AV-Monster is a proof-of-concept macOS/OS X kernel extension designed to disable or bypass anti-virus products that rely on Apple’s Kauth authorization interface. It targets anti-virus kernel modules responsible for forwarding file events to userland scanning engines, locating those modules in kernel memory and patching their Kauth listener callbacks so they return values such as KAUTH_RESULT_DEFER, thereby preventing files from being sent for scanning. The content also notes an older implementation that disabled the listener callback by replacing it with NOP instructions, and describes the possibility of more selective, stealthier bypasses.
According to the content, AV-Monster works by iterating the kmod_info_t linked list to find target anti-virus kernel modules, hashing module names and comparing them to precomputed hashes, parsing the target module’s Mach-O header, and identifying references to the strings "com.apple.kauth.fileop" and "com.apple.kauth.vnode" to recover listener callback addresses. Patching involves saving original bytes, disabling kernel write protection and interrupts, modifying the callback, and restoring protections. The content states that the modified anti-virus binaries continue running after patching and that products could be patched both at runtime and on disk.
The PoC is described as having been tested on Snow Leopard 10.6.8 and Lion 10.7.3 against multiple Mac anti-virus vendors, including Intego, Avast, Comodo, ESET, Kaspersky, McAfee, Panda, Sophos, Dr Web, BitDefender, Mac Keeper, and F-Secure, with the author asserting that many other Mac anti-virus products were likely similarly vulnerable. The weakness is attributed to anti-virus designs that depend on Kauth listeners as a single point of failure and, per the content, lacked even simple checksum verification of their own binaries. One vendor reportedly detected this specific AV-Monster implementation after prior disclosure.
High-confidence indicators and artifacts mentioned in the content include the strings "com.apple.kauth.fileop" and "com.apple.kauth.vnode", and the SHA-256 hash for av-monster_v0.2.zip: 554943e9f5d90e65f22d904c96526819ffe4348f391c8c0b8865b797abb490a2. The content attributes AV-Monster to public offensive research by fG! and describes it as an old February 2012 PoC rather than a named in-the-wild malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A proof-of-concept targeting the Kauth interface used by OS X antivirus solutions to bypass or disrupt scanning.
A proof-of-concept OS X rootkit-style tool that exploits the Kauth interface used by antivirus products to bypass file scanning by patching or hijacking listener callbacks and hiding selected files from AV visibility.
A macOS kernel extension proof-of-concept designed to locate anti-virus kernel modules and patch or hijack their KAUTH listener callbacks, effectively disabling or selectively bypassing on-access scanning.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.