HomeSecurityEncryption? It's no obstacle for the new Doc Malware

Encryption? Not a Barrier to the New Doc Malware

A highly dangerous malware is being distributed through a coordinated email phishing campaign, intercepting user traffic – including SSL-encrypted communications.

Encryption? Not a Barrier to the New Doc Malware

The Dok malware was discovered by security researchers at Check Point, who report that the malware affects all versions of Mac OS X and is digitally undetectable on VirusTotal. What makes matters worse is that the malware is digitally signed by Apple, having received a valid developer certificate.

Doc Malware

Once a system is infected with Dok, attackers gain full access to all of the victims' communications, including those encrypted via SSL.

Security researchers have discovered that the malware primarily targets European users and the phishing technique used is quite sophisticated. One of the email samples detected informs the potential victim of an alleged inconsistency in their tax return.

The malware is contained in a file named Dokument.zip. Once executed, the malware copies itself to /Users/Shared/Folder and begins executing. A pop-up window then appears stating that the file is corrupted and cannot be executed.

Encryption? Not a Barrier to the New Doc Malware

In fact, if there is a loginItem named “AppStore”, the malware deletes it and adds itself instead. This way the malware remains on the system and runs automatically every time the system is rebooted, until it finishes installing its payload.

Malware - AppStore

A new window then appears informing victims that a security issue has been identified in their operating system for which a new update is available.

Doc Malware - OS X Updates

Users cannot access any windows or use the computer until they enter the password requested to complete the supposed system update process, at which point the malware completes its installation.

Once this happens, a new root certificate is installed on the infected device, which allows cybercriminals to monitor victims' traffic, via the Man in The Middle (MiTM) attack technique.

"The malware changes the victim's network settings so that all outgoing connections go through a proxy server, which is dynamically obtained from a Proxy AutoConfiguration (PAC) file located on a malicious server," the researchers note.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS