3 ms·
Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypa
by CryptoBard 7y ago
Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched-macos-gatekeeper-bypass-published-online/ https://www.bleepingcomputer.com/news/security/new-unpatched...). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf
- sterlind 7y agoSounds extremely targeted, if an attacker is porting the attack to Macs (presumably a lot of work), and combining it with other loaders... I wonder how long this 0-day was in the wild. Your friend should probably be browsing as a non-admin in a continuously-reimaged VM, separate from an air-gapped machine, if you have those kinds of attackers after you. Spooky..
- admax88q 7y agoWhat about that makes it sound targeted? Seems like standard vulnerabilities chained together, nothing specific to the "target"
- FDSGSG 7y ago> presumably a lot of work How come?
- fabianhjr 7y agoJust jail outside facing processes like firefox. (BSD Jails, Firejail in Linux and probably another solution on Mac)
- kchr 7y agoJust speculation, but "targeting" in this case may be as trivial as checking the user agent header, or other "device recognition" tricks common in web development nowadays. I am sure there are hundreds of libraries that do this for you...
- saidajigumi 7y agoif an attacker is porting the attack to Macs (presumably a lot of work) It's worth noting that a professional security and pentest company I know of had a Python-based exploit authoring DSL that automatically generated exploit code across a very wide range of processor architectures and OSes. This was about fifteen years ago.
- stcredzero 7y agoIt's worth noting that a professional security and pentest company I know of had a Python-based exploit authoring DSL that automatically generated exploit code across a very wide range of processor architectures and OSes. Makes sense. If entire OSes can be written in an intermediate representation, then exploits can be as well.
- kseifried 7y agoYou mean Core Impact? =).
- saidajigumi 7y agodingdingdingdingding!
- deleted 7y ago[deleted]
- ga-vu 7y agoIt's just hearsay, buddy. You can't be sure the same bug was exploited.
- campuscodi 7y agoAdditional details about the Firefox zero-day: https://twitter.com/campuscodi/status/1141279052893999104 https://twitter.com/campuscodi/status/1141279052893999104
- ga-vu 7y agowow... so I've had a comment downvoted because I've pointed out the obvious "conspiracy theory" in your comment. Glad you just attributed some random hack to a Firefox zero-day with zero proof and I'm the one told to fuck off. HN... jesus christ... this site.
- CryptoBard 7y agoI don't know why you are addressing me, I can't even downvote. Your "conspiracy theory" comment is certainly valid, unfortunately I'm not willing to provide more information so I suppose it will remain a "conspiracy theory" albeit one I believe is true.