Automated Payload Recovery and Tactic Detection Across macOS Active Families
macOS has become a primary target for credential theft and enterprise compromise.
In 2024–2025, Malware-as-a-Service platforms accelerated the problem: AMOS distributed new Mach-O builds continuously, each with a rotated encryption scheme and no shared key material; Adaptix shipped pure-Go implants with interactive remote shell capabilities; a SwiftUI-based credential stealer embedded native password-capture dialogs; a Go binary bridged directly into the Objective-C runtime for keychain access; and additional families carried forward legacy cipher implementations from older codebases. Threat actors deliberately diversified across implementation languages — Go, Rust, Swift, compiled scripting bridges — specifically to stay ahead of signature-based detection. Each produces a structurally different Mach-O binary. Static analysis alone cannot catch all of them; detection must generalise across techniques, not just individual builds.
This talk presents two complementary research pipelines developed in response to this diversification.
The first is a static payload extraction pipeline built around the AMOS family as the primary case study. AMOS encrypts its AppleScript stealer payload differently in every build — no hardcoded constants, no shared key material. Over 18 months of collection, multiple distinct cipher architectures were identified across the family. The pipeline eliminates per-variant manual reverse engineering by combining Radare2 structural analysis — import profiling, section layout, byte-pattern scanning — with LLM-assisted cipher identification from decompiler output. The majority of architectures are fully decoded statically; variants that seed cipher parameters at runtime are addressed via targeted Unicorn emulation scoped to the cipher initialisation routine, with no full sandbox or network access required. Decoded payloads feed an automated IOC extraction stage that surfaces C2 infrastructure, persistence mechanisms, and data exfiltration targets as structured output. The same pipeline, with only new decoder modules, successfully recovers payloads from additional infostealer families — demonstrating it is family-agnostic.
The second pipeline addresses detection at the technique level. Systematic coverage analysis across active macOS families revealed gaps that traced to detection logic bound to family-specific implementation details rather than to the underlying techniques of those implementations expressed. The findings drove a set of technique-level detection signals: system-level API patterns that identify interactive remote shell behaviour regardless of language or framework, a binary marker in SwiftUI-based tools that flags native password-capture dialogs, Go library path scoring that identifies offensive toolkit choices without naming specific families, and detection of Go binaries that directly invoke the Objective-C runtime — a structural combination with no legitimate use in non-trivial macOS applications. Each signal fires on future variants of the same technique without requiring updates.
The two pipelines address different stages of the defender’s problem: the decoder pipeline surfaces intelligence from samples already collected; the detection engineering work ensures future variants are caught before coverage gaps accumulate. Together they represent a systematic approach to the macOS threat ecosystem that does not require per-sample manual reverse engineering or per-family custom detection work.
Attendees will leave with a concrete methodology for stratified corpus sampling, automated cipher identification, and decoder construction; an understanding of how to design detection signals at the technique level so they generalise across family variants; and a practical pattern for expanding detection coverage across a diversifying threat landscape.
Key Takeaways
- Kill the manual RE grind: Radare2 + LLM pipeline automates cipher recovery across both static and runtime-seeded variants — no sandbox, no commercial tooling required
- Future-proof your detection: move beyond family-specific signatures to high-fidelity technique signals — native password-capture markers, Go library path scoring, ObjC-bridge detection — that automatically flag future variants
- Scale across implementation diversity: modular, family-agnostic architecture cuts through language-level noise (Go, Rust, Swift) to focus on the underlying malicious tradecraft

Rajesh Nikam – CrowdStrike
Rajesh Nikam is a Principal Threat Research Engineer at CrowdStrike’s Malware Research Center, with 20+ years of experience in Malware Research, Endpoint Protection, and Machine Learning. At CrowdStrike, he focuses on improving Detection Coverage for Windows, macOS, and Linux through ML models, corpus development, and model evaluation methodologies—with a growing focus on AI-assisted reverse engineering and feature engineering.
Previously, Rajesh held leadership roles at Microsoft (Principal Researcher Lead), Qualys and Quick Heal (Senior Manager, Malware Research), and Symantec (Senior Security Researcher). He has presented at AVAR and c0c0n, and is proud to contribute to CrowdStrike’s mission to stop breaches and Secure AI through continuous innovation.