Blog | G5 Cyber Security

New MacOS Backdoor Distributed through Malicious Word Documents

The MacOS Backdoor OSX_OCEANLOTUS.D is written in Perl programming language and the macro is obfuscated using decimal ASCII code. Researchers believe the backdoor is linked to hacking group OceanLotus, who responsible for launching high profile attacks against human rights organizations, media organizations, research institutes, and maritime construction firms. Backdoor is embedded in malicious Word documents and asks users to enable macros to download the final payload. The backdoor is a persistent one and all the strings in the dropper are encrypted using an RSA256 key and custom base64-encoded.”]

Source: https://gbhackers.com/macos-backdoor-word-documents/

Exit mobile version