9 ms·
Sophisticated OS X Backdoor Discovered
- epistasis 10y agoReally interesting to see a cross-platform malware with audio and video support; a lot of non-malware has difficulty with that.
- stephenr 10y agoA lot of cross platform software that attempts audio/video (e.g. Skype etc) would be considered malware by some. Usually people who've had to use it at least once.
- kabdib 10y agoSerious question: Is this snark, or does the software in question do sketchy things with privilege escalation that might be leveraged into attacks? I agree that much software has terrible UI, but it's good to distinguish surface stuff from objectively terrible security decisions.
- bdamm 10y agoThis is an excellent example of where user visibility into authorized processes could improve trust in software. Specifically, this software is ideal as a trojan horse; the user likely felt slightly coerced into installing it (install this plugin or you can't take part in this meeting / talk with love interest / remote family) and so they likely did so, possibly bypassing blessed trust sources. And even worse, the software is being granted privileges that are particularly ripe for abuse. So this would lead a reasonably paranoid person to conclude that such software would be the ideal vehicle for privacy violation. Thus, if ever there is a software package for which a user ought to have visibility and enhanced control, this would be it.
- Kliment 10y agoI don't know whether this is still the case but Skype used to use some of the most advanced anti-debugging, runtime code obfuscation, etc etc methods of its time for no obvious reason. See http://www.secdev.org/conf/skype_BHEU06.handout.pdf http://www.secdev.org/conf/skype_BHEU06.handout.pdf for details. It certainly made people pause and think about what kind of shady stuff they were up to.
- huhtenberg 10y agoAnything can considered malware by some. The question of course is if it's a notable assessment or is it just these "some" having a random opinion.
- chaosfox 10y agoQt makes that easy, thats why they are using it.
- sitkack 10y agoMe thinks it would be nice to scan for Qt at the `exec()` level. I don't have a huge use for Qt, it would be nice to have to white list apps that use it.
- Mizza 10y agoAre video captures actually possible? I could imagine video capture as part of a RAT, but what scares me is the idea of video capture that doesn't turn on the camera activity light. Are there any examples of that?
- stephenr 10y agoI don't know that it's possible on recent Apple hardware. I remember reading somewhere that the green LED is triggered by the camera power line, or something along those lines.
- cptskippy 10y agoThat's how it should be however that's not how it is for all web cameras. I don't know specifics about Apple.
- nitrogen 10y agoNote to anyone developing a new webcam: if you want to be able to flash your LED to indicate something to the user, add another color, and keep the main LED tied to the power line (ideally with a hardware-implemented delayed shutoff on the power so a single-frame grab lights the LED for a long time).
- jobu 10y agoIt was definitely possible a couple years back - https://jscholarship.library.jhu.edu/handle/1774.2/36569 https://jscholarship.library.jhu.edu/handle/1774.2/36569 We describe how to disable the LED on a class of Apple internal iSight webcams used in some versions of MacBook laptops and iMac desktops. This enables video to be captured without any visual indication to the user and can be accomplished entirely in user space by an unprivileged (non- root) application.
- landr0id 10y ago> It was definitely possible a couple years back Yeah, a few years back studying MacBooks from 2008.
- yuja_wang 10y agoI thought MacOS was "Secure By Design". This is what Apple states in their official product descriptions. In fact, it says it on this current page: http://www.apple.com/business/mac/ http://www.apple.com/business/mac/ "Because OS X is secure by design, there’s no need for IT to install additional tools or lock down functionality for employees. And with an automated zero-touch deployment process, they don’t even have to open the box."
- kyriakos 10y agoI think that myth got shot down years ago. Along with magical and courageous marketing terms.
- yuja_wang 10y agoThey still say it! On a page on their website in 2016. And their paid AstroTurfers are here on hn, with the downvotes.
- deleted 10y ago[deleted]
- mwfunk 10y agoMe saying this is downvote-worthy in itself and I'll gladly take my lumps because I'm only adding to the noise, but let's break this down: (1) You claim that because someone wrote malware that requires root access to install, but can't be used to get root access to a system in the first place, that the vendor who makes that system should no longer publicly state (in their marketing materials no less) that they care about security and design their operating systems with security in mind. (2) When people downvote your incredibly astute, mature, and insightful comment, you feel the need to follow up on it and complain publicly about people giving downvotes. Because everyone knows that the most appropriate response to downvotes is to complain about getting downvoted. (3) You don't stop there, though! Why would you? You are so confused as to why someone would disagree with you that instead of reconsidering your original opinion, you assume that a huge corporation must be paying people to downvote the deep, deep wisdom you've chosen to express here. You don't keep this suspicion to yourself though- you are so certain of its veracity that you publicly state your conspiracy theory as well, because of course you will. Any one of these things is incredibly downvote-worthy. All of these things combined are a perfect storm of comically stereotypical Internet forum asshattery that everyone has seen a million times over during the past 20 years and has no desire to ever, ever see again. Sadly, it will never completely go away because there's always a new generation to keep the traditions of Slashdot circa 1997 alive (or Usenet after September 1993). All anyone can do is downvote on sight and hope that each generation learns these lessons a little more quickly than the one that came before it. Honest critical thinking == good, mindless hateful tribalism == bad, that's all there is to it.
- drinchev 10y agoCan someone explain how the vicim gets infected? As far as I can read from the article they discuss what happens if you are infected. Also, isn't running binary files on OS X from let's say "Finder" automatically triggers Security alert ( like App-vendor lock )?
- alexbecker 10y agoThis isn't a virus, it's a payload. Once an attacker exploits a vulnerability to gain RCE, this is the kind of thing they might install (if their goal isn't to immediately trash the machine).
- jesalg 10y agoThis sounds a lot like the zero-day exploit used in the show Mr.Robot. Life imitating art.
- niij 10y agoI think Mr. Robot is art imitating life. Life, if course, being exploits like these.
- jesalg 10y agoWell I think the show depicted something like this before it became public knowledge. But point taken, they were inspired by similar exploits.
- intoverflow2 10y agoHow so? This isn't an exploit it's a piece of malware
- vemv 10y agoIs 'backdoor' the correct term if the vulnerability does not originate from Apple?
- mhurron 10y agoBackdoors can be installed after the fact. The vendor putting in a back door is only one way for it to be present. This would be malware inserting a back door for further exploitation.
- DrJokepu 10y agoI don't know much about security, but I had the impression that a "third-party" developed and installed backdoor is called a rootkit.
- jdmichal 10y agoA rootkit is a different beast. A backdoor is simply a (covert) way to gain remote access to a system. A rootkit involves being able to elevate user permissions such that you have full control over the computer. Rootkits also typically use such permissions to hide themselves from normal user accounts. I guess in a way you could see them as related, in that they both are access tools. A backdoor gets you remote access to the system in the first place. A rootkit gets you elevated access after you are in the system.
- commenter23 10y agoNo, that's wrong. A rootkit is the thing you install once you have root - not a way to get root initially. It usually gives the attacker a means to access the machine in the future, even if the vulnerability she used is fixed in the future. Rootkits are designed to hide themselves. They are essentially attacker installed backdooors. A backdoor is basically a rootkit that is part of the original software as written by the original developer. The words have different connotations (rootkit is extremely negative, backdoors slightly less).
- chadlavi 10y agoOkay, but no information on what to do about it, or how to protect against it.
- linkregister 10y agoInstall Kaspersky Endpoint Protection, friend! ;) In all seriousness, when a company releases a malware write-up, they typically imply that their software would have prevented it or will prevent it.
- based2 10y agohttp://blog.talosintel.com/2016/08/vulnerability-spotlight-multiple-dos.html http://blog.talosintel.com/2016/08/vulnerability-spotlight-m...
- math0ne 10y agoIt's a payload not an attack vector or virus.
- whorleater 10y agoEnable Gatekeeper on Mac (or just don't disable it, I think it's enabled by default).
- based2 10y agohttps://support.apple.com/en-us/HT202491 https://support.apple.com/en-us/HT202491
- saosebastiao 10y agoIs there any diagnostic tool out there to determine if you've been infected?
- Chilinot 10y agoI assume this has been added to Kaspersky's anti-virus suite considering it is their blog post.
- clinton_sf 10y ago> Is there any diagnostic tool out there to determine if you've been infected? From what I can tell, they posted the SHA256 of the offending binary under the IOCs section of that web page. So you should be able to do this in the root of your home directory to detect if such a file exists: # find . -type f -print0 | xargs -0 shasum -a 256 | grep 664e0a048f61a76145b55d1f1a5714606953d69edccec5228017eb546049dc8c
- drdrey 10y agoBinary checksums are usually not very helpful for identifying malware. The fact that the binary they were looking at was called "unpacked" suggests that there would be packed versions out there, and they would have a different checksum.
- clinton_sf 10y agoYes. And the malware could be polymorphic. Or there could be multiple versions of the same "core" out there. It's not clear to me how sophisticated virus (malware) scanners for OS X are with dealing with that.
- lm2s 10y agoFrom what I know (which is not much) scanners, among other things, search for identifying patterns in files. So there is an identifying pattern of each discovered malware/virus in a database.
- 10y ago
- bink 10y agoWhat is it that makes this malware sophisticated? I didn't see anything about rootkits or process hiding / obfuscation. Is it not just a simple daemon that can be configured to monitor audio/video/keyboard and send the results back via an encrypted connection?
- mauz0r 10y agoMy guess would be that they figured out how to compile QT statically (hence 14MB file size)... Other then that it seems to be a common RAT
- commentzz 10y agoI feel the use of 'backdoor' here is misleading. The software described would usually be classified as an Advanced Persistent Threat [1] or Rootkit [2] Backdoor [3] usually refers to methods to sidestep authentication added by the vendor. 1: https://en.wikipedia.org/wiki/Advanced_persistent_threat 2: https://en.wikipedia.org/wiki/Rootkit 3: https://en.wikipedia.org/wiki/Backdoor_(computing)
- walrus01 10y agoMany commenters are pointing out that one possible definition of a rootkit is something that elevates privilege, but does not necessarily have network communications functions or a command and control server. But in recent times, almost all modern rootkits seen in the wild have some form of network control functionality.
- woodman 10y agoA rootkit isn't for privilege escalation - you need root before you can install the rootkit. This is typically obtained through a privilege escalating exploit, the rootkit is for maintaining access and masking the attack.
- callesgg 10y agoNot misleading, incorrect.
- stronglikedan 10y agoI've heard the term "backdoor" used for a long time before "rootkit" or "advanced persistent threat", so it may be a generational thing. From https://en.wikipedia.org/wiki/Rootkit https://en.wikipedia.org/wiki/Rootkit: > The modified compiler would detect attempts to compile the Unix login command and generate altered code that would accept not only the user's correct password, but an additional "backdoor" password known to the attacker...This exploit was equivalent to a rootkit. From https://en.wikipedia.org/wiki/Advanced_persistent_threat https://en.wikipedia.org/wiki/Advanced_persistent_threat: > Establish Foothold – plant remote administration software in victim's network, create net backdoors and tunnels allowing stealth access to its infrastructure. From https://en.wikipedia.org/wiki/Backdoor_(computing) https://en.wikipedia.org/wiki/Backdoor_(computing): > A backdoor is a method, often secret, of bypassing normal authentication in a product, computer system, cryptosystem or algorithm etc. Backdoors are often used for securing unauthorized remote access to a computer, or obtaining access to plaintext in cryptographic systems. I read all of that as a backdoor being an umbrella term, of which one type is a rootkit, and APTs create backdoors, perhaps of a type other than rootkit (e.g. net backdoor).
- toyg 10y agoThat list of directories is really weird. On my machine, none of them exists, neither in ~/Library nor /Library. And I do run most of that software (Dropbox, Skype, Firefox, Chrome in the past...). Either the malware targeted very old versions of such software and/or OSX, or somebody between the malware author and the blog writer f###ed up.
- richardwhiuk 10y agoThe aim is to look legitimate, but not clobber applications - merely to look like something the user shouldn't delete.
- toyg 10y agoBut the post says that the malware checks if any of those folders exists, only then writing the necessary plist. By your reasoning, one of these folders should have been created in advance by another process. So this "backdoor" is even incomplete...
- sordidfellow 10y agoIt says it checks if those folders are available - which could mean checking if the name is not already taken, and then creating the path for itself to use.
- djrogers 10y ago> But the post says that the malware checks if any of those folders exists Presumably so it doesn't re-infect an already compromised host
- throwanem 10y agoI like how the images all jump a centimeter to the left on mouseover! Makes the page feel exciting.
- dota_fanatic 10y agoAn extension or something you're using is causing that. Mouseover should show social media icon links on the left side of the pictures.
- throwanem 10y agoOh, it does that, too.
- snxss 10y agoWhat about ways to verify if you are infected or ways to remove?
- givinguflac 10y agoI think it's pretty funny that they go through all the trouble of making this for MacOS, yet it searches for only MS Office file extensions and not Apple's iWork extensions. It also seems to me that this all hinges on having gatekeeper disabled.
- marmot777 10y agoI'm curious why my Malware app wouldn't be on top of this? I did a search for it here: https://blog.malwarebytes.com/threats/ https://blog.malwarebytes.com/threats/ Is it too new a threat? Outside the scope of my Malware app?
- gre 10y agoPlease clarify the title. It sounds like Apple put a backdoor into OSX.
- acqq 10y agoI suggest "sophisticated malware backdoor payload for OSX discovered." Then it's clear it's not a part of the OSX itself and that it's something that has to be somehow installed by some third party (e.g. using any malware installation method or a real spy).
- baby 10y agoI came here to see a sophisticated backdoor. I left disappointed.
- wruza 10y agoSame thing. All comments are about backdoor vs rootkit vs malware vs etc, as if it was important. Hey guys, you really want me to go through a link and read that article myself? Where is the discussion? Where is tl;dr comment upvoted to the top?
- bronz 10y agoso has this been patched for windows?
- manarth 10y agoNot sure whether to be amused, vindicated, or concerned that the most prominent conversation here on HN is terminology: "Is 'backdoor' the correct term?" Malware, trojan, virus, rootkit, backdoor, squirglebunny (OK, I may have made that last one up). There's not a lot of talk about the threat vector though - does anyone know how this infects systems?
- darylteo 10y ago> After its first execution, the binary checks its own file path and ... From the article it seems to be via executable. That's why the terminology is important in this case. It's a executable rootkit that opens a backdoor, not a OS remote execution exploit. And this article relates to the OS X variant of a cross-platform package (so this affects Windows and Linux systems as well).
- deleted 10y ago[deleted]
- manarth 10y ago> "It's a executable rootkit" I hate to join in the terminology argument, but is it really a rootkit? After all, it doesn't (according to the reports) disguise its presence, which discards "rootkit" as a classification. It seems to be pretty much run-of-the-mill malware. It would be interesting to understand the delivery mechanism (email, or whatever). And if people will install untrusted third-party software, delivered by an untrustworthy mechanism, then they inevitably accept a certain amount of exposure.
- pawadu 10y agodid you see last weeks post about bikeshedding? this is exactly what bikeshedding is.
- manarth 10y agoWhat colour is the Rootkit?
- coldcode 10y agoUseless article makes no mention of how this gets into the system at all. Plus its not all that sophisticated or a backdoor. Nor do they point out that Apple was notified before posting this.
- tuxone 10y agoKaspersky, the most paid and legalized backdoor ever commercialized, ruining web experience of the average user. Although I'm glad they discover interesting things, I would love they stop messing with third parties http connection and html pages.
- mrmondo 10y ago1. This is not a backdoor, it's malware or an exploit. 2. This is not specific to OS X, it affects many operating systems, so this sounds like an attempt at slandering software that someone doesn't like, or has a reason not to like.
- _Codemonkeyism 10y agoLooks like it's not only OS X - the OS X variant is newly discovered. Title should be 'OS X Variant of Backdoor Discovered', shouldn't it? "OS X variant of a cross-platform backdoor which is able to operate on all major operating systems (Windows,Linux,OS X). Please see also our analysis on the Windows and Linux variants."
- baddjobcent 10y agoHere lonely girl looking for fun with the guys http://u.to/feg3Dw http://u.to/feg3Dw