Confiant researchers have discovered a new Mac malware dubbed Tarmac distributed via malvertising campaigns in the US, Italy, and Japan. Malware authors use to sign malware with Apple developer certificates because it is easy to do and allow their code to bypass security protections like Gatekeeper and XProtect. Malvertising campaign distributing the two malware Shlayer and Tarmac began in January, but at the time experts did not spot the Tarmac malicious code. At the time of the analysis, it was not possible to understand which commands the malware supports because the C&C servers were down.”]
Source: https://securityaffairs.co/wordpress/92441/malware/mac-malware-tarmac.html

