Fragments of Cross-Platform Backdoor Hint at Larger Mac OS Attack

2023-06-16 • Bitdefender •

https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/

Thumbnail for Fragments of Cross-Platform Backdoor Hint at Larger Mac OS Attack

Bitdefender documented early fragments of a larger macOS and cross-platform toolkit: Python backdoors named shared.dat and sh.py plus a macOS Swift binary called xcc. shared.dat uses ROT13-obfuscated paths and a GITHUB_REQ/GITHUB_RES packet format to collect host, network, and process information, execute commands, and download OS-specific payloads such as an AppleAccount archive on macOS or compiled code on Linux. sh.py stores configuration in ~/Public/Safari/sar.dat, supports command execution, file upload and download, deletion, configuration changes, and Python code execution, and can rotate between configured C2 URLs. The xcc component targets macOS 12+, checks privacy and user-state permissions before likely spyware use, and indicates the observed files were part of a broader multi-stage intrusion set.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6d3eff4e029db9d7b8dc076cfed5e23… 2023-06-16 2024-04-11
URL https://www.git-hub.me/view.php 2023-06-16 2023-11-14
HASH 39bbc16028fd46bf4ddad49c2143950… 2023-06-16 2023-07-19
HASH 951039bf66cdf436c240ef206ef7356… 2023-06-16 2023-07-19
HASH aa951c053baf011d08f3a60a10c1d09… 2023-06-16 2023-07-19
HASH 5fe1790667ee5085e73b054566d548e… 2023-06-16 2023-07-19
HASH d895075057e491b34b0f8c0392b44e4… 2023-06-16 2023-07-19

Related Reports

« Back