Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Mac malware, possibly made in Iran, targets US defense industry (Doesn't work)
MacDailyNews ^ | Tuesday, February 7, 2017 ยท 4:50 pm

Posted on 02/07/2017 10:57:59 PM PST by Swordmaker

“Just because you’re using a Mac doesn’t mean you’re safe from hackers,” Michael Kan reports for IDG News Service. “That’s what two security researchers are warning, after finding a Mac-based malware that may be an attempt by Iranian hackers to target the U.S. defense industry.”

“The malware, called MacDownloader, was found on a website impersonating the U.S. aerospace firm United Technologies, according to a report from Claudio Guarnieri and Collin Anderson, who are researching Iranian cyberespionage threats,” Kan reports. “The fake site was previously used in a spear phishing email attack to spread Windows malware and is believed to be maintained by Iranian hackers, the researchers claimed.”

“Visitors to the site are greeted with a page about free programs and courses for employees of U.S. defense companies Lockheed Martin, Raytheon, and Boeing,” Kan reports. “The malware itself can be downloaded from an Adobe Flash installer for a video embedded in the site. The website will provide either Windows or Mac-based malware, depending on the detected operating system.”

“The MacDownloader malware was designed to profile the victim’s computer, and then steal credentials by generating fake system login boxes and harvesting them from Apple’s password management system, Keychain. However, the malware is of shoddy quality and is ‘potentially a first attempt from an amateur developer,’ the researchers said,” Kan reports. “The malware failed to run a script to download additional malicious coding onto the infected Mac. But despite the shoddy quality, the malware still managed to evade detection on VirusTotal, which aggregates antivirus scanning engines.”

Read more in the full article here.

MacDailyNews Note: If you receive what you believe to be a phishing email purporting to be from Apple, send it to reportphishing@apple.com, a monitored email inbox, which does not generate individual email replies.

Forwarding the message with complete header information provides Apple with important information. To do this in OS X Mail, select the message and choose Forward As Attachment from the Message menu.


TOPICS: Business/Economy; Computers/Internet; Conspiracy
KEYWORDS: applepinglist; flash; iran; malware; symantec; windowspinglist
Note this is another FLASH malware and another reason to not have FLASH installed on your Mac or Windows computer. On the Mac it failed to work to steal any passcodes because to access the keychain requires the re-input of the user's password to access the password directly from the keychain.
1 posted on 02/07/2017 10:57:59 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: Nailbiter

bflr


2 posted on 02/07/2017 10:59:08 PM PST by Nailbiter
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; ~Kim4VRWC's~; 1234; 5thGenTexan; Abundy; Action-America; acoulterfan; AFreeBird; ...
A new malware found for Macs that is based on FLASH. . . But it doesn't work as it is an amateurish effort. Apparently written by someone in Iran, it appears to be targeted towards the US Military with Macs and Windows. Another good reason to not have FLASH installed on your computers! — PING!

Pinging dayglored for malware targeting both Mac and Windows.


Just SAY NO TO FLASH!
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

3 posted on 02/07/2017 11:03:23 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

sadly, our users take “compliance training” with software that is flash dependent. I’ve just started using Windows Packaging Publisher via WSUS to start pushing Flash updates/patches to about 1000 endpoints. We don’t have SCCM.


4 posted on 02/08/2017 1:35:35 AM PST by AbolishCSEU (Amount of CS paid is inversely proportionate to Mother's actual parenting of children)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Swordmaker; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ...
> Pinging dayglored for malware targeting both Mac and Windows.

Malware, Windows and Mac ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Swordmaker for the ping!!

5 posted on 02/08/2017 6:57:13 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: Swordmaker

I use Flash on Linux and haven’t seen any updates in the last week or so. I wonder if Linux is affected.


6 posted on 02/08/2017 8:39:44 AM PST by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; All

Does anyone know if the windows insider program makes the user unable to turn off all the ‘phone home’ junk in windows 10? Do they require that you send them info automatically such as usage, browsing etc for purposes of development?

I missed out on the offer of windows 10 because I procrastinated too long- but I don’t relish the thought of not having control over phone home junk if that would be the case with the insider program


7 posted on 02/08/2017 8:42:00 AM PST by Bob434
[ Post Reply | Private Reply | To 5 | View Replies]

To: Dalberg-Acton

that reminds me, i just installed fresh linux mint 18.1 and forgot to enable firewall- lol thanks for the reminder


8 posted on 02/08/2017 8:44:01 AM PST by Bob434
[ Post Reply | Private Reply | To 6 | View Replies]

To: Bob434
> Does anyone know if the windows insider program makes the user unable to turn off all the ‘phone home’ junk in windows 10? Do they require that you send them info automatically such as usage, browsing etc for purposes of development?

Good question, I honestly don't know, but I assume that the point of the insider program is precisely to gather telemetry like crazy. I can't imagine they would give away advance copies of releases unless they were looking for more detailed feedback not merely opinions.

9 posted on 02/08/2017 9:14:21 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

[[but I assume that the point of the insider program is precisely to gather telemetry like crazy.]]

Yep- that would be my assumption too- I would think they’d want to see how ‘real world’ computers handle the code- ie: how vastly different setups and hardware, and software configurations would handle it- The average users like me wouldn’t know hardly any of these things- something would go wrong and we just wouldn’t know what caused it or how to fix it- but if the error messages were sent to MS automatically, they could use it for development purposes without the user needing to know the intricate details of the problem

But then again- perhaps they don’t- i just don’t know- it just seems more probable that they would


10 posted on 02/08/2017 9:31:27 AM PST by Bob434
[ Post Reply | Private Reply | To 9 | View Replies]

To: AbolishCSEU

Even if you had sccm you should need Shavlik to push flash or Java updates via windows updates. It’s pretty slick


11 posted on 02/08/2017 10:33:05 AM PST by miliantnutcase
[ Post Reply | Private Reply | To 4 | View Replies]

To: miliantnutcase

I’ve heard of that. Right now I’m relegated to WPP. I got Java 8_121 to push but without configurations. I’m not a coder so I find it difficult to write configuration files such as exception sites, etc.


12 posted on 02/08/2017 1:25:17 PM PST by AbolishCSEU (Amount of CS paid is inversely proportionate to Mother's actual parenting of children)
[ Post Reply | Private Reply | To 11 | View Replies]

To: AbolishCSEU

I’m in the same boat I’m just an IT Engineer/Manager I try to use off the shelf solutions for deployments our dev team is busy with non-client stuff. I build silent deployment packages but the .exe or base base .MSI has to already support it. Flexera Admin Studio is a great option but it’s very spendy.


13 posted on 02/08/2017 1:56:07 PM PST by miliantnutcase
[ Post Reply | Private Reply | To 12 | View Replies]

To: miliantnutcase

I work for the local county—they don’t spend money on anything except 30-lifer’s salaries.


14 posted on 02/09/2017 4:54:51 AM PST by AbolishCSEU (Amount of CS paid is inversely proportionate to Mother's actual parenting of children)
[ Post Reply | Private Reply | To 13 | View Replies]

To: AbolishCSEU

I hear ya! Do you everything for them IT wise?


15 posted on 02/09/2017 9:33:34 AM PST by miliantnutcase
[ Post Reply | Private Reply | To 14 | View Replies]

To: miliantnutcase

No we have a more recent hire from the private sector such as myself that do all the work. The “lifers” here are stuck on their old programming skills (fox pro) and refuse to learn anything new after 30 years on the job. Basically they are being paid to do little or nothing.

I do WSUS, desktop support, help the sr. network analyst—recent private sector guy who knows his stuff. Two desktop support people were voluntold to leave—aka forced retirement in the last two years after refusing to change their attitude. I have picked up the slack there pretty much exclusively.

We have two “lifers” left in IT; one who pushes the envelope stirs the pot just so far to escape trouble (ex. calls the boss to ask him what the number to Dell support is)—same guy who REFUSES to learn a new programming language and just makes it miserable for others by refusing to pitch in.


16 posted on 02/09/2017 9:59:24 AM PST by AbolishCSEU (Amount of CS paid is inversely proportionate to Mother's actual parenting of children)
[ Post Reply | Private Reply | To 15 | View Replies]

To: AbolishCSEU

Sounds like most government IT shops. Have a buddy who’s CIO for a school system and he’s dealing with the same issues. These state union dumbasses are so inflexible.


17 posted on 02/09/2017 2:35:25 PM PST by miliantnutcase
[ Post Reply | Private Reply | To 16 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson