Malware News New MAC complex trojan used for cyber-espionage

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Security researchers have discovered Komplex, a new Mac OS X trojan, which they say is tied to the activities of a cyber-espionage group named Sofacy, operating out of Russia.

Researchers say they've only spotted the malware payloads until now and haven't tied it to any infected victims. Nevertheless, they say that based on the document lures used during its operation, the trojan samples seem to have been customized to target individuals in the aerospace industry.

Palo Alto Networks, the company that detected the trojan, says there are three versions of this trojan known to date. There's a version that can target x64 architectures, one for x86 architectures, and another for both.Komplex uses MacKeeper vulnerability to compromise targetsSecurity experts say the infection occurs when the trojan's first-stage component leverages a vulnerability in the MacKeeper Mac antivirus application to get a foothold on a Mac computer.

From the samples they analyzed, researchers say this first-stage component is disguised as a PDF document presenting details about Russia's Federal Space Program.

The first-stage component gets boot persistence by adding its own .plist file to the computer's startup routine and then downloads the so-called Komplex payload dropper.

This second-stage component gathers data about the system, and only when an Internet connection is active, starts communicating with the C&C server, sending details about the infected host.Komplex has basic, but intrusive, featuresAt this point, the C&C server will decide what other Komplex modules to send over. Researchers say they've identified modules that allow Sofacy operators to download files on the infected hosts, gather and steal data, or execute commands.

Palo Alto says the Komplex trojan was the same trojan discovered in June 2015 by BAE Systems. Furthermore, based on the trojan's mode of operation and source code structure, they feel positive Komplex is a Mac port of the Carberp Windows trojan deployed in late May against a US government official.

The Sofacy group, also known as Fancy Bear, APT28, Sednit, Pawn Storm, or Strontium, is one of the most active cyber-espionage groups known today. APT28 is believed to be one of the groups that hacked the DNC in the summer of 2015, and behind the recentWADA data leaks.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top