HomeSecurityMalicious Windows EXE files infect macOS users

Malicious Windows EXE files infect macOS users

exeSecurity researchers have discovered several Windows EXE files that use malicious payloads to infect macOS with infostealers and adware.

Trend Micro found a sample containing adware hidden within an installer for the Little Snitch firewall app for Windows and Mac, which is available for download from various torrent sites. The sample was able to bypass Mac's Gatekeeper, as this built-in protection mechanism does not perform code signature checks or otherwise verify EXE files on computers running macOS.

Inside a ZIP file downloaded from torrent sites, there is a DMG file that hosts the installer for Little Snitch. This installer hides an EXE file that loads an infostealer onto the computer. The malware then collects basic system information, such as Memory, BootROMVersion and SMCVersion, and scans the applications directory for installed applications, such as App Store, FaceTime and Mail. After completing these steps, the malware sends all its findings to its command-and-control (C&C) server.

Additionally, the executable file is capable of downloading many other files from the internet. These files, in turn, download adware and other potentially unwanted applications.

Bridging Windows and macOS with malicious software

These files are not the only case of a digital threat between Windows and macOS. In May 2017, for example, Fox-IT identified a macOS X version of the malicious software Snake, which traditionally targets the Windows platform. Less than a year later, security researcher Patrick Wardle of Objective-See revealed CrossRat, a versatile threat capable of targeting Windows, macOS, and Linux machines.

In some cases, researchers have even observed attack campaigns that distribute distinct threats targeting Windows and Mac computers. Microsoft security researchers faced such a case in 2011, which included the Olyx backdoor and other malicious Windows programs.

How to protect yourself from malicious EXE files

Security professionals can help you protect yourself from EXE files by creating security policies that limit the types of websites from which users can download applications. They can implement this policy within a broader application approval framework, through which security teams follow a logical sequence for uploading / reviewing applications and ensuring vendor consolidation. At the same time, security professionals should apply user activity analytics in a long‑term data repository to adequately protect corporate data from digital threats such as infostealers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS