A highly dangerous malware is being distributed through a coordinated email phishing campaign, intercepting user traffic – including SSL-encrypted communications.

The Dok malware was discovered by security researchers at Check Point, who report that the malware affects all versions of Mac OS X and is digitally undetectable on VirusTotal. What makes matters worse is that the malware is digitally signed by Apple, having received a valid developer certificate.

Once a system is infected with Dok, attackers gain full access to all of the victims' communications, including those encrypted via SSL.
Security researchers have discovered that the malware primarily targets European users and the phishing technique used is quite sophisticated. One of the email samples detected informs the potential victim of an alleged inconsistency in their tax return.
The malware is contained in a file named Dokument.zip. Once executed, the malware copies itself to /Users/Shared/Folder and begins executing. A pop-up window then appears stating that the file is corrupted and cannot be executed.

In fact, if there is a loginItem named “AppStore”, the malware deletes it and adds itself instead. This way the malware remains on the system and runs automatically every time the system is rebooted, until it finishes installing its payload.

A new window then appears informing victims that a security issue has been identified in their operating system for which a new update is available.

Users cannot access any windows or use the computer until they enter the password requested to complete the supposed system update process, at which point the malware completes its installation.
Once this happens, a new root certificate is installed on the infected device, which allows cybercriminals to monitor victims' traffic, via the Man in The Middle (MiTM) attack technique.
"The malware changes the victim's network settings so that all outgoing connections go through a proxy server, which is dynamically obtained from a Proxy AutoConfiguration (PAC) file located on a malicious server," the researchers note.
