Skip to content
Brewing Trouble: Homebrew Spoofed Sites on the Rise
Adam Kohler & Christopher Lopez

5 min read

Brewing Trouble: Homebrew Spoofed Sites on the Rise

In September 2025, Iru's security researchers identified multiple spoofed Homebrew installer sites designed to mimic the official brew.sh page. These replicas injected malicious payloads under the guise of a standard install. In this post, we examine the tactics, infrastructure, and impact of the campaign.

Threat Intelligence
Threat Detected: RustyPages Malware - Part I
Adam Kohler & Christopher Lopez

6 min read

Threat Detected: RustyPages Malware - Part I

Threat Intelligence
It’s About The Journey: Fake Cloudflare Authenticator
Adam Kohler & Christopher Lopez

23 min read

It’s About The Journey: Fake Cloudflare Authenticator

Threat Intelligence

Update: Cuckoo Malware Evolves
Adam Kohler & Christopher Lopez

5 min read

Update: Cuckoo Malware Evolves

Since our initial report about the Cuckoo malware, there have been some updates to its functionality and infection vector that we wanted to let the Apple security community know about.

Threat Intelligence
Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware
Adam Kohler & Christopher Lopez

28 min read

Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware

On April 24, 2024, we found a previously undetected malicious Mach-O binary programmed to behave like a cross between spyware and an infostealer. We have named the malware Cuckoo, after the bird that lays its eggs in the nests of other birds and steals the host's resources for the gain of its young.

Threat Intelligence
CloudChat Infostealer: How It Works, What It Does
Adam Kohler & Christopher Lopez

11 min read

CloudChat Infostealer: How It Works, What It Does

On April 3, 2024, we came across an undetected file that had been uploaded to the online virus-checker VirusTotal that day named Clip. Right off the bat, we noticed that the file had some red flags that warranted further investigation.

Threat Intelligence

Stay up to date

Iru's weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.