SYMBOLCOMMON_NAMEaka. SYNONYMS
osx.pureland (Back to overview)

Pureland


According to SentinelOne, this is an infostealer, targeting among other things the encrypted database of Zoom.

References
2024-04-02SentinelOnePhil Stokes
Session Cookies, Keychains, SSH Keys and More | 7 Kinds of Data Malware Steals from macOS Users
EggShell RAT KeySteal Pureland

There is no Yara-Signature yet.