New mac malware opens secure act new mac malware opensea new mac malware openstreetmap new mac malware opensubtitles new mac os new mack trucks for sale new mac computers
New Mac malware opens secure reverse shell
A new backdoor Trojan for OS X is making the rounds, attempting to set up a secure connection for a remote hacker to connect through and grab private information.
The malware, dubbed "Pintsized" by Intego, is suspected of using a modified implementation of OpenSSH to set up a reverse shell that creates a secure connection to a remote server.
The use of an encrypted connection makes it more difficult to detect and trace, especially since it uses the common SSH protocol. In addition, the malware attempts to hide itself by disguising its files to look like components of the OS X printing system, specifically the following:
com.apple.cocoa.plist
cupsd (Mach-O binary)
com.apple.cupsd.plist
com.apple.cups.plist
com.apple.env.plist
Intego does not state where these files are placed in the OS, but as with prior malware in OS X this requires an option to automatically launch the malware whenever the system is started or when a user logs in, which in OS X is the various launch agent directories in the system. Launch agents use a property list (plist) structure, and can be used to target a binary executable (such as the mentioned "cupsd" one above) to keep it always running on the system.
Therefore, to check for this malware, open the following directories in the system to check for the presence of any of the above files:
/System/Library/LaunchDaemons
/System/Library/LaunchAgents
/Library/LaunchDaemons
/Library/LaunchAgents
~/Library/LaunchAgents
NOTE: You can highlight each folder path above individually, right-click the selection, and choose "Open" from the Services contextual submenu to open it in the Finder.
Because malware developers use these folders as a means of running their malware in OS X, one easy way to detect any misuse of them is to set up an alert that will notify you whenever files are added to them. I outlined how to do this with tools and services that are included in OS X, and the Luxembourg CIRCL subsequently developed a standalone installer that sets up a similar monitoring routine.
In addition to monitoring these folders, you can also install a reverse firewall like Little Snitch, which will notify you whenever a program attempts to make a connection to a remote server.
Currently it is unknown how the malware initiates its attack, whether it uses a previously documented vulnerability or one that is yet to be disclosed; however, the malware is not known to be widespread and is primarily being discussed on various security mailing lists. Nevertheless, by checking for the presence of the above files in the system's Launch Agent and Launch Daemon folders you should be able to determine if your system is free of it.
Questions? Comments? Have a fix? Post them below or e-mail us!
Be sure to check us out on Twitter and the CNET Mac forums.
Source
Blog Archive
-
▼
2023
(62)
-
▼
February
(22)
- Nvidia's Powerful New Chip Aims To Help AI Underst...
- Best Cheap Video Doorbells For 2022
- Black Adam Teaser Trailer Reveals The Rock In God ...
- Samsung's New Galaxy S21 FE Will Keep The Galaxy S...
- 9 Alexa Tips For Music Junkies
- Moon Knight Is Returning For Season 2, Oscar Isaac...
- Best Prepaid Phones For 2022
- Here's The Production Honda E In All Its Glory
- Windows 11 Draining Your Battery? Here's How To Fi...
- IOS 16's New Apple Pay Option Lets IPhone Users Bu...
- Twitter Expands Fact-Checking Project Birdwatch In...
- Pokemon Scarlet And Violet Teasing Another New Pok...
- Acer Predator Triton 300 SE Review: A Special Edit...
- The Best Cyber Monday Kitchen Deals Still On: Henc...
- HP Rumored To Be Working On 17-Inch Laptop With A ...
- 2022 Audi Q4 E-Tron First Drive Review: Easy EV Li...
- 2022 Kia EV6 First Drive Review: Simply The Best
- Intel's New Diversity Goals: Put Women In 40% Of T...
- New Mac Malware Opens Secure Reverse Shell
- Apple's IPhone 13 Leads To Company's Largest Reven...
- CES 2021: Lenovo ThinkBook Plus Gen 2 I Laptop Has...
- Intel Pledges To Cut Greenhouse Gas Emissions To Z...
-
▼
February
(22)
Total Pageviews
Search This Blog
Popular Posts
-
Panic's Playdate Feels Like a Delightful, Bizarro Nintendo Game and Watch Panic's Playdate Feels Like a Delightful, Biz...
-
Amazon Slashes Apple Watch SE and Series 7 Prices as Apple Watch Series 8 Launch Looms Amazon Slashes Apple Watch SE and Series...
-
Google pixel 6 vs pixel 6 pro which camera is best google pixel 6 vs pixel 6 pro which camera is more realistic google pixel 6 vs pixel 6 pr...