HomeSecuritymacOS Malware Evaded Detection Through Run-Only AppleScripts

macOS malware evaded detection via run-only AppleScripts

According to security firm SentinelOne, users have been targeted by a sneaky malware campaign for more than five years. The campaign used a clever trick (run-only AppleScripts) to evade detection and aimed to mine cryptocurrency macOS systems victims'

macOS run-only AppleScripts
macOS malware evaded detection via run-only AppleScripts

Researchers said the malware used in the campaign is called OSAMiner and has been distributed since at least 2015, through pirated (cracked) games and software, such as League of Legends and Microsoft Office for Mac.

“OSAMiner has been active for a long time and has evolved in recent months,” a SentinelOne spokesperson told ZDNet.

“From the data we have, it appears to be primarily targeting communities in China and the Asia-Pacific region,” the spokesperson added.

Run-only AppleScripts to avoid detection

As we said above, the cryptominer has been distributed since at least 2015. However, according to SentinelOne, two Chinese security firms detected and analyzed older versions of OSAMiner in August and September 2018, respectively.

Their reports, however, were incomplete, identifying only a few of OSAMiner's capabilities. This was partly due to the fact that the researchers were unable to recover the entire malware code at the time.

After installing the pirated software, the boobytrapped installers download and execute a run-only AppleScript, which downloads and executes a second run-only AppleScript, and then a third.

macOS malware evaded detection via run-only AppleScripts
macOS malware evaded detection via run-only AppleScripts

Since “run-only” AppleScript is in a state where the source code is not human-readable, analyzing the cryptominer is even more difficult.

A SentinelOne researcher has published details of the attack, along with indicators of compromise (IOCs) from older and newer OSAMiner campaigns. The research team hopes that by breaking the mystery surrounding this campaign and publishing IOCs, other security will be able to detect OSAMiner attacks and protect users .

“Run-only AppleScripts are surprisingly rare in the world of macOS malware, but both the duration (5 years) and the lack of attention to the OSAMiner campaign show just how powerful run-only AppleScripts are in avoiding detection and analysis,” the researcher concluded.

“In this case, we didn't see the attacker using any of the more powerful AppleScript capabilities we've discussed elsewhere. However, it's a threat that remains potent because many defense tools can't handle it.“.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS