Threats Tagged 'bash'
View all threats tagged with 'bash'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bash'
Click on any threat for detailed analysis and mitigation recommendations
NovaStealer is a macOS-targeting cryptostealer malware that uses bash scripts to establish persistence and execute malicious modules. It installs itself in the ~/. mdrivers directory, uses screen sessions for stealthy background execution, and employs LaunchAgents to maintain persistence. The malware exfiltrates cryptocurrency wallet data, collects system information, and replaces legitimate wallet applications with malicious versions. It also uses WebKit to render phishing pages and tracks user behavior to increase effectiveness. While not highly sophisticated, its modular design allows remote updates, making it adaptable and persistent. The malware does not require prior authentication but relies on user interaction for initial infection, such as phishing. There are no known exploits in the wild yet, but the threat is notable due to its focus on valuable crypto assets on macOS systems. Join the discussion | AlienVault OTX General | 11/14/2025, 12:04:55 UTC Added: 11/14/2025, 12:31:21 UTC |
Showing 1 to 1 of 1 result