Writing Bad @$$ Malware For OS X
by Patrick Wardle In comparison to Windows malware, known OS X threats are really quite lame. As an Apple user that has drank the 'Apple Juice,' I didn't think that was fair! From novel persistence techniques, to native OS X components that can be abused to thwart analysis, this talk will detail exactly how to create elegant, bad@ss OS X malware. And since detection is often a death knell for malware, the talk will also show how OS X's native malware mitigations and 3rd-party security tools were bypassed. For example I'll detail how Gatekeeper was remotely bypassed to allow unsigned download code to be executed, how Apple's 'rootpipe' patch was side-stepped to gain root on a fully patched system, and how all popular 3rd-party AV and personal firewall products were generically bypassed by my simple proof-of-concept malware. However, don't throw out your Macs just yet! The talk will conclude by presenting several free security tools that can generically detect or even prevent advanced OS X threats. Armed with such tools, we'll ensure that our computers are better protected against both current and future OS X malware. So unless you work for Apple, come learn how to take your OS X malware skills to the next level and better secure your Mac at the same time!

Red Vs. Blue: Modern Active Directory Attacks, Detection, And Protection

The Memory Sinkhole - Unleashing An X86 Design Flaw Allowing Universal Privilege Escalation

DEF CON 31 - Demystifying (& Bypassing) macOS's Background Task Management - Patrick Wardle

How Smartcard Payment Systems Fail

Broadpwn: Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets

World's Deadliest Computer Virus: WannaCry

How to Disappear Online and Become Untraceable

DEF CON 25 - Patrick Wardle - Offensive Malware Analysis: Dissecting OSX FruitFly

How Your Phone is Tracked in 2026 – And How to Stop It

Every Level of Reverse Engineering Explained

DRAMA: How Your DRAM Becomes a Security Problem

DEFCON 19: Steal Everything, Kill Everyone, Cause Total Financial Ruin! (w speaker)

S13 E15: Iran, FIFA & UK Elections: 6/14/26: Last Week Tonight with John Oliver

Passkeys Explained: Are They Actually Better Than Passwords?

American Reacts to The Final Heute Show (WM⚽)

slink: WAF: Wrong Approach Firewall

Can a PDF File be Malware?

DEF CON 23 - Patrick Wardle - DLL Hijacking on OS X

Defcon 21 - How my Botnet Purchased Millions of Dollars in Cars and Defeated the Russian Hackers

