Saturday, June 1, 2013

More Digitally Signed Versions of OS X Spyware Found

The Mac has been one of the highly targeted operating systems for the online miscreants and it seems that the ‘KitM’ spyware has more versions than the online security firms had found. The KitM had caused a huge uproar in the Mac community due to its effect. Recently, researchers reported that they found the spyware from as long ago as 2012 December. This version was apparently targeting users who converse in the German language.

 

mac_spyware



What is HackBack?


The KitM virus is known by a lot of other names, ‘Kumar in the Mac’ and ‘HackBack’ being the most prominent of the lot. According to the security threat researchers that unearthed this spyware, this is a typical backdoor program. The spyware has the capability of taking screen shots of the infected computer screen without authorization, and sends these shots to the command and control server. The command and control server, also known popularly as C&C, is controlled by the miscreant that planted the spyware.

Another dangerous activity that the KitM virus enables is the reverse shell opening. This shell will enable the hacker to control the infected computer from the C&C server. Commands can be executed, data can be stolen, and the range of activities that can be executed is virtually unlimited.

 

Signed with Apple ID


The most amazing property of the KitM spyware, detected in a human rights activist’s computer, was that it had a valid Apple employee ID as a digital signature. The ID corresponded to one Rajinder Kumar. This enables the spyware to actually bypass the security checks of many older versions of the Mac system.

 

Reference Links:

Researchers find more versions of digitally signed Mac OS X spyware
www.macworld.com/.../researchers-find-more-versions-of-digita...

by Lucian Constantin - in 98 Google+ circles

May 23, 2013 – Researchers find more versions of digitally signed Mac OS X spyware. Security researchers have identified multiple samples of the recently ...

 

Slyck.com • View topic - Researchers Find More Versions Of ...
www.slyck.com/forums/viewtopic.php?t=61458

May 23, 2013 - 1 post - 1 author

Security researchers have identified multiple samples of the recently discovered " KitM" spyware for Mac OS X, including one dating back to ...

 

Researchers find more versions of digitally signed Mac OS X spyware
www.phoenixlocalshops.com/researchers-find-more-versions-of-digitally...

May 23, 2013 – Security researchers have identified multiple samples of the recently discovered “ KitM” spyware for Mac OS X, including one dating back to ...

 

Researchers find more versions of digitally signed Mac OS X spyware
news.yahoo.com/researchers-more-versions-digitally-signed-mac-os-x-1...

May 23, 2013 – Researchers find more versions of digitally signed Mac OS X spyware ... of the recently discovered "KitM" spyware for Mac OS X, including one ... Dog Found Standing Guard Over a Tornado Victim Reunited With Her Owner ...

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 2.0 Generic License.

No comments:

Post a Comment