4 ms·
There's also a very easy attack vector with pkg installs where an installer can "run software to ensure it's compatible with this machine" that's been there sin
by 2cb 6y ago
There's also a very easy attack vector with pkg installs where an installer can "run software to ensure it's compatible with this machine" that's been there since forever. Not sure if it was removed in Big Sur or not but I hope so.
Zoom used that hole to gain admin permissions and install itself before the user even completed the installation process if the user was admin[1] (and we know most people use admin accounts as their main ones). I'm sure plenty of other malware has done this as well.
If this was simply delivered as a trojan with one of those fake "Flash Player needs updating" type popups, it could have very well abused that.
If it's installing without user interaction the attack vector is a far more advanced 0day exploit chain.
I'll be very interested to find out.
I am also curious about how they can get away with using AWS and Akamai as C&C. Surely now this malware has been found, those providers will just shut down the accounts being used? They'll also have some kind of trail towards whoever's behind it, it's not like AWS takes payment in crypto.
[1] https://twitter.com/c1truz_/status/1244737672930824193 https://twitter.com/c1truz_/status/1244737672930824193
- NateEag 6y agoSpeculation, but I'd not be at all surprised if the C&C servers are compromised boxes that have other uses.