Black Hat Europe 2025 | Silence On macOS: What 70K Binaries Reveal About The macOS Malware Ecosystem
macOS adoption in enterprise environments has surged in recent years, yet defensive tooling and public research still center heavily on Windows threats, leaving macOS malware underrepresented. To help bridge this gap, we introduce MALET, the largest public dataset of macOS malware to date (48.4k malicious / 22.9k benign Mach-O binaries), and Katalina, a new, open-source, high-performance static analysis tool capable of processing thousands of binaries per minute on commodity hardware. Our talk distills 18 months of measurement into actionable insights for malware analysts, detection engineers, and incident responders. We show how 96% of macOS malware remains unsigned, and of the signed remainder, 38% use certificates that were later revoked often tied to DPRK APT infrastructure. These binaries evaded Gatekeeper and persisted for up to 721 days before revocation. We surface 185 previously misclassified binaries that AV engines labeled benign despite sharing structural fingerprints with known malware. Static clustering using UUIDs, TeamIDs, and symbol hashes reveals four dominant macOS malware archetypes. We also show how rare entitlement combinations (e.g., com.apple.private.tcc.allow) appear 25x more often in malware, enabling stealth access to sensitive hardware like the microphone and camera. We demonstrate how these findings can directly feed into resilient detection pipelines, including Sigma/YARA rule generation, a live triage workflow, and an extensible open-source toolchain. Attendees will leave with data, tooling, and practical heuristics they can apply immediately in their own environments. By: Obinna Igbe | Independent Researcher, Godwin Attigah | Security Engineer, Airbnb https://blackhat.com/eu-25/briefings/...

Black Hat Europe 2025 | Ghosts in the Stream: Exposing Lives and Devices Behind Encrypted Doors

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Phishing For Patterns: What Happens When Agents Explore Domain Data - Beni Urech & Patrick Schläpfer

Black Hat Europe 2025 | Pickle Exploitation Techniques And Their Detection Using SaferPickle

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

Using Large Language Models | Build Your Own LLM Workshop #1

The Obsessive Engineering of Precision Linear Motion

The Database That Should Be Dead but Runs the Internet

Android 17 sucks. So I put Linux on a phone.

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup

Chip design from the bottom up – Reiner Pope

Attacking AI - Jason Haddix - NDC Security 2026

World's Deadliest Computer Virus: WannaCry

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

The Honey Scam is Worse Than I Thought

Co-Creator of Haskell: Functional Programming, Thinking in Types, Useless Languages | Simon Jones

Black Hat Europe 2025 | Habemus Securitas - Exploring Apple's Hidden Territories

Edward Snowden Reveals How They Spy on You

The Truth about Space Data Centers

