HomeSecurityOceanLotus Mac Trojan Pretends to be a Flash Installer

OceanLotus Mac Trojan pretends to be a Flash Installer

For some strange reason, the Mac version of the OceanLotus trojan detected in May 2015 was not voted down by any antivirus engine, even though it presented several dangerous characteristics.

The discovery was made by security researchers at AlienVault, who note that, ten months after Qihoo 360 researchers uncovered this malware campaign, they noticed that none of the security products listed on VirusTotal had detected the Mac version of the trojan.

OceanLotus Mac Trojan pretends to be a Flash Installer

In their report, Qihoo 360 researchers say they discovered four versions of the OceanLotus trojan, one of which was specifically created to attack Apple computers. The trojan has been used primarily against Chinese targets, most of which were government organizations, educational institutions, and local companies specializing in maritime trade.

Just like the Windows variants, the Mac version of OceanLotus used fake Adobe Flash installations to infect users' computers.

This version comes with support for i386 and x86_64 Mac architectures and once installed, it also implements bootpersistenceby installing its own Launch Agent.

Of course, as is the case with every modern malware family, the trojan uses a C&C (command and control) server to communicate with its owners, from where it receives instructions on what to steal.

The trojan has powerful espionage capabilities, is able to get a list of local running applications, a list of recently opened documents, and can take screenshots of the user's desktop.

Additionally, the trojan's C&C server can tell the malware to download various files, unzip application bundles, run applications, execute code from a dynamic library, close some processes, and delete files.

“The use of specific OS X commands and APIs is evidence that the authors are intimately familiar with the operating system and have spent considerable time adapting it for the OS X environment,” notes AlienVault’s Eddie Lee. “The OS X version of OceanLotus is clearly a mature piece of malware written specifically for OS X.”

In addition to the mature version, which was very reminiscent of its Windows, AlienVault also reported seeing a simpler version of OceanLotus, which appears to be an intermediate variant for testing only.

Since AlienVault's report, the detection rate on VirusTotal has gone from 0/55 to 22/55. So, given that the team that developed OceanLotus was considered very skilled at targeting victims per attack, regular users should be pretty safe from this threat now.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS