{"id":2465,"date":"2024-02-02T20:03:22","date_gmt":"2024-02-02T20:03:22","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/macos-malware-campaign-showcases-novel-delivery-technique"},"modified":"2024-02-02T20:03:22","modified_gmt":"2024-02-02T20:03:22","slug":"macos-malware-campaign-showcases-novel-delivery-technique","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/02\/macos-malware-campaign-showcases-novel-delivery-technique\/","title":{"rendered":"macOS Malware Campaign Showcases Novel Delivery Technique"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltb79e6ba816615266\/65bd4373c6f7cc040a01efec\/Apple_Bhubeth_Bhajanavorakul_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security researchers have sounded the alarm on a new cyberattack campaign using cracked copies of popular software products to distribute a backdoor to macOS users.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What makes the campaign different from numerous others that have employed a similar tactic \u2014 such as one reported just earlier this month <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/stealthy-backdoor-found-hiding-in-pirated-macos-apps\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">involving Chinese websites<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 is its sheer scale and its&nbsp;novel, multistage payload delivery technique. Also noteworthy is the threat actor&#8217;s use of cracked macOS apps with titles that are of likely interest to business users, so organizations that don&#8217;t restrict what users download can be at risk as well.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kaspersky was the first to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/securelist.com\/new-macos-backdoor-crypto-stealer\/111778\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">discover and report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on the Activator macOS backdoor in January 2024. A subsequent analysis of the malicious activity by SentinelOne has showed the malware to be &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.sentinelone.com\/blog\/backdoor-activator-malware-running-rife-through-torrents-of-macos-apps\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">running rife through torrents of macOS apps<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; according to the security vendor.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Our data is based on the number and frequency of unique samples that have appeared across VirusTotal,&#8221; says Phil Stokes, a threat researcher at SentinelOne. &#8220;In January since this malware was first discovered, we&#8217;ve seen more unique samples of this than any other macOS malware that we [tracked] over the same period of time.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The number of samples of the Activator backdoor that SentinelOne has observed is more than even the volume of macOS adware and bundleware loaders (think Adload and Pirrit) that are supported by large affiliate networks, Stokes says. &#8220;While we have no data to correlate that with infected devices, the rate of unique uploads to VT and the variety of different applications being used as lures suggests that in-the-wild infections will be significant.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Building a macOS Botnet?\">Building a macOS Botnet?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One potential explanation for the scale of the activity is that the threat actor is attempting to assemble a macOS botnet, but that remains just a hypothesis for the moment, Stokes says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The threat actor behind the Activator campaign is using as many as 70 unique cracked macOS applications \u2014 or &#8220;free&#8221; apps with copy protections removed \u2014 to distribute the malware. Many of the cracked apps have business-focused titles that could be of interest to individuals in workplace settings. A sampling: Snag It, Nisus Writer Express, and Rhino-8, a surface modeling tool for engineering, architecture, automotive design, and other use cases.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There are many tools useful for work purposes that are used as lures by macOS.Bkdr.Activator,&#8221; Stokes says. &#8220;Employers that do not restrict what software users can download could be at risk of compromise if a user downloads an app that is infected with the backdoor.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Threat actors seeking to distribute malware via cracked apps typically embed the malicious code and backdoors within the app itself. In the case of Activator, the attacker has employed a somewhat different strategy to deliver the backdoor. &nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Different Delivery Method\">Different Delivery Method<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unlike many macOS malware threats, Activator doesn&#8217;t actually infect the cracked software itself, Stokes says. Instead, users get an unusable version of the cracked app they want to download, and an &#8220;Activator&#8221; app containing two malicious executables. Users are instructed to copy both apps to the Applications folder, and run the Activator app.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The app then prompts the user for the admin password, which it then uses to disable macOS&#8217; Gatekeeper settings so that applications from outside Apple&#8217;s official app store can now run on the device. The malware then initiates a series of malicious actions that ultimately turn off the systems notifications setting and install a Launch Agent on the device, among other things. The Activator backdoor itself is a first-stage installer and downloader for other malware.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The multistage delivery process &#8220;provides the user with the cracked software, but backdoors the victim during the installation process,&#8221; Stokes says. &#8220;This means that even if the user later decided to remove the cracked software, it will not remove the infection.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sergey Puzan, malware analyst at Kaspersky, points to another aspect of the Activator campaign that is noteworthy.&nbsp;&#8220;This campaign uses a Python backdoor that doesn&#8217;t appear on disk at all and is launched directly from the loader script,&#8221; Puzan says. &#8220;Using Python scripts without any &#8216;compilers&#8217; such as pyinstaller is a bit more tricky as it require attackers to carry a Python interpreter at some attack stage or ensure that the victim has a compatible Python version installed.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Puzan also believes that one potential goal of the threat actor behind this campaign is to build a macOS botnet. But since Kaspersky&#8217;s report on the Activator campaign, the company has not observed any additional activity, he adds.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/macos-malware-campaign-showcases-novel-delivery-technique\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers have sounded the alarm on a new cyberattack<\/p>\n","protected":false},"author":12,"featured_media":2466,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2465","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/macos-malware-campaign-showcases-novel-delivery-technique.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2465"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2465\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2466"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}