"223\" valign=\"top\">\n<p>Sends data to C&amp;C server<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/a\/-dridex-targets-macos-using-new-entry-method.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Dridex variant we analyzed targets MacOS platforms with a new technique to deliver documents embedded with malicious macros to users. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":49993,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9508,9513,9509],"class_list":["post-49992","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-endpoints","tag-trend-micro-research-malware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Dridex Returns, Targets MacOS Using New Entry Method 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Dridex Returns, Targets MacOS Using New Entry Method 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-01-05T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/dridex-returns-macos-641.png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Dridex Returns, Targets MacOS Using New Entry Method\",\"datePublished\":\"2023-01-05T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/\"},\"wordCount\":1474,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/dridex-returns-targets-macos-using-new-entry-method.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Malware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/\",\"name\":\"Dridex Returns, Targets MacOS Using New Entry Method 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/dridex-returns-targets-macos-using-new-entry-method.png\",\"datePublished\":\"2023-01-05T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/dridex-returns-targets-macos-using-new-entry-method.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/dridex-returns-targets-macos-using-new-entry-method.png\",\"width\":1027,\"height\":567},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dridex-returns-targets-macos-using-new-entry-method\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Dridex Returns, Targets MacOS Using New Entry Method\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Dridex Returns, Targets MacOS Using New Entry Method 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/","og_locale":"en_US","og_type":"article","og_title":"Dridex Returns, Targets MacOS Using New Entry Method 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-01-05T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/dridex-returns-macos-641.png","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Dridex Returns, Targets MacOS Using New Entry Method","datePublished":"2023-01-05T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/"},"wordCount":1474,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/01\/dridex-returns-targets-macos-using-new-entry-method.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Endpoints","Trend Micro Research : Malware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/","url":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/","name":"Dridex Returns, Targets MacOS Using New Entry Method 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/01\/dridex-returns-targets-macos-using-new-entry-method.png","datePublished":"2023-01-05T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/01\/dridex-returns-targets-macos-using-new-entry-method.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/01\/dridex-returns-targets-macos-using-new-entry-method.png","width":1027,"height":567},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/dridex-returns-targets-macos-using-new-entry-method\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Dridex Returns, Targets MacOS Using New Entry Method"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49992","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=49992"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49992\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/49993"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=49992"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=49992"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=49992"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}