HomeSecurity30,000 Macs infected with new Silver Sparrow malware

30,000 Macs infected with new Silver Sparrow malware

Security researchers have identified a new malware targeting Mac devices that has infected nearly 30,000 systems. The malware, dubbed Silver Sparrow, was discovered by security researchers from Red Canary and analyzed alongside researchers from Malwarebytes and VMWare Carbon Black.

“According to data provided by Malwarebytes, Silver Sparrow has infected 29,139 macOS endpoints in 153 countries since February 17 – including the United States, the United Kingdom, Canada, France, and Germany,” Red Canary’s Tony Lambert wrote in a report published last week.

However, despite the large number of infections, details about how the malware was distributed and the users infected are still unavailable, and it is unclear whether Silver Sparrow was hidden within malicious ads, pirated applications, or fake Flash updaters – the classic distribution vector for most Mac malware strains.

Furthermore, the purpose of this malware is also unclear and researchers do not know what its ultimate goal is.

Once Silver Sparrow infects a system, the malware waits for new commands from its operators – commands that never arrived during the time researchers analyzed it, hoping to learn more about inner workings before releasing their report.

Silver Sparrow

But this shouldn't be interpreted as a failed malware strain, Red Canary warns. It's possible that the malware is detecting research analyzing its behavior and simply avoiding delivering second-stage payloads to these systems.

The large number of infected systems clearly indicates that this is a very serious threat and not just an isolated attempt by a hacker.

Furthermore, the malware also comes with support for infecting macOS systems running Apple's latest M1 chip, confirming once again that this is a new threat.

In fact, Silver Sparrow is the second malware strain discovered that can run on M1 chips, after the first was discovered just four days ago.

The Red Canary report contains various information, such as files and file paths created and used by the malware, which can be used to identify infected systems.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS