Attacks/Breaches
7/30/2012
12:13 PM
Connect Directly
RSS
E-Mail
50%
50%

Mac Malware Spies On Email, Survives Reboots

Crisis malware lets attackers install without an administrator password and intercept email, IM, and other communications.

Mac users, beware new malware targeting Apple OS X systems that's disguised as an Adobe Flash Player installer.

That warning comes via antivirus software vendor Kaspersky Lab, which said it first spotted the Crisis malware--also known as Morcut--last week. While not widespread, the malware's ability to intercept email and IM, among other features, demonstrates that malicious applications written to target Macs can be just as powerful as malware that comes gunning for PCs.

Concerns over Mac malware have been growing since the Flashback malware infected an estimated 600,000 Apple OS X systems earlier this year. Apple ultimately patched multiple versions of its operating system against the malware, and also took the unusual step of altering OS X to disable outdated versions of Java and the Adobe Flash Player, to help prevent malware from exploiting known vulnerabilities in the software.

[ Is Apple upping the ante on security? Read more at Apple's Authentec Buy Hints At Secure iPad. ]

Such steps should pay off in the case of Crisis, since the malware arrives in the form of a Java archive (a.k.a. JAR) file that's allegedly been signed by VeriSign. The malware includes an installer for various modules, including one that communicates with the botnet's command-and-control servers. The installer first checks to see if it's already been installed--via the presence of a file the malware creates to hide its stolen data--and then activates a rootkit, which hides its malicious files and processes in the OS X system library, enabling the malware to survive reboots. The rootkit also ensures that the malware can run automatically, without requiring administrator-level authentication.

Based on the malware's capabilities, "these modules were written professionally, obviously with the intention of being used widely in the future," said Sergey Golovanov, a security researcher at Kaspersky Lab, in a blog post. "From the code, we can see that the cybercriminals developed this Trojan in order to sell it on hacker forums."

But it's unclear if the malware, which offers functionality similar to the Zeus financial malware, has been designed solely with black-market distribution in mind, or whether it might also be marketed to law enforcement agencies, said Golovanov.

Regardless of the malware's origins, it offers attack capabilities on par with modern PC-targeting malware. "If this malware managed to infect your Mac computer, it could learn an awful lot about you and potentially steal information which could read your private messages and conversations, and open your email and other online accounts," said Graham Cluley, senior technology consultant at Sophos, in a blog post. "Clearly, [Morcut] was created with spying in mind."

Notably, the code contains hooks into the Apple OS X operating system that allow it to either monitor or control any built-in Webcam, track mouse coordinates, record keystrokes, copy clipboard contents, and spy on instant messaging tools such as Adium, MSN Messenger, and Skype, as well as call data related to Skype. The malware can also activate the internal microphone, read calendar data and alerts, retrieve address book information, take screenshots, and recall visited URLs.

"Fortunately, we haven't seen Morcut in the wild," Cluley said, which means that either the malware may simply have not found many buyers, or that it's being used only in very targeted attacks.

"At the moment the threat is low," Cluley said. "However, the complexity of the malware is yet another indication that malware on the Mac is becoming more serious--and designed to make money at your expense."

Your networks may be under attack as you read this, but unless your security personnel are analyzing logs and leveraging common tools that are well known to your network operations teams, you may not find out until it is too late. In our What's Going On?: Monitor Networks To Thwart Intrusions report, we explain how your security and network teams can cooperate and use common tools to detect threats before your databases are compromised. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

CVE-2012-5702
Published: 2014-10-21
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to i...

CVE-2013-7406
Published: 2014-10-21
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2531
Published: 2014-10-21
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) R...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.