Microsoft on Wednesday shed light on a previously undocumented Mac trojan that it said has undergone several iterations since its first appearance in September 2020, effectively granting it an "increasing progression of sophisticated capabilities."
The company's Microsoft 365 Defender Threat Intelligence Team dubbed the new malware family "UpdateAgent," charting its evolution from a barebones information stealer to a second-stage payload distributor as part of multiple attack waves observed in 2021.
"The latest campaign saw the malware installing the evasive and persistent Adload adware, but UpdateAgent's ability to gain access to a device can theoretically be further leveraged to fetch other, potentially more dangerous payloads," the researchers said.
The actively in-development malware is said to be propagated via drive-by downloads or advertisement pop-ups that masquerade as legitimate software like video applications and support agents, even as the authors have made steady improvements that have transformed UpdateAgent into a progressively persistent piece of malware.
Chief among the advancements include the capability to abuse existing user permissions to surreptitiously perform malicious activities and circumvent macOS Gatekeeper controls, a security feature that ensures only trusted applications from identified developers can be installed on a system.
In addition, UpdateAgent has been found to take advantage of public cloud infrastructure, namely Amazon S3 and CloudFront services, to host its second-stage payloads, including adware, in the form of .DMG or .ZIP files.
Once installed, the Adload malware makes use of ad injection software and man-in-the-middle (MitM) techniques to intercept and reroute users' internet traffic through the attacker's servers to insert rogue ads into web pages and search engine results to increase the chances of multiple infections on the devices.
"UpdateAgent is uniquely characterized by its gradual upgrading of persistence techniques, a key feature that indicates this trojan will likely continue to use more sophisticated techniques in future campaigns," the researchers cautioned.
More articles
- Pentest Tools Tcp Port Scanner
- Black Hat Hacker Tools
- Hacker Tools Hardware
- Hacking Tools And Software
- Hacker Tools Mac
- Hacking Tools And Software
- Pentest Tools Port Scanner
- Pentest Tools Find Subdomains
- Easy Hack Tools
- Pentest Tools Website Vulnerability
- Hacker Tools
- Hacking Tools Windows 10
- Easy Hack Tools
- Hacker Search Tools
- Pentest Tools For Ubuntu
- Hacker Tools Online
- Pentest Tools Online
- Pentest Tools Framework
- Hacking Apps
- Pentest Tools Subdomain
- Computer Hacker
- Best Hacking Tools 2020
- Hacker Tools Windows
- Pentest Tools For Android
- Blackhat Hacker Tools
- Hacking Tools And Software
- Hack Tools Github
- Pentest Tools Windows
- How To Install Pentest Tools In Ubuntu
- Nsa Hack Tools
- Hacker Tools For Pc
- Hacking Apps
- Pentest Tools Website
- Pentest Tools List
- Pentest Tools Website Vulnerability
- Hacker Tools For Pc
- Hacker Search Tools
- Pentest Tools Nmap
- Game Hacking
- How To Hack
- Hackrf Tools
- Hacking Tools Online
- Hacker Tools Online
- Hacking Tools For Pc
- Hacker Tools
- Hack Tools Pc
- Hacking Tools Online
- Hack Tools Mac
- How To Hack
- Hacking Tools Kit
- Blackhat Hacker Tools
- Hacker Tools Apk
- Hacking Tools Usb
- Hack Tools For Pc
- Hack Tool Apk
- Hacking Tools Hardware
- Easy Hack Tools
- Hacking Tools And Software
- World No 1 Hacker Software
- Pentest Tools Website Vulnerability
- Hacking Tools
- Github Hacking Tools
- Hacker Tools 2020
- Hacking Tools Hardware
- Hack Tools
- Game Hacking
- Hacker Tools Linux
- Hacking Tools Download
- Hacking Apps
- Pentest Tools Url Fuzzer
- Tools For Hacker
- Hacking Tools For Mac
- Hacking Tools For Kali Linux
- Hacking Tools For Beginners
- Hacker Hardware Tools
- Hack Tools Online
- Free Pentest Tools For Windows
- Hack Tools Mac
- Pentest Tools Subdomain
- Hack Tools For Windows
- Hackrf Tools
- Pentest Tools For Ubuntu
- Pentest Tools Open Source
- Hack Apps
- Android Hack Tools Github
- Tools 4 Hack
- Wifi Hacker Tools For Windows
- Pentest Tools Android
- How To Make Hacking Tools
- Hacker Tools Free
- New Hacker Tools
- How To Make Hacking Tools
- Pentest Recon Tools
- Pentest Tools Apk
- Hacker
- Free Pentest Tools For Windows
- Pentest Reporting Tools
- Pentest Tools
- Growth Hacker Tools
- Hack Apps
- Hack Tools Pc
- Hacking Tools 2020
- Hacker Tools Mac
No hay comentarios:
Publicar un comentario