CryptoMagazine
    What's Hot

    Evertwine To Launch A New Free-to-Play Blockchain TCG Game and NFT Ecosystem

    2023-02-26

    The Ultimate Impact of Blockchain Technology on Global Finance

    2023-02-26

    Solana Blockchain hit by hours-long network slowdown and technical problems

    2023-02-26
    Facebook Twitter Instagram
    LinkedIn Facebook Twitter YouTube Discord Telegram BlogLovin
    CryptoMagazineCryptoMagazine
    ํ™”์š”์ผ, 3์›” 21
    • #FTX
    • Daily News
    • Short News
    • Editor’s Pick
    • Project Review
    • Crypto
    • Defi
    • Game
    • NFT
    • Metaverse
    • Etc
    • Learn
    CryptoMagazine
    Home»Crypto»macOS targeted by evasive crypto-jacking malware
    Crypto

    macOS targeted by evasive crypto-jacking malware

    ICARUSBy ICARUS2023-02-24๋Œ“๊ธ€ ์—†์Œ3 Mins Read
    LinkedIn Facebook Twitter Telegram Email
    #image_title
    Share
    LinkedIn Facebook Twitter Telegram Email


    New malware targets macOS





    AppleInsider may earn an affiliate commission on purchases made through links on our site.

    An investigation has discovered a new evasive crypto-jacking malware on macOS distributed through pirated versions of Final Cut Pro.

    Jamf Threat Labs has spent the past few months tracking a family of malware that recently resurfaced. An earlier version is known in the security community, but the new iteration hasn’t seen much detection.

    During routine monitoring, Jamf received an alert about XMRig usage, a command-line tool for mining cryptocurrency. Although XMRig is frequently used for good, its customizable, open-source nature has also made it a well-liked option for bad actors.

    The team found the malware hiding in pirated versions of Final Cut Pro, Apple’s video editing software. This malicious version of Final Cut Pro was running XMRig in the background.

    Embedded malware script. Source: Jamf Labs

    Embedded malware script. Source: Jamf Labs

    It uses the Invisible Internet Project (i2p) for communication, a private network layer that can anonymize traffic. The malware uses it to download malicious components and send mined currency to the attacker’s wallet.

    Jamf searched through The Pirate Bay, a famous repository for pirated music, movies, software, and other file categories. They downloaded the most recent torrent with the highest number of seeders and found it contained malware.

    The uploader was the source of the malware and the source of the previously reported samples. Almost all the numerous uploads that started in 2019 were infected with a malicious payload to covertly mine cryptocurrency.

    After a user installs the infected Final Cut Pro app, a process immediately starts to download and set up the malware and the XMRig command-line components. It disguises the mining as a “mdworker_local” process.

    Staying protected

    The researchers note that macOS Ventura can block the malicious app from running. It’s due to the malware leaving the original code signing intact but modifying the application, failing the system security policy.

    Gatekeeper blocking the app

    Gatekeeper blocking the app

    However, macOS Ventura doesn’t prevent the miner from executing. So, by the time the user receives an error message saying Final Cut Pro is damaged and can’t be opened, the malware has already been installed.

    The team only found the error message on pirated Logic Pro and Final Cut Pro versions. However, a pirate version of Photoshop successfully launched the malicious and working components on macOS Ventura 13.2 and earlier.

    The most obvious way to avoid malware is not to download pirated software. Final Cut Pro is expensive at $299.99, but iMovie and DaVinci Resolve are both free options.

    VirusTotal image showing malicious binary with 0 detections from other vendors. Taken by Jamf Threat Labs on February 10, 2023

    VirusTotal image showing malicious binary with 0 detections from other vendors. Taken by Jamf Threat Labs on February 10, 2023

    At the time of discovery, Jamf found that the malware sample wasn’t detected as malicious by any security vendors on VirusTotal, a website that can detect malware. From January 2023, a few unnamed vendors appeared to have started detecting the malware, however, some maliciously altered programs continue to go undetected.

    Therefore, users might be unable to rely on their antimalware software to detect the infection โ€” at least for now.



    Source link

    Share. LinkedIn Facebook Twitter Telegram Email
    ICARUS
    • Facebook
    • LinkedIn

    ICARUS (Kim min hoe): Cryptomagazine.live Publisher ๐Ÿ“ข Contact - Telegram: https://t.me/TSA_XICARUS - Kakao Talk: https://open.kakao.com/o/sXad89x - Email: xicarus2@gmail.com

    Related Posts

    Police discovered a secret crypto-mining operation beneath a US high school

    2023-02-26

    2022 Crypto Crash: 4 Bitcoin Moguls Who Suffered Huge Losses

    2023-02-26

    Polygon’s race to become Ethereum’s top sidechain

    2023-02-26

    Comments are closed.

    Game

    Evertwine To Launch A New Free-to-Play Blockchain TCG Game and NFT Ecosystem

    By ICARUS2023-02-260

    Zagreb, Croatia, Februaryย 25, 2023ย /ย AlexaBlockchain/ โ€“ย Evertwine, a free-to-play blockchain trading card game and NFT ecosystem, is…

    The Ultimate Impact of Blockchain Technology on Global Finance

    2023-02-26

    Solana Blockchain hit by hours-long network slowdown and technical problems

    2023-02-26

    Largest NFT Dump ever: Whale sold 1010 NFTs in 2 days

    2023-02-26

    How Eco-friendly Is The Metaverse? Road To Sustainability | Ask The Experts

    2023-02-26
    Popular posts
    • Evertwine To Launch A New Free-to-Play Blockchain TCG Game and NFT Ecosystem
    • The Ultimate Impact of Blockchain Technology on Global Finance
    • Solana Blockchain hit by hours-long network slowdown and technical problems
    • Largest NFT Dump ever: Whale sold 1010 NFTs in 2 days
    • How Eco-friendly Is The Metaverse? Road To Sustainability | Ask The Experts

    Editors Picks

    New beginning โ€“ TSA.Land

    2023-01-02

    ํ•œ๊ตญ ์ปค๋ฎค๋‹ˆํ‹ฐ๋งŒ์„ ์œ„ํ•œ ํ™”์ดํŠธ๋ฆฌ์ŠคํŠธ ์ ‘์ˆ˜(๋‹จ ํ•˜๋ฃจ)

    2022-11-26

    How Crypto Scams Get the job done โ€” A Reminder In The Age Of Digital Environment

    2022-11-22

    BTC internal transfer diagnosis worth about 2 trillionin response to Binance’s urgent request

    2022-11-18

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement

    Cryptomagazine provides the latest news and information on the future related to blockchain and cryptocurrency.

    About Us / Privacy Policy / terms-of-service

    ยฉ 2021 CryptoMagazine.live All rights reserved

    Facebook Twitter YouTube LinkedIn Discord Telegram BlogLovin
    Comprehensive Economy Magazine - Tstock.net

    Type above and press Enter to search. Press Esc to cancel.