HomeinetA new unusual and clever malware for MAC

A new unusual and clever malware for MAC

janicab_2aSecurity researchers from F-Secure have discovered a very interesting malware designed for Mac devices. The most surprising thing about Backdoor:Python/Janicab.A is that it hides the malicious file using the Arabic script, i.e. right-to-left (RLO). This way it hides its extension.

Unicode RLO characters are designed to support languages ​​written from right to left, such as Hebrew or Arabic. However, malware developers using this technique have managed to mask the extensions of malicious files.

In the case of the Mac malware as analyzed by F-Secure, the malicious file has the extension .App (RecentNews.fdp.app). However, because they use the RLO script, Unicode characters are placed before the “f” and the file becomes RecentNews.ppa.pdf.

So instead of appearing as an application, the malicious file appears as a PDF. If someone tries to open it, it creates a cron job for its future launch, and a hidden folder that stores its components.

The malware gets its instructions on how to find its C&C server from YouTube videos and other websites.

Its main goal is to take screenshots and record audio files using a third-party application called Sox.

Janicab.A is written in Python, uses py2app for distribution, and is signed with an Apple Developer ID.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS