Attackers compromised a prominent Georgian news website and used its Georgian-language pages as a watering hole to selectively infect macOS visitors. Malicious JavaScript profiled users by operating system, browser, and prior visits, then redirected qualifying Safari users to an attacker-controlled fake Adobe Flash update that delivered a signed macOS application, GetFlashPlayer.app. The malware established persistence with a LaunchAgent, opened the legitimate Adobe Flash website as a decoy, and communicated with command-and-control infrastructure over TCP port 7777.
Volexity identified the payload as a newer variant of OSX/Leverage.A, a macOS backdoor that expanded beyond earlier versions by providing unrestricted shell access. Reporting on the malware family and related analysis highlighted code-signing details, file hashes, network indicators, and host- and network-based detection opportunities, giving defenders concrete artifacts to hunt for on potentially exposed Apple systems.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Volexity reported that attackers had breached a respected Georgian media outlet and used the Georgian-language section to selectively target Safari users on Mac OS X with a fake Adobe Flash update flow. The report detailed the infection chain, persistence via a LaunchAgent, command-and-control traffic to downloadarchives.servehttp[.]com on TCP port 7777, and assessed the payload as a newer OSX/Leverage.A variant with unrestricted shell access.
ESET published reporting on the Stantinko adware campaign, describing it as operating covertly since 2012. Volexity later noted one IP overlap with an ESET Stantinko report but said it was unaware of any tie between the macOS activity and Stantinko.
The macOS malware sample used in the campaign was digitally signed with an Apple Developer certificate for "aleks papandopulo." The code-signing metadata carried a timestamp of February 5, 2016, 06:25:25.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
volexity.com
Open sourcewelivesecurity.com
Open sourcealienvault.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.