Packing Malware in Rosetta 2
Summary
Packing Malware in Rosetta 2 is a security-focused exploration of how Rosetta 2's ahead-of-time and just-in-time translation, dynamic linking, and macOS security features can be leveraged (or abused) to load and execute code across architectures. The article covers attack surfaces, interposing techniques, and practical examples (including gamehacking and unsigned libraries), with notes on potential detection and defensive considerations and references to related incidents.