BPC Squad Bank Paypal And Cards | Carders Forum | Carding Forum

- Advertisement Area (For purchasing Ads or Banner contact ) Jabber [email protected] -(Telegram : @bpclover) -




Jerry's Store Excellent bases | AVS checker
Cerberux.CC The king shop with new checker feature attached + high quality spam cards direct from inbox.
Algae For Sale Global rare CC, Best Quality
CC+CVV Private Base Wholesale & Retail | Rare BINs
Bankman.biz Merchants, Banks US/EU, Crypto
BIGSTACKS DUMPS+PINS, EBT+PINS, CC+CVV




- Advertisement Area (For purchasing Ads or Banner contact )-Jabber-[email protected]

Best Regards
BPC Team







-BPCFORUM-  Registration Opened ####.


We are the Best one Carding Forum on Internet And you choose the right place to start Carding World so Enjoy your time with bpc , Also bpc is not responsible for any kind of post Because we are not a post owner So all stuff you will use at your own risk and If you face any kind of problem please feel free to contact with us.. Telegram : @bpclover
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5


New MacOS Malware, Signed With Legit Apple ID, Found Spying On HTTPS Traffic
#1
[Image: mac-malware-proxy-setting.png]
Many people believe that they are much less likely to be bothered by malware if they use a Mac computer, but is it really true? Unfortunately, No.

According to the McAfee Labs, malware attacks on Apple's Mac computers were up 744% in 2016, and its researchers have discovered nearly 460,000 Mac malware samples, which is still just a small part of overall Mac malware out in the wild.

Today, Malware Research team at CheckPoint have discovered a new piece of fully-undetectable Mac malware, which according to them, affects all versions of Mac OS X, has zero detections on VirusTotal and is "signed with a valid developer certificate (authenticated by Apple)."

Dubbed DOK, the malware is being distributed via a coordinated email phishing campaign and, according to the researchers, is the first major scale malware to target macOS users.

The malware has been designed to gain administrative privileges and install a new root certificate on the target system, which allows attackers to intercept and gain complete access to all victim communication, including SSL encrypted traffic.

Just almost three months ago, Malwarebytes researchers also discovered a rare piece of Mac-based espionage malware, dubbed Fruitfly, that was used to spy on biomedical research center computers and remained undetected for years.

Here's How the DOK Malware Works:
[Image: mac-malware.png]
The malware is distributed via a phishing email masquerading as a message regarding supposed inconsistencies in their tax returns, tricking the victims into running an attached malicious .zip file, which contains the malware.

Since the malware author is using a valid developer certificate signed by Apple, the malware easily bypasses Gatekeeper -- an inbuilt security feature of the macOS operating system by Apple. Interestingly, the DOK malware is also undetectable in almost all antivirus products.

Once installed, the malware copies itself to the /Users/Shared/ folder and then add to "loginItem" in order to make itself persistent, allowing it to execute automatically every time the system reboots, until it finishes to install its payload.

The malware then creates a window on top of all other windows, displaying a message claiming that a security issue has been identified in the operating system and an update is available, for which the user has to enter his/her password.

Once the victim installed the update, the malware gains administrator privileges on the victim's machine and changes the victim system's network settings, allowing all outgoing connections to pass through a proxy.

According to CheckPoint researchers, "using those privileges, the malware will then install brew, a package manager for OS X, which will be used to install additional tools – TOR and SOCAT."

DOK Deletes itself after Setting up Attacker's Proxy
[Image: osx-malware.png]
The malware then installs a new root certificate in the infected Mac, which allows the attacker to intercept the victim’s traffic using a man-in-the-middle (MiTM) attack.
Quote: "As a result of all of the above actions, when attempting to surf the web, the user’s web browser will first ask the attacker web page on TOR for proxy settings," the researchers say.

"The user traffic is then redirected through a proxy controlled by the attacker, who carries out a Man-In-the-Middle attack and impersonates the various sites the user attempts to surf. The attacker is free to read the victim's traffic and tamper with it in any way they please."
According to researchers, almost no antivirus has updated its signature database to detect the DOK OS X malware, as the malware deletes itself once it modifies proxy settings on the target machines for interceptions.

Apple can resolve this issue just by revoking the developer certificate being abused by the malware author.

Meanwhile, users are always recommended to avoid clicking links contained in messages or emails from untrusted sources and always pay extra attention before proving your root password.

Update: Apple Revokes Certificate Used By Dok Mac Malware
[Image: mac-malware-apple.png]
After this story had gone up, Apple responded to the issue and revoked the legitimate developer certificate used by hackers behind the DOK malware that can be used to eavesdrop on victim's communication, including secure HTTPS traffic.

Quote: MalwareBytes has confirmed this in its blog post, which reads: "Apple has already revoked the certificate used to sign the app, so, at this point, anyone who encounters this malware will be unable to open the app and unable to be infected by it."

It further adds: "If the user clicks past this warning to open the app, it will display a warning that the file could not be opened, which is simply a cover for the fact that no document opened, as shown above."

Besides this, Apple also rolled out an update this weekend to its XProtect built-in anti-malware software in an attempt to prevent existing and future DOK-type malware attacks.



greendump24
Find Rate
Reply

#2
Thanks for the info. Fortunately, there is some kind of protection https://macsecurity.net/view/195-remove-mac-auto-fixer-virus
This is a complete knowledgebase covering the features of Mac Auto Fixer virus and providing intuitive manual and automatic instructions to remove it from Mac.
Find Rate
Reply

#3
Find Rate
Reply

#4
Thank you for this and I hope you keep more coming
Find Rate
Reply


Digg   Delicious   Reddit   Facebook   Twitter   StumbleUpon  


Possibly Related Threads…
Thread Author Replies Views Last Post
  APPLE METHOD c0c41nm4n 0 1,080 01-20-2023, 11:07 PM
Last Post: c0c41nm4n
  NEWS More Hacking Groups Found Exploiting SMB Flaw Weeks Before WannaCry GreenDumps24 2 5,161 08-02-2017, 01:53 PM
Last Post: newyear
  Hi DEAR USER'S, try my services and stay with me forever :) FIRE MALWARE/BOT Humble wolf 2 5,072 08-02-2017, 01:52 PM
Last Post: newyear
  Adwind RAT Returns! Cross-Platform Malware Targeting Aerospace Industries GreenDumps24 1 2,426 08-02-2017, 01:50 PM
Last Post: newyear
  Newly Found Malware Uses 7 NSA Hacking Tools, Where WannaCry Uses 2 GreenDumps24 1 2,391 05-23-2017, 06:50 PM
Last Post: czop1223
  Malware Hunter — Shodan's new tool to find Malware C&C Servers GreenDumps24 0 1,977 05-03-2017, 07:49 AM
Last Post: GreenDumps24
  NEWS Malware Bricking Insecure IoT Devices Could Be a Vigilante Tool Against Botnets GreenDumps24 1 2,220 04-28-2017, 11:02 PM
Last Post: aSpi
  TRAFFIC GOOGLE ADWORDS OXXO -NO BAN- rootsanzz 1 2,162 01-29-2017, 07:40 PM
Last Post: VOV
  How to card apple frfr. Swoopgawd00 0 1,849 10-04-2016, 01:05 PM
Last Post: Swoopgawd00
  Card apple Johntrey43 2 2,206 12-21-2015, 09:21 PM
Last Post: michaelwoody



Users browsing this thread:
4 Guest(s)

 
Carding forum