Categories: SecurityWorkspace

Mac Malware Pretends To Be Share-Trading App

Security researchers have warned that a malware variant is making use of legitimate share-trading software to invade Mac users’ systems.

The two known variants of the malware, which Trend Micro identifies as Trojan.MacOS.GMERA.A and Trojan.MacOS.GMERA.B, both include a copy of Stockfolio, a legitimate application for trading shares and cryptocurrencies.

The malware is, however, signed with the malware developer’s own digital signature.  Apple told Trend the code signing certificate involved was revoked in July of this year.

When users launch the application, it runs as expected, but a hidden app also runs in the background, Trend said.

Data theft

The malware’s main known activity involves sending data from the system to a remote server, but version A also tries to execute a second application file whose purpose remains unknown, since Trend was unable to decrypt the file.

Both variants collect data from the system, including username, IP address, files in the Desktop and Documents folders and screenshots.

Version B also creates a reverse shell on the system, allowing the attacker to remotely run shell commands.

Persistence

In addition, it establishes persistence on the system via a property list (plist) file, which re-creates the reverse shell every 10,000 seconds, or slightly less than three hours.

Trend said the alterations in version B indicate the malware’s developers are “looking for ways to make it more efficient – perhaps even adding evasion mechanisms in the future”.

The company warned users not to download applications from unknown or suspicious websites.

“We recommend that users only download apps from official sources to minimize chances of downloading a malicious one,” the firm said in its advisory.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago