Categories: Malware

Running OSX relatively safe? New Malware strains targeting all versions of MacOSX clients

People regularly anticipate that in case you’re strolling OSX, you’re highly secure from malware. But that is turning into much less and less real, as evidenced via brand new strain of malware encountered with the aid of the Check Point research team.

Checkpoint said This new malware – dubbed OSX/Dok — influences all versions of OSX, has zero detections on VirusTotal (as of the writing of these words), is signed with a legitimate developer certificate (authenticated by means of Apple), and is the primary fundamental scale malware to target OSX users thru a coordinated email phishing campaign.

The Malware strain discovered by checkpoint researchers targeting OSX users mostly in European countries.

For instance, one phishing message turned into determined to target a person in Germany by using baiting the user with a message regarding supposed inconsistencies of their tax returns (see image, and translation, under).

Source: checkpoint
Attackers get whole access to all information exchange, such as communique encrypted by means of SSL. This is done by means of redirecting victim traffic thru a malicious proxy server.

Malware Execution

The malware package consists of a.Zip archive named Dokument.Zip. It became signed on April 21th, 2017 via a “Seven Muller” and the package name is Truesteer.AppStore.

Once executed it moves to Users/Shared/ folder and then ready to execute from different locations.

Source: checkpoint

It will show a message the package is damaged and cannot execute.If a loginItem named “AppStore” exists, the malware will delete it, and as a substitute add itself as a loginItem, to be able to persist within the device and execute routinely each time the device reboots.

It will do the same process until payload installation successfully completed.And then it will pop up a window asking to update and try to get user’s credentials.

The victim is barred from gaining access to any windows or the usage of their system in any manner until they relent, enter the password and permit the malware to finish installing.

Then it will install additional tools like TOR(used to connect dark web) and SOCAT(multipurpose relay).

The malware then modifies the victim machine’s network settings such that every one outgoing connection will bypass thru a proxy, that is dynamically acquired from a Proxy AutoConfiguration (PAC) document sitting on a malicious server.

Then after that, it will install a bogus certificate on the victim machine to launch an MITM attack to impersonate any websites.

security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/cert.der

Source: checkpoint

Launch Agents

/Users/training/Library/LaunchAgents/com.apple.Safari.proxy.plist
/Users/training/Library/LaunchAgents/com.apple.Safari.proxy.pac

As an end result of all of the above actions, whilst trying to surf the net, the consumer’s web browser will first ask the attacker web page on TOR for proxy settings.

The consumer traffic is then redirected through a proxy managed via the attacker, who consists of out a Man-In-the-Middle assault and impersonates the diverse websites the user tries to surf.

The attacker is free to study the victim’s visitors and tamper with it in any way they like.When achieved, the malware will delete itself.

Checkpoint alerts users to beware of Trojans bearing gifts, especially if they ask for your root password. Sample hash – 7819ae7d72fa045baa77e9c8e063a69df439146b27f9c3bb10aef52dcc77c1454131d4737fe8dfe66d407bfd0a0df18a4a77b89347471cc012da8efc93c661a5

Also Read

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

View Comments

  • The sample purports to originate from the Swiss tax authorities, not Germany. The text is is badly written: there are missing diacritcs simulated by double quotes, and only the first sentence has a resemblance to real German. The rest is gabbledigook composed from standard terms and conditions collected online.

    At any rate, I had to help an unfortunate victim by advising him to do a complete restore from a time machine backup before the infection. Even well educated people seem to be prone to ignore warning signs when expect trouble from the tax authorities.

    What I wonder though is if the certificates has already been revoked and how one could get Apple and Comodo to do this as fast as possible?

Recent Posts

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a disguised…

1 day ago

New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers

Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated attack…

1 day ago

NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern

The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms in…

1 day ago

Palo Alto Networks Vulnerability Puts Firewalls at Risk of DoS Attacks

A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo Alto…

1 day ago

Araneida Scanner – Hackers Using Cracked Version Of Acunetix Vulnerability Scanner

Threat Analysts have reported alarming findings about the "Araneida Scanner," a malicious tool allegedly based…

2 days ago

A Dark Web Operation Acquiring KYC Details TO Bypass Identity Verification Systems

A major dark web operation dedicated to circumventing KYC (Know Your Customer) procedures, which involves…

2 days ago