Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > News > Mac News > New OS X 'KitM.A' malware discovered, mostly impotent

New OS X 'KitM.A' malware discovered, mostly impotent
Thread Tools
MacNN Staff
Join Date: Jul 2012
Status: Offline
Reply With Quote
May 16, 2013, 05:08 PM
 
A new semi-functional malware has been found for OSX. Discovered on a computer at the Oslo Freedom Forum by researcher Jacob Appelbaum, the OSX/KitM.A is a backdoor application which launches on boot and captures screenshots on a regular basis, which are then dumped in a folder.


The malware has two command and control servers, with one nonfunctional and one delivering a 403 - public access forbidden warning. It is unknown if the servers were ever put into service, or will be running in the future.

The malware is signed with a legitimate Apple Developer ID, which can bypass Apple's built-in malware installation block. The source of the malware is under investigation by anti-virus company F-Secure. Apple has not as of yet revoked the developer's signature.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -4. The time now is 01:07 AM.
All contents of these forums © 1995-2015 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2015, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2