[FSec] Mac Spyware Found at Oslo Freedom Forum

Newsfeed

Nachrichtenbote
The Oslo Freedom Forum is an annual event "exploring how best to challenge authoritarianism and promote free and open societies." This year's conference (which took place May 13-15) had a workshop for freedom of speech activists on how to secure their devices against government monitoring. During the workshop, Jacob Appelbaum actually discovered a new and previously unknown backdoor on an African activist's Mac.

Our Mac analyst (Brod) is currently investigating the sample.

It's signed with an Apple Developer ID.

KITM_Apple_Developer_ID.png


The launch point:

KITM_launchpoint.png


It dumps screenshots into a folder called MacApp:

KITM_screenshot_dump_folder.png


Functions:

KITM_Functions.png


There are two C&C servers related to this sample:

KITM_domaintools_securitytable_org.png

securitytable.org

KITM_domaintools_docforum_info.png

docsforum.info

One C&C doesn't currently resolve, and the other:

KITM_docsforum_info.png

Forbidden

Our detection is called: Backdoor: OSX/KitM.A. (SHA1: 4395a2da164e09721700815ea3f816cddb9d676e)
On 16/05/13 At 12:29 PM

Weiterlesen...
 
Zurück
Oben