VideoGAMESCanada.ca:
 


 
NEWSLETTER:
Email:

News

New Mac OS X Backdoor Being Used for an Advanced Persistent Threat Campaign

Kaspersky Lab’s experts have intercepted a new wave of Mac OS X attacks targeting Uyghur activists that were part of an Advanced Persistent Threat (APT) campaign.

The APT attackers were sending customised emails to a select number of Uyghur activists who were presumed Mac users. The targeted emails included ZIP attachments inside them, which contained a malicious Mac OS X backdoor. To disguise the malware, the ZIP file showed a JPEG photo together with the malicious application.

Kaspersky Lab’s researchers analysed the Mac OS X backdoor and concluded that the malicious application is a new, and primarily undetected, variant of the MaControl backdoor, which supports both i386 and PowerPC Macs. However, Kaspersky Lab’s system detects the malicious variant as “Backdoor.OSX.MaControl.b.”

When executed, the MaControl backdoor installs itself inside the victim’s Mac and connects to its Command and Control (C&C) server to get instructions. The backdoor allows its operator to list files, transfer files and generally run commands on the infected Mac computer at will. During the analysis of the malware, Kaspersky Lab identified its C&C server, which is located in China.

“Macs are growing in global popularity, even amongst high-profile people. Many choose to use Mac OS X computers because they believe it’s safer,” said Costin Raiu, Director of Global Research & Analysis at Kaspersky Lab. “However, we believe that as the adoption increases for Mac OS X, so will both mass-infection attacks and targeted campaigns. Attackers will continue to refine and enhance their methods to mix exploits and social engineering techniques to try and infect victims. Just like PC malware, this combination is commonly the most effective and cybercriminals will continue to challenge Mac OS X users’ security, both technically and psychologically.”

This is not the first time Kaspersky Lab has identified APT-driven attacks targeting Mac OS X users. In April 2012, Kaspersky Lab’s researchers published information about an active APT campaign, SabPub, which was attacking the Mac OS X platform by exploiting an MS Office vulnerability. Once the custom backdoor Trojan infected a victim’s machine, it was able to take screenshots of the user’s current session and execute commands on the infected computer.

Even though the notorious Flashfake Trojan, which helped to create a botnet of 700k+ Mac computers, was the most prominent example of Mac OS X infections, cybercriminals have continued to attack the platform, most notably in targeted campaigns. Several days ago, Apple pulled a claim from their website which said that “a Mac isn’t susceptible to the thousands of viruses plaguing Windows-based computers.”

The Mac OS X security landscape continues to change in 2012 as cybercriminals target the platform with various types of techniques and methods.

 [July 4, 2012]


Send this IT news to a friend
Recipient :
(enter the e-mail address of the recipient)

From 
(enter your name)

(enter your e-mail address)

 

Other IT news about Kaspersky

  • Laptops, Tablets and Smartphones Top Online Poll of Items UK Adults Would Save if Their Home Was on Fire (September 24, 2012)
  • Double Triumph for Kaspersky Lab in AV-Test.org independent Tests (September 20, 2012)
  • Kaspersky Lab Publishes New Research on Destructive Malware, Wiper (August 31, 2012)
  • Kaspersky Lab’s New “Safe Money” Technology Protects Online Purchases (August 24, 2012)
  • Android Under Attack: Malware Levels for Google’s OS Rise Threefold in Q2 2012 (August 16, 2012)
  • UK Consumers Lax With Online Financial Security (August 13, 2012)
  • Kaspersky Lab and Seculert Announce ‘Madi’, a Newly Discovered Cyber-Espionage Campaign in the Middle East (July 18, 2012)
  • Kaspersky Lab Partners with The Dark Knight Rises to Launch the Ultimate Batman Sweepstakes (July 3, 2012)
  • Resource 207: Kaspersky Lab Research proves that Stuxnet and Flame developers are connected (June 13, 2012)
  • Kaspersky lab ends year with winning streak of comparative test victories (February 13, 2012)
  • Kaspersky Lab named a "Leader" in Magic Quadrant for endpoint protection platforms (January 26, 2012)
  • British explorer becomes first woman to cross Antarctica alone (January 24, 2012)
  • Kaspersky Lab wins product of the year in AV-comparatives’ annual awards (January 16, 2012)
  • AV-Test Once Again Confirms Superiority of Kaspersky Endpoint Security 8 for Windows (December 8, 2011)
  • Brand New Kaspersky Lab Virus Scanner Now Available in Mac App Store (December 5, 2011)
  • The Kaspersky ONE Transantarctic Expedition: Follow Felicity Aston and win a Sony Tablet protected by Kaspersky Tablet Security (November 30, 2011)
  • Kaspersky Lab Expands Its Partnership with Scuderia Ferrari (November 25, 2011)
  • Kaspersky Lab Announces the Start of Felicity Aston’s Kaspersky ONE Transantarctic Expedition (November 25, 2011)
  • Kaspersky Lab announces enhanced Partner Programme for existing and new partners (November 15, 2011)
  • Kaspersky Lab Announces New Partnership with TAG Heuer (November 11, 2011)
  • Kaspersky Endpoint Security 8 for Windows Provides Best Endpoint Control Functionality in Independent Testing (November 3, 2011)
  • Kaspersky Anti-Virus 2011 for Mac is fully compatible with new Mac OS X Lion operating system (August 1, 2011)
  •  

    Website based on SPIP, an Open Source program under GNU/GPL licence
    GADGETS: