A trojanized DMG distributing a pirated copy of the legitimate macOS text and hex editor UltraEdit was modified to load an unsigned third-party library, libConfigurer64.dylib. The library operates as a dropper, downloading and executing concealed payloads including a Khepri backdoor placed at /private/tmp/.test.
A second component at /Users/Shared/.fseventsd provides downloader and persistence functionality by installing a masqueraded macOS launch agent and retrieving an additional hidden payload into a temporary directory. Defenders should investigate unsigned dylib loads by trusted applications, network or execution activity from hidden binaries, suspicious launch-agent creation, and hidden Mach-O files in atypical directories.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Malwrhunterteam posted about a pirated macOS application with malicious capabilities. Subsequent analysis linked the activity to a trojanized version of the UltraEdit editor.
Patrick Wardle reported that the malicious application deployed second- and third-stage payloads, while JAMF Threat Labs identified and analyzed additional related samples.
A pirated UltraEdit DMG was altered to load the unsigned libConfigurer64.dylib dropper, which downloaded hidden payloads including a Khepri backdoor at /private/tmp/.test. A second component at /Users/Shared/.fseventsd established launch-agent persistence and downloaded another hidden payload into /tmp/.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.