A Better Way, YARA-X, Mach-O Feature Extraction, and Malware Similarity
2024-12-06 • Proofpoint •
The excerpt describes research into improving similarity analysis for macOS Mach-O malware, where analysts often lack easy pivots comparable to Windows import hashes or Rich Header artifacts. The work led to Mach-O feature extraction in YARA-X, supported by a Rust Mach-O parser built for the project. The talk uses APT Mach-O families to demonstrate how these features can help analysts find related samples beyond simple string searches. The North Korea relevance is limited to the speaker’s threat research focus on tracking and disrupting malicious activity linked to North Korea and Russia, rather than a specific campaign or malware family in the excerpt.