Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

June 29th, 2012, 12:47 GMT · By

BLOG

APT Attacks Rely on New Mac OS X Backdoor to Target Uyghur Activists

SHARE:

Adjust text size:


Uyghur activists threatened by new Mac OS X backdoor Enlarge picture - Uyghur activists threatened by new Mac OS X backdoor
Kaspersky specialists have come across a new version of the Mac OS X MaControl backdoor, which is designed to allow attackers to steal files and run commands on infected computers. The threat has been seen as part of an Advanced Persistent Threat (APT) campaign that targets Uyghur activists.

It all starts with an email that contains an archive. When uncompressed, the .zip file reveals a .jpeg picture and a Mac OS X app.

The program actually hides the previously unseen version of the malware, identified in this case as Backdoor.OSX.MaControl.b.

Once it’s executed, it attempts to connect to the command and control server from which it gets further instructions.

“The backdoor is quite flexible – its Command and Control servers are stored in a configuration block which has been appended at the end of the file, which his 0x214 bytes in size. The configuration block is obfuscated with a simple ‘substract 8’ operation,” Costin Raiu explained.

Experts believe that as the popularity of Apple devices grows so will the number of such APTs.
FILED UNDER:
APT
MAC malware
backdoor

TELL US WHAT YOU THINK:

1,099 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Flashback Operators Fail to Cash Out Their “Winnings”

Security App of the Week: Hash Code Verifier

Flashback Mac OS X Trojan Earns Its Masters $10,000 (€ 7,600) Each Day

Microsoft Details Mac OS X Malware That Exploits Office Vulnerability

Java-Exploiting Malware Targets Both Mac and Windows Users

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM