Vigram

Aliases: WizardUpdate

Malware type
downloader
Family
Malware family
Profile updated
2026-07-07 14:03:15

Context

Vigram, also known as WizardUpdate, is a malware family primarily targeting macOS systems. It is a downloader malware that masquerades as a software update platform to deploy additional malicious payloads.

Detection coverage

  • 1 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_OSX_Wizardupdate_Oct_2021_1 (yara-rule)

Reports & references

  • sentinelone.com — The Art And Science Of Macos Malware Hunting With Radare2 Leveraging Xrefs Yara And Zignatures (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Vigram (report)
  • twitter.com — 1451279679059488773 (report)
  • twitter.com — 1351559054565535745 (report)

External references