An insidious Mac malware is getting more sophisticated

[ad_1]

Known Mac Malware Since UpdateAgent has been around for over a year, it’s getting more and more vicious as its developers add new bells and whistles. The additions include pushing an aggressive second-stage adware payload that installs a persistent backdoor on infected Macs.

The UpdateAgent malware family started spreading as a relatively basic information stealer by November or December 2020 at the latest. It collects the product name, version number, and other basic system information.its persistence method – i.e. the ability to run it once per time Apple Computer Boots – pretty rudimentary too.

man-in-the-middle attack

Over time, Microsoft says On Wednesday, UpdateAgent became more advanced.In addition to the data sent to the attacker’s server, the application also sends “heartbeats” that let the attacker know malicious software still running. It also installs adware called Adload.

Microsoft researchers wrote:

When adware is installed, it uses ad-injection software and techniques to intercept the device’s online communications and redirect user traffic through the adware operator’s servers, injecting advertisements and promotions into web pages and search results. More specifically, Adload exploits a man-in-the-middle (PiTM) attack by installing web proxies to hijack search engine results and inject ads into web pages to suck ad revenue away from official website holders to adware operators.

Adload is also an unusually persistent adware. In addition to collecting system information sent to the attacker’s C2 server, it is also able to open backdoors to download and install other adware and payloads. Considering that both UpdateAgent and Adload are capable of installing additional payloads, an attacker could leverage one or both of these vectors to potentially deliver more dangerous threats to the target system in future campaigns.

UpdateAgent now removes a flag before installing adware Mac OS security mechanism Watchmen added to the downloaded file. (Gatekeeper ensures that users are warned about new software coming from the Internet and that it doesn’t match known malware.) While this malicious feature isn’t new —Mac Malware in 2017 Did the same thing – its incorporation into UpdateAgent indicates that malware is being developed on a regular basis.

UpdateAgent’s reconnaissance expanded to collect system configuration file and SPH hardware type The data, among other things, reveals the serial number of the Mac. The malware also started modifying the LaunchDaemon folder instead of the previous LaunchAgent folder. While the change requires UpdateAgent to be run as an administrator, the change allows the Trojan to inject persistent code that runs as root.

The following timeline illustrates the evolution.

Provided by Microsoft

[ad_2]

Source link