BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: macOS Doesn’t Get Malware…Until It Does\n   Tags
 : Red Team Village | Misc\n   When: Friday\, Aug 7\, 12:00 - 12:59 PDT\n  
  Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 -\n  
  [1]Map\n\n   Description:\n   Abstract:\n\n   macOS has long been perceiv
 ed as a low-risk platform\, often treated as\n   a secondary concern compa
 red to Windows and Linux. That assumption no\n   longer holds. As MacBooks
  become increasingly common in corporate\n   environments\, adversaries ha
 ve followed\, turning macOS into a viable\n   and attractive target for re
 al-world attacks.\n\n   This talk presents a practical\, research-driven a
 nalysis of the recent\n   evolution of macOS malware. Through hands-on exp
 eriments and real\n   techniques\, it explores how modern threats achieve 
 execution\, fileless\n   operation\, persistence\, and evasion by abusing 
 native macOS\n   components. The presentation also evaluates how widely ad
 opted to\n   macOS security tools respond\, and in many cases fail\, to de
 tect these\n   behaviors.\n\n   By walking through the attacker’s mindse
 t and development process\,\n   this session aims to expose a growing blin
 d spot in enterprise\n   security and challenge the outdated belief that 
 macOS doesn’t get\n   malware.”\n\n   Description:\n\n   As organiza
 tions continue to expand their macOS footprint\, security\n   strategies o
 ften lag behind. Many defensive teams remain heavily\n   focused on Window
 s and Linux\, leaving macOS environments\n   under-monitored\, under-teste
 d\, and misunderstood.\n\n   In this talk\, I will share my journey resear
 ching and developing macOS\n   malware from an adversarial perspective.\n\
 n   The session focuses on how attackers leverage legitimate macOS\n   mec
 hanisms to achieve:\n\n     * Initial execution and in-memory (fileless) t
 echniques\n\n     * Persistence through native system components\n\n     *
  Evasion of endpoint security and detection tools\n\n   Each technique is 
 demonstrated using real experiments\, with analysis\n   of macOS internals
  and the behavior of commonly deployed security\n   solutions. Rather than
  theoretical concepts\, the talk emphasizes how\n   these attacks work in 
 practice\, and why many defenses fail to stop\n   them.\n\n   The presenta
 tion also addresses a persistent myth\, especially common\n   in the Brazi
 lian security community\, that macOS is inherently safer or\n   “immune
  to malware. By examining real attack paths and defensive\n   gaps\, the
  session highlights the urgent need for improved detection\n   strategies\
 , visibility\, and threat modeling on macOS.\n\n   Attendees will learn:\n
 \n     * How modern malware abuses internal macOS mechanisms\n\n     * Rea
 l-world persistence techniques observed in active threats\n\n     * How se
 curity tools react or fail\, when faced with these attacks\n\n     * Pract
 ical Red Team techniques to identify weaknesses and evaluate\n       detec
 tion capabilities\n\n     * Practical mitigation strategies to reduce expo
 sure and improve\n       detection\n\n   This talk is intended for defende
 rs\, red teamers\, malware researchers\,\n   and anyone interested in unde
 rstanding how adversaries are actively\n   adapting to the macOS ecosystem
 .\n\n   About events where I've spoken:\n\n   Analyzing malicious PDFs - C
 onfraSec 2019 Reconnaissance vs\n   Vulnerability Analysis - OWASP-Vitoria
  2019 Red Team X Blue Team -\n   OWASP Latam 2020 Maldocs: an analysis of 
 malicious documents - Bsides\n   Vitoria 2022 LockBit and its tricks - Bsi
 des Vitoria 2023 LockBit and\n   its tricks - Bsides São Paulo 2023 LockB
 it and its tricks - HackBahia\n   2023 Ransomware: No one can stop this na
 ughty baby - Bsides Vitoria\n   2024 Ransomware: No one can stop this naug
 hty baby - Bsides São\n   Pauço 2024 Ransomware: No one can stop this na
 ughty baby - CajuSEC\n   2024 From Zero to Ransomware for MacOS - HackBahi
 a 2024 Ransomware vs\n   EDR: Inside the Attacker's Mind- BHack Conference
  2024 Ransomware vs\n   EDR: Inside the Attacker's Mind - Bsides Rio de Ja
 neiro 2025\n   Ransomware vs EDR: Inside the Attacker's Mind - Bsides São
  Paulo 2025\n   Ransomware vs EDR: Inside the Attacker's Mind - Bsides Vit
 oria 2025\n   Ransomware vs EDR: Inside the Attacker's Mind - CajuSEC 2025
 \n   Ransomware vs EDR: Inside the Attacker's Mind - Bsides Las Vegas\n   
 (backup speaker) Ransomware vs EDR: Inside the Attacker's Mind - Red\n   T
 eam Village - DEFCON 2025 Ransomware vs EDR: Inside the Attacker's\n   Min
 d - BxSec - 2025 Ransomware vs EDR: Inside the Attacker's Mind -\n   Malwe
 e Cyber Security Event Ransomware vs EDR: Inside the Attacker's\n   Mind -
  Online - BMW Group MacOS Malwares: Breaking Barriers - BHack\n   Conferen
 ce 2025 Ransomware vs EDR: Inside the Attacker's Mind - 307\n   Security C
 onference MacOS Malwares: Breaking Barriers - Ox3 Hacker\n   Conference 20
 26 Ransomware vs EDR: Inside the Attacker's Mind - Red\n   Team Village Ov
 erflow (Online) - DEFCON 2026\n\n   SpeakerBio:  Zoziel Freire\n\n   I hav
 e a degree in Information Systems and a postgraduate degree in\n   Forensi
 c Computing. With over 16 years of experience in the\n   information techn
 ology sector\, I have had the opportunity to provide\n   services to sever
 al companies across various segments in Brazil and\n   other countries.\n\
 n   Throughout my career\, I have acquired solid experience in Incident\n 
   Response\, Forensic Analysis\, Threat Hunting\, Pentester\, Malware\n   
 Analysis and Developer\, and Reverse Engineering. I have also worked on\n 
   Ransomware incidents\, both in Brazil and in other countries.\n\n   I ha
 ve actively contributed to the information security community\,\n   partic
 ipating in Brazilian events. Sometimes I spend time bypassing\n   EDR and 
 AntiVirus\, and testing operating system gaps. I am passionate\n   about m
 usic\, especially guitar and piano\, and I am a fan of Chaves and\n   Chap
 olin.\n\n   BSides Las Vegas – US – 2025 (Backup Speaker) – Ransomwa
 re vs\n   EDR: Inside the Attacker's Mind Red Team Village @ DEF CON – L
 as\n   Vegas\, US – 2025 – Ransomware vs EDR: Inside the Attacker's Mi
 nd\n   BMW Group – Online – 2025 – Ransomware vs EDR: Inside the\n  
  Attacker's Mind Red Team Village Overflow @ DEF CON – Online –\n   20
 26 – Ransomware vs EDR: Inside the Attacker's Mind\n\n   '\n\n   1. #LVC
 CW_Level1_Hall1\n\n\n
DTEND:20260807T195900Z
DTSTART:20260807T190000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 1
SUMMARY:macOS Doesn’t Get Malware…Until It Does
END:VEVENT
END:VCALENDAR
