Showing posts with label spying. Show all posts
Showing posts with label spying. Show all posts

Tuesday, May 2, 2017

New MacOS Malware, Signed With Legit Apple ID, Found Spying On HTTPS Traffic


Thursday, April 27, 2017 Swati Khandelwal


Many people believe that they are much less likely to be bothered by malware if they use a Mac computer, but is it really true? Unfortunately, No.

According to the McAfee Labs, malware attacks on Apple's Mac computers were up 744% in 2016, and its researchers have discovered nearly 460,000 Mac malware samples, which is still just a small part of overall Mac malware out in the wild.

Today, Malware Research team at CheckPoint have discovered a new piece of fully-undetectable Mac malware, which according to them, affects all versions of Mac OS X, has zero detections on VirusTotal and is "signed with a valid developer certificate (authenticated by Apple)."



Dubbed DOK, the malware is being distributed via a coordinated email phishing campaign and, according to the researchers, is the first major scale malware to target macOS users.

The malware has been designed to gain administrative privileges and install a new root certificate on the target system, which allows attackers to intercept and gain complete access to all victim communication, including SSL encrypted traffic.

Just almost three months ago, Malwarebytes researchers also discovered a rare piece of Mac-based espionage malware, dubbed Fruitfly, that was used to spy on biomedical research center computers and remained undetected for years.


Here's How the DOK Malware Works:
The malware is distributed via a phishing email masquerading as a message regarding supposed inconsistencies in their tax returns, tricking the victims into running an attached malicious .zip file, which contains the malware.

Since the malware author is using a valid developer certificate signed by Apple, the malware easily bypasses Gatekeeper -- an inbuilt security feature of the macOS operating system by Apple. Interestingly, the DOK malware is also undetectable in almost all antivirus products.



Once installed, the malware copies itself to the /Users/Shared/ folder and then add to "loginItem" in order to make itself persistent, allowing it to execute automatically every time the system reboots, until it finishes to install its payload.

The malware then creates a window on top of all other windows, displaying a message claiming that a security issue has been identified in the operating system and an update is available, for which the user has to enter his/her password.

Once the victim installed the update, the malware gains administrator privileges on the victim's machine and changes the victim system's network settings, allowing all outgoing connections to pass through a proxy.

According to CheckPoint researchers, "using those privileges, the malware will then install brew, a package manager for OS X, which will be used to install additional tools – TOR and SOCAT."


DOK Deletes itself after Setting up Attacker's Proxy
The malware then installs a new root certificate in the infected Mac, which allows the attacker to intercept the victim’s traffic using a man-in-the-middle (MiTM) attack.

"As a result of all of the above actions, when attempting to surf the web, the user’s web browser will first ask the attacker web page on TOR for proxy settings," the researchers say.

"The user traffic is then redirected through a proxy controlled by the attacker, who carries out a Man-In-the-Middle attack and impersonates the various sites the user attempts to surf. The attacker is free to read the victim's traffic and tamper with it in any way they please."According to researchers, almost no antivirus has updated its signature database to detect the DOK OS X malware, as the malware deletes itself once it modifies proxy settings on the target machines for interceptions.

Apple can resolve this issue just by revoking the developer certificate being abused by the malware author.

Meanwhile, users are always recommended to avoid clicking links contained in messages or emails from untrusted sources and always pay extra attention before proving your root password.

Wednesday, April 12, 2017

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks
The US National Security Agency (NSA) has been spying on Pakistan’s mobile networks, whistleblowing organisation WikiLeaks has tweeted. “Hundreds of NSA cyber weapons variants publicly released including code showing hacking of Pakistan mobile system,” @wikileaks tweeted.
According to a report in Express Tribune on Monday, the hacker group “Shadow Brokers” released a new cache of information detailing how the NSA accessed private and public networks in other countries. A researcher on Twitter who identifies himself as ‘x0rz’ decrypted the files and uploaded them on Github, a web-based repository and internet hosting service.
“The researcher confirmed that the archives include evidence of NSA operators’ access inside the GSM network of Mobilink – one of the Pakistan’s most popular mobile services provider,” the report noted. The hacker group had previously released data suggesting the US agency may have been monitoring hundreds of IP addresses in Pakistan. The encrypted files were being decrypted by security researchers around the world.
“Shadow Brokers” had initially wanted to auction its data cache in exchange for Bitcoin but as no buyer turned up, they released the data online. This is not the first time that reports have surfaced claiming that the US NSA is snooping on other countries. According to a Daily Mail report in 2014, WikiLeaks disclosed documents that suggested the Bharatiya Janata Party (BJP) was among six political parties from around the world the NSA was authorised to conduct surveillance on for gathering foreign intelligence. The authorisation was given by a secret American court, it said.
The leak was planned months ahead of Prime Minister Narendra Modi’s visit to the US, the report claimed. Another report in the Washington Post that also came in 2014 said the US has long had broad no-spying arrangements with four countries – Britain, Canada, Australia and New Zealand – in a group known collectively as the “Five Eyes”.
“But a classified 2010 legal certification – approved by the Foreign Intelligence Surveillance Court and included among a set of documents leaked by former NSA contractor Edward Snowden – lists 193 countries [including India], that would be of valid interest for US intelligence,” the Post said.
Publish date: April 12, 2017 11:45 am| Modified date: April 12, 2017 11:41 am

Saturday, December 10, 2016

US and UK spies tried accessing data from passengers’ mobile phones on commercial airline, says report

US and UK spies tried accessing data from passengers’ mobile phones on commercial airline, says report

American and British spy agencies have tried to intercept data from passengers’ mobile phones on commercial airlines including Air France, French media has reported, citing documents from US whistleblower Edward Snowden.
The French flag-carrier was an early target of the US National Security Agency and its British counterpart GCHQ as it was seen as a terrorist target and it carried out tests in 2007 on allowing the use of mobile phones on its aircraft.
“The use of mobile phones with Internet connections in the sky gave rise to the creation of specific programs at the NSA and GCHQ,” said Le Monde, which has access to Snowden’s archive in partnership with news website The Intercept.
While it is not normally possible to make phone calls on planes, some carriers allow passengers to connect to a cabin Wi-Fi, allowing them to use internet-based functions on their handsets.
In 2012, at least 27 airlines allowed passengers to use mobile phones on board, including British Airways, Aeroflot, Etihad, Cathay Pacific, Lufthansa and Singapore Airlines.
But Air France was “such a symbol of the surveillance of communications on board airlines that the British spy agency used a drawing of one of their planes to illustrate how the interception worked.”
Asked about the British and American surveillance claims, Air France told Le Monde, “We are visibly not the only ones to have been targeted and we know absolutely nothing about these practices.”
According to the report, internal documents from the two agencies describe the results of the “impressive” programs – codenamed “Thieving Magpie” and “Homing Pigeon” – which allowed data to be collected “almost in real time”.
In order to spy on a telephone, all that was needed was that the aircraft be cruising at an altitude above 10,000 feet, the report said.
Secret aerial stations on the ground could intercept the signal as it transited through a satellite.
“The simple fact that the telephone was switched on was enough to give away its position, the interception could then be cross-referenced with the list of known passengers on the flight, the flight number, and the airline code to determine the name of the smartphone user,” the report said.
The mobile phone’s function could also be disrupted, it said, forcing the user to input their access codes and thereby allowing the British spy agency to intercept the information.
Snowden, a former National Security Agency contractor, leaked thousands of classified documents to the press in 2013 which revealed the vast scope of US surveillance of private data that was put in place after the 9/11 attacks.
After fleeing his home in Hawaii, he now lives in exile in Russia where he has sought asylum.
Should he ever return to the United States, Snowden would be tried for espionage and other charges carrying up to 30 years in prison.
AFP

Related Posts Plugin for WordPress, Blogger...