HomeSecurityNew Variant of XLoader macOS Malware Disguises as OfficeNote App

New variant of XLoader macOS Malware disguises itself as OfficeNote app

New variant of XLoader malware for macOS masquerades as 'OfficeNote' productivity app.

New variant of XLoader macOS Malware disguises itself as OfficeNote app

First detected in 2020, XLoader is considered a successor to Formbook and is a keylogger and information-stealing software offered under the malware-as-a-service (MaaS) model. A macOS variant of the malware appeared in July 2021, distributed as a Java program in the form of a compiled .JAR file.

“Such files require the Java Runtime Environment, and for this reason the malicious .jar file will not run on an out-of-the-box macOS installation, since Apple stopped shipping JRE with Macs a decade ago,” cybersecurity firm SentinelOne noted at the time.

The latest version of XLoader addresses this limitation by switching programming languages ​​such as C and Objective C, with the disk image file signed on July 17, 2023. Apple has since revoked the signature.

SentinelOne reported that multiple submissions of the file to VirusTotal were detected throughout July 2023, indicating a widespread operation.

Upon execution, OfficeNote displays an error message stating that “it cannot be opened because the original object cannot be found,” but, in fact, it installs a Launch Agent in the background to maintain persistence.

XLoader is designed to collect data from the clipboard as well as information stored in folders associated with web browsers, such as Google Chrome and Mozilla Firefox . However, the Safari browser is not its target.

In addition to taking steps to avoid analysis by both manual and automated solutions, the malware is configured to execute sleep commands to delay execution and avoid recognition of any suspicious activity.

Researchers concluded that XLoader continues to pose a threat to macOS users and businesses.

This latest version, presented as an office productivity app, is primarily aimed at users working in an office environment. The malicious code attempts to steal browser and personal information that can be used or sold to other hackers for further compromise.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS