Jump to content

Warning: DNS Hijacking Malware Targeting Apple macOS Users

Jon4248

Sources; 

https://objective-see.com/blog/blog_0x26.html

https://thehackernews.com/2018/01/macos-dns-hijacker.html?m=1

https://9to5mac.com/2018/01/15/macos-dns-hijacking-malware/
 

Good thing I installed Malwarebytes today...

 

Quote

Dubbed OSX/MaMi, an unsigned Mach-O 64-bit executable, the malware is somewhat similar to DNSChanger malware that infected millions of computers across the world in 2012.

I have a few Mac computers, so this is a concern to me, as well as I feel it will be for a lot of other users.

It is my understanding it is very hard to detect tell that it has been installed until scanners are updated;

 

Quote

virusTotal.png

MacOS users may wish to check out their DNS settings;

Quote

First appeared on the Malwarebytes forum, a user posted a query regarding unknown malware that infected his friend's computer that silently changed DNS settings on infected macOS to 82.163.143.135 and 82.163.142.137 addresses.

I did check mine and they appear to be fine. I for sure do not want these types of issues; 

 

Quote
"OSX/MaMi isn't particularly advanced - but does alter infected systems in rather nasty and persistent ways," Patrick said.
"By installing a new root certificate and hijacking the DNS servers, the attackers can perform a variety of nefarious actions such as man-in-the-middle'ing traffic (perhaps to steal credentials, or inject ads)" or to insert cryptocurrency mining scripts into web pages.

Besides this, the OSX/MaMi macOS malware, which appears to be in its initial stage, also includes below-mentioned abilities, most of which are not currently activated in its version 1.1.0:

 
  • Take screenshots
  • Generate simulated mouse events
  • Perhaps persist as a launch item
  • Download and upload files
  • Execute commands

 

Link to comment
Share on other sites

Link to post
Share on other sites

Doesn't meet the requirements 

  • Your thread must include some original input to tell the reader why it is relevant to them, and what your personal opinion on the topic is. This needs to be MORE than just a quick, single comment to meet the posting guidelines.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just redirect @DrMacintosh to Pornhub. That'll teach 'em.

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, hey_yo_ said:

Doesn't meet the requirements 

  • Your thread must include some original input to tell the reader why it is relevant to them, and what your personal opinion on the topic is. This needs to be MORE than just a quick, single comment to meet the posting guidelines.

ya I was adding more, clicked post to quickly sorry sir 

Link to comment
Share on other sites

Link to post
Share on other sites

if ur a big dum dum and run unsigned software whut u think will happen. Its hardly anything newsworthy.

Link to comment
Share on other sites

Link to post
Share on other sites

50 minutes ago, RorzNZ said:

if ur a big dum dum and run unsigned software whut u think will happen. Its hardly anything newsworthy.

true, I guess we should just delete it then. 

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, Jon4248 said:

true, I guess we should just delete it then. 

 

55 minutes ago, RorzNZ said:

if ur a big dum dum and run unsigned software whut u think will happen. Its hardly anything newsworthy.

Just by the way, we don't delete threads unless they're directly in violation of our Community Standards.

 

Since this thread is about news (how relevant they are can be argued) and meets the guidelines, it'll stay on TnR :)

We have a NEW and GLORIOUSER-ER-ER PSU Tier List Now. (dammit @LukeSavenije stop coming up with new ones)

You can check out the old one that gave joy to so many across the land here

 

Computer having a hard time powering on? Troubleshoot it with this guide. (Currently looking for suggestions to update it into the context of <current year> and make it its own thread)

Computer Specs:

Spoiler

Mathresolvermajig: Intel Xeon E3 1240 (Sandy Bridge i7 equivalent)

Chillinmachine: Noctua NH-C14S
Framepainting-inator: EVGA GTX 1080 Ti SC2 Hybrid

Attachcorethingy: Gigabyte H61M-S2V-B3

Infoholdstick: Corsair 2x4GB DDR3 1333

Computerarmor: Silverstone RL06 "Lookalike"

Rememberdoogle: 1TB HDD + 120GB TR150 + 240 SSD Plus + 1TB MX500

AdditionalPylons: Phanteks AMP! 550W (based on Seasonic GX-550)

Letterpad: Rosewill Apollo 9100 (Cherry MX Red)

Buttonrodent: Razer Viper Mini + Huion H430P drawing Tablet

Auralnterface: Sennheiser HD 6xx

Liquidrectangles: LG 27UK850-W 4K HDR

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, RorzNZ said:

if ur a big dum dum and run unsigned software whut u think will happen. Its hardly anything newsworthy.

It's unsure how the malware actually gets to the system. It's also easy to trick the average user into thinking a piece of malware is a legitimate piece of software from a trusted source, ie. Chrome extension, antivirus, F2P game, etc.

 

Particularly when the (false) notion that an OS is inherently secure and impervious to these types of attacks exist.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

I bet its already patched xD 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, Jon4248 said:

I have a few Mac computers, so this is a concern to me, as well as I feel it will be for a lot of other users.

It is my understanding it is very hard to detect tell that it has been installed until scanners are updated;

Why? Because most AV vendors focus on detecting threats in Windows than in macOS even though threats on macOS is on the rise. That's why sometimes, freshly made malware gets detected by a few AV programs (heuristics or behavior analysis) and not to mention, Windows gives more access to AV programs to system resources like the kernel. I don't think macOS has given them that kind of access just yet. I could be wrong.

Edited by hey_yo_

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, DrMacintosh said:

I bet its already patched xD 

I'm never taking you to Vegas. I'd be broke the second we got there.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Drak3 said:

I'm never taking you to Vegas. I'd be broke the second we got there.

There is a reason they call it lost wages 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Energycore said:

 

Just by the way, we don't delete threads unless they're directly in violation of our Community Standards.

 

Since this thread is about news (how relevant they are can be argued) and meets the guidelines, it'll stay on TnR :)


I mean the notion of Macs not having viruses, or publicising this as a big threat. It is still worth knowing about, just in a different sense. It should definitely stay here for people to see.
 

1 hour ago, Drak3 said:

It's unsure how the malware actually gets to the system. It's also easy to trick the average user into thinking a piece of malware is a legitimate piece of software from a trusted source, ie. Chrome extension, antivirus, F2P game, etc.

 

Particularly when the (false) notion that an OS is inherently secure and impervious to these types of attacks exist.

You can't install unsigned apps from anywhere without unlocking the option. There are 3 tiers to choose from: Apps from the App Store, Apps from App Store and Identified Developers (Signed Apps), and from Anywhere. Any time you change these options and when you install an app that accesses the system you need to input your password / touchID / Apple Watch.

Now if you have it set to "anywhere" and you are a very naughty Mac user who gets their content through interesting means, this will be a problem. As with any virus this probably targets the gullible.

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, RorzNZ said:

You can't install unsigned apps from anywhere without unlocking the option. There are 3 tiers to choose from: Apps from the App Store, Apps from App Store and Identified Developers (Signed Apps), and from Anywhere. Any time you change these options and when you install an app that accesses the system you need to input your password / touchID / Apple Watch.

I wonder how this malware persisted this long probably even when Mac OS X Lion introduced Gatekeeper ?

Looks like in 2018 days will get bleaker when it comes to cybersecurity 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

46 minutes ago, hey_yo_ said:

I wonder how this malware persisted this long probably even when Mac OS X Lion introduced Gatekeeper ?

Looks like in 2018 days will get bleaker when it comes to cybersecurity 

Well i'm pretty interested to see the method used there as well. Thats a pretty extrodinary case, and like I said Macs certianly aren't immune to viruses. I myself run Sophos Antivirus. Hopefully that article has a follow-up. I'll keep an eye out in MacOS updates.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×