TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Sophisticated OS X Backdoor Discovered

385 pointsby cyphersanctusover 8 years ago

23 comments

binkover 8 years ago
What is it that makes this malware sophisticated? I didn't see anything about rootkits or process hiding / obfuscation. Is it not just a simple daemon that can be configured to monitor audio/video/keyboard and send the results back via an encrypted connection?
评论 #12460726 未加载
vemvover 8 years ago
Is 'backdoor' the correct term if the vulnerability does not originate from Apple?
评论 #12455845 未加载
评论 #12455728 未加载
评论 #12455898 未加载
评论 #12456337 未加载
评论 #12456217 未加载
评论 #12461696 未加载
评论 #12459844 未加载
drinchevover 8 years ago
Can someone explain how the vicim gets infected?<p>As far as I can read from the article they discuss what happens if you are infected.<p>Also, isn&#x27;t running binary files on OS X from let&#x27;s say &quot;Finder&quot; automatically triggers Security alert ( like App-vendor lock )?
评论 #12455751 未加载
commentzzover 8 years ago
I feel the use of &#x27;backdoor&#x27; here is misleading.<p>The software described would usually be classified as an Advanced Persistent Threat [1] or Rootkit [2] Backdoor [3] usually refers to methods to sidestep authentication added by the vendor.<p><pre><code> 1: https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Advanced_persistent_threat 2: https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Rootkit 3: https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Backdoor_(computing)</code></pre>
评论 #12456166 未加载
评论 #12457079 未加载
评论 #12459731 未加载
评论 #12456704 未加载
epistasisover 8 years ago
Really interesting to see a cross-platform malware with audio and video support; a lot of non-malware has difficulty with that.
评论 #12456494 未加载
评论 #12455351 未加载
manarthover 8 years ago
Not sure whether to be amused, vindicated, or concerned that the most prominent conversation here on HN is terminology: &quot;Is &#x27;backdoor&#x27; the correct term?&quot;<p>Malware, trojan, virus, rootkit, backdoor, squirglebunny (OK, I may have made that last one up).<p>There&#x27;s not a lot of talk about the threat vector though - does anyone know how this infects systems?
评论 #12458337 未加载
评论 #12460398 未加载
babyover 8 years ago
I came here to see a sophisticated backdoor. I left disappointed.
评论 #12458490 未加载
snxssover 8 years ago
What about ways to verify if you are infected or ways to remove?
chadlaviover 8 years ago
Okay, but no information on what to do about it, or how to protect against it.
评论 #12455852 未加载
评论 #12456688 未加载
评论 #12455931 未加载
greover 8 years ago
Please clarify the title. It sounds like Apple put a backdoor into OSX.
评论 #12457358 未加载
tuxoneover 8 years ago
Kaspersky, the most paid and legalized backdoor ever commercialized, ruining web experience of the average user. Although I&#x27;m glad they discover interesting things, I would love they stop messing with third parties http connection and html pages.
givinguflacover 8 years ago
I think it&#x27;s pretty funny that they go through all the trouble of making this for MacOS, yet it searches for only MS Office file extensions and not Apple&#x27;s iWork extensions. It also seems to me that this all hinges on having gatekeeper disabled.
saosebastiaoover 8 years ago
Is there any diagnostic tool out there to determine if you&#x27;ve been infected?
评论 #12456757 未加载
评论 #12456131 未加载
评论 #12455982 未加载
评论 #12456356 未加载
_Codemonkeyismover 8 years ago
Looks like it&#x27;s not only OS X - the OS X variant is newly discovered.<p>Title should be &#x27;OS X Variant of Backdoor Discovered&#x27;, shouldn&#x27;t it?<p>&quot;OS X variant of a cross-platform backdoor which is able to operate on all major operating systems (Windows,Linux,OS X). Please see also our analysis on the Windows and Linux variants.&quot;
toygover 8 years ago
That list of directories is really weird. On my machine, none of them exists, neither in ~&#x2F;Library nor &#x2F;Library. And I do run most of that software (Dropbox, Skype, Firefox, Chrome in the past...).<p>Either the malware targeted very old versions of such software and&#x2F;or OSX, or somebody between the malware author and the blog writer f###ed up.
评论 #12456045 未加载
marmot777over 8 years ago
I&#x27;m curious why my Malware app wouldn&#x27;t be on top of this? I did a search for it here: <a href="https:&#x2F;&#x2F;blog.malwarebytes.com&#x2F;threats&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.malwarebytes.com&#x2F;threats&#x2F;</a><p>Is it too new a threat? Outside the scope of my Malware app?
mrmondoover 8 years ago
1. This is not a backdoor, it&#x27;s malware or an exploit.<p>2. This is not specific to OS X, it affects many operating systems, so this sounds like an attempt at slandering software that someone doesn&#x27;t like, or has a reason not to like.
Mizzaover 8 years ago
Are video captures actually possible? I could imagine video capture as part of a RAT, but what scares me is the idea of video capture that doesn&#x27;t turn on the camera activity light. Are there any examples of that?
评论 #12455457 未加载
评论 #12455336 未加载
评论 #12455581 未加载
评论 #12455909 未加载
评论 #12457696 未加载
评论 #12455480 未加载
评论 #12457774 未加载
评论 #12456325 未加载
coldcodeover 8 years ago
Useless article makes no mention of how this gets into the system at all. Plus its not all that sophisticated or a backdoor. Nor do they point out that Apple was notified before posting this.
throwanemover 8 years ago
I like how the images all jump a centimeter to the left on mouseover! Makes the page feel exciting.
评论 #12456976 未加载
bronzover 8 years ago
so has this been patched for windows?
jesalgover 8 years ago
This sounds a lot like the zero-day exploit used in the show Mr.Robot. Life imitating art.
评论 #12455827 未加载
评论 #12460693 未加载
yuja_wangover 8 years ago
I thought MacOS was &quot;Secure By Design&quot;. This is what Apple states in their official product descriptions.<p>In fact, it says it on this current page:<p><a href="http:&#x2F;&#x2F;www.apple.com&#x2F;business&#x2F;mac&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.apple.com&#x2F;business&#x2F;mac&#x2F;</a><p>&quot;Because OS X is secure by design, there’s no need for IT to install additional tools or lock down functionality for employees. And with an automated zero-touch deployment process, they don’t even have to open the box.&quot;
评论 #12455862 未加载
评论 #12455676 未加载
评论 #12455880 未加载
评论 #12455554 未加载