Slashdot Mirror


Sneaky Mac Malware Went Undetected By AV Providers For Four Month (arstechnica.com)

Four months after a mysterious group was outed for a digital espionage operation that used novel techniques to target Mac users, its macOS malware samples continued to go undetected by most antivirus providers, a security researcher reported on Thursday. Ars Technica reports: Windshift is what researchers refer to as an APT -- short for "advanced persistent threat" -- that surveils individuals in the Middle East. The group operated in the shadows for two years until August, when Taha Karim, a researcher at security firm DarkMatter, profiled it at the Hack in the Box conference in Singapore. Slides, a brief description, and a report from Forbes are here, here and here, respectively.

On Thursday, Mac security expert Patrick Wardle published an analysis of Meeting_Agenda.zip, a file Karim had said installed the rare Mac malware. To Wardle's surprise, results from VirusTotal at the time showed that only two antivirus providers -- Kaspersky and ZoneAlarm -- detected the file as malicious. Wardle then used a feature that searched VirusTotal for related malicious files and found four more. Three of them weren't detected by any AV providers, while one was detected by only two providers. The reason the findings were so surprising is that Apple had already revoked the cryptographic certificate the developers used to digitally sign their malware. That meant Apple knew of the malware. In fairness, the control servers the malware contacts are no longer available on the Internet. That means any infected computers aren't in danger of being surveilled. Also in fairness, the number of detections has slowly risen in the day since Wardle published his analysis.

4 of 28 comments (clear)

  1. AV works best with...sigs by xxxJonBoyxxx · · Score: 3, Informative

    Newsflash: AV is pretty useless beyond detecting signatures of KNOWN malware. I've yet to see one that catches, for example, custom PS scripts.

    1. Re:AV works best with...sigs by rtb61 · · Score: 2

      Which makes this story even weirder. It's like where are the staff that are meant to be monitoring competitors and running competitors software. What the hell happened, to "hey guys, our competitors software is blocking this malware and our's isn't", and then they fix that within the next hour. Just ignore the failure of your software for four months, kinds of makes you think they were forced to ignore it because of who it belong to or well, they are just shite companies, selling a shite product and they simply do not care how shite it is, as long as they get their money, much like gaming companies.

      --
      Chaos - everything, everywhere, everywhen
    2. Re:AV works best with...sigs by AHuxley · · Score: 2

      When unexpected software tries to copy itself deep into an OS X location that change can be detected in real time.
      From the linked https://objective-see.com/blog...
      ""First, good news, Objective-See’s tools such as BlockBlock and KnockKnock are able to both detect and block this malware with no a priori knowledge" ...

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:AV works best with...sigs by auzy · · Score: 2

      That's incorrect..

      If you look at Watchguard and other advanced router vendors such these days, they send unknown samples of files to a fake windows computer in the cloud, run them and analyse them.

      Whilst it won't detect everything, if everyone ran such sandbox based AV systems things would work much better.

      The big issue with OSX, is that Apple DECEIVED people into believing OSX couldn't get viruses, so everyone let their guard down.

      Don't be surprised if there is a lot more OSX malware out there than people know about