Mostrando postagens com marcador Mac. Mostrar todas as postagens
Mostrando postagens com marcador Mac. Mostrar todas as postagens

sábado, 26 de janeiro de 2019

Attackers successfully hide Mac malware in ad images

By Waqas em 25/01/2019 no site Hack Head

Resultado de imagem para mac malware
MacBooster


Malware campaigns have become quite regular on Apple devices and as per the new report from Confiant, a cyber-security firm, there’s a new group on the block called that is specifically targeting Apple users through malvertising. The group called VeryMal has employed steganography techniquethis time to prevent detection and hide the malicious code in an advertisement’s images.

The campaign has been analyzed by both Confiant and Malwarebytes and the researchers believe that it has been active since January 11 and lasted until January 13. The infected ad was viewed over 5 million times during the time that it was active.
Ad viewers claim that the campaign involved a tried-and-tested tactic of displaying a notification that the user needs to update the Adobe Flash Player and to do this the user has to open a file to download the new version. Whoever accepted the download ended up running malware on their Mac and the device was infected with the Shlayer Trojan.
“As malvertizing detection continues to mature, sophisticated attackers are starting to learn that obvious methods of obfuscation are no longer getting the job done. Techniques like steganography are useful for smuggling payloads without relying on hex encoded strings or bulky lookup tables,” Confiant researcher Eliya Stein revealed.
It is a noteworthy attempt from VeryMal because usually, attackers find it difficult to evade the numerous protection layers of the ad networks and user desktops. But, VeryMal successfully hides the payload within the ad’s graphics file using steganography. The code can create a Canvas object, extract an image file from a certain URL, and create a function to check if the browser supports a particular font.
Attackers successfully hide Mac malware in ad images
The results of payload executed by the advertising-based malware attack
In case the font check fails, the campaign won’t work, but if it is successful then the image file’s underlying data is looped through and each loop determines a pixel value that later becomes an alphanumeric character. The character is later converted into a string and executed.
However, despite harboring the payload, the image is harmless itself if someone views it and only becomes harmful when the malicious code is executed and the browser is redirected to a link containing the payload.
Mac users are urged to remain alert and don’t pay heed to all the online notifications that they see on their desktop screens because it may be a part of malvertising campaign. They should specifically be wary of notices that ask users to install software updates and provide an unofficial link for the download.
What happens in steganography is that hackers extract the file and hide malicious code in image’s User Comment EXIF metadata field.
This is not the first time that hackers have used steganography technique to drop malware. Just last month, researchers discovered two memes hiding commands in their metadata with the help of steganography spreading malware on Twitter. 
In another attack, malicious images were hosted on GoogleUserContent CDN using steganography, however, what’s shocking is that these attacks are not limited to computer users. Back in 2016, steganography was also used for deploying over 60 malicious applications on Play Store.

quarta-feira, 25 de outubro de 2017

Hackers infect Mac users with Proton malware using Elmedia Player

By Waqas on 
The general concept regarding Apple devices is that they are secure from growing number of malware and other cyber attacks, but the reality is far from the truth. In the latest campaign, cybercriminals have infected hundreds of Mac users by distributing Proton malware by compromising Elmedia Player software.
According to IT security researchers at ESET, this happened when attackers infected the free version of Elmedia Player downloaded file available on its developer’s site Eltima with Proton malware that was then downloaded by Mac users without triggering any warning.
Proton malware was first discovered this year on the Dark Web being sold for just 40 BTC (USD 41891 at the time of sale). Proton is capable taking full control of a targeted device, keylogging, Observers with SMS notifications, SSH/VNC tunneling with VPS, webcam/screen surveillance, premium customer support, file uploadings, and downloads.
Other than Elmedia, attackers also infected Folx download manager with the same malware. In a blog post, Eltima has acknowledged the attack and stated that:
“On the 19th of October 2017 we were informed by a malware research company ESET that our servers have been hacked and our apps namely Folx and Elmedia Player DMG files are distributed with a malware.”
[…] 
“Only Elmedia Player and Folx version downloaded from our official Eltima website was infected by this malware. However, the built-in automatic update mechanism is unaffected based on the data available to our cybersecurity experts.”
Those who downloaded Elmedia Player or Folx on 19th of October 2017, their system is likely to be infected with Proton malware. Another bad news is that the only way out is a full OS reinstall. However, the good news is that Apple has already revoked misused Clifton Grimm certificate. To verify if your system is infected, follow these steps:
/tmp/Updater.app/
/Library/LaunchAgents/com.Eltima.UpdaterAgent.plist
/Library/.rand/
/Library/.rand/updateragent.app/
The same malware was distributed by cybercriminals through Handbrake Mirror after compromising its server in May this year. Also, a similar incident took place last month in which hackers infected over two million users with a backdoor who downloaded 5.33 Version of CCleaner, a subsidiary of anti-virus giant Avast and security software for Windows.
Mac users are highly advised not to download software and apps from third-party sites and avoid using unnecessary apps. Remember, Former National Security Agency (NSA) chief Michael Hayden and his wife were in an Apple store in Virginia, Hayden said at a conference that salesman approached and raved about the iPhone, saying that there were already “400,000 apps” for the device. Hayden, amused, turned to his wife and quietly asked: “This kid doesn’t know who I am, does he? Four-hundred-thousand apps mean 400,000 possibilities for attacks.”

quarta-feira, 26 de julho de 2017

Apple Users, Beware! A Nearly-Undetectable Malware Targeting Mac Computers

Swati Khandelwal
Em 24/07/2017 no site The Hacker News

macos-malware-fruitfly
Yes, even Mac could also get viruses that could silently spy on its users. So, if you own a Mac and think you are immune to malware, you are wrong.

An unusual piece of malware that can remotely take control of webcams, screen, mouse, keyboards, and install additional malicious software has been infecting hundreds of Mac computers for more than five years—and it was detected just a few months back.

Dubbed FruitFly, the Mac malware was initially detected earlier this year by Malwarebytes researcher Thomas Reed, and Apple quickly released security patches to address the dangerous malware.

Now months later, Patrick Wardle, an ex-NSA hacker and now chief security researcher at security firm Synack, discovered around 400 Mac computers infected with the newer strain of the FruitFly malware (FruitFly 2) in the wild.

Wardle believes the number of infected Macs with FruitFly 2 would likely be much higher, as he only had access to some servers used to control FruitFly.

Although it is unknown who is behind FruitFly or how the malware gets into Mac computers, the researchers believe the nasty malware has been active for around ten years, as some of its code dates back to as far as 1998.
"FruitFly, the first OS X/macOS malware of 2017, is a rather intriguing specimen. Selectively targeting biomedical research institutions, it is thought to have flown under the radar for many years," Wardle wrote in the abstract of his talk, which he is going to present at the Black Hat later this week.
Since the initial infection vector for FruitFly is unclear, like most malware, Fruitfly could likely infect Macs either through an infected website delivering the infection or via phishing emails or a booby-trapped application.

FruitFly is surveillance malware that's capable of executing shell commands, moving and clicking a mouse cursor, capturing webcam, killing processes, grabbing the system's uptime, retrieving screen captures, and even alerting the hacker when victims are again active on their Mac.
"The only reason I can think of that this malware has not been spotted before now is that it is being used in very tightly targeted attacks, limiting its exposure," Reed wrote in the January blog post. 
"Although there is no evidence at this point linking this malware to a specific group, the fact that it has been seen specifically at biomedical research institutions certainly seems like it could be the result of exactly that kind of espionage."
Wardle was able to uncover FruitFly victims after registering a backup command and control (C&C) server that was once used by the attacker. He then noticed around 400 Mac users infected with FruitFly started connecting to that server.

From there, the researcher was also able to see IP addresses of FruitFly infected victims, indicating 90 percent of victims were located in the United States.

Wardle was even able to see the name of victims' Macs as well, making it "really easy to pretty accurately say who is getting infected," he told Forbes.

But rather than taking over those computers or spying on the victims, Wardle contacted law enforcement and handed over what he found to law enforcement agents, who are now investigating the matter.

Wardle believes surveillance was the primary purpose of FruitFly, though it is yet unclear whether it is government or other hacker groups.
"This did not look like cyber crime type behaviour; there were no ads, no keyloggers, or ransomware," Wardle said. "Its features had looked like they were actions that would support interactivity—it had the ability to alert the attacker when users were active on the computer, it could simulate mouse clicks and keyboard events."
Since the Fruitfly's code even includes Linux shell commands, the malware would work just fine on Linux operating system. So, it would not come as a surprise if a Linux variant of Fruitfly was in operation.