Blog | G5 Cyber Security

New MacOS X backdoor variant used in APT attacks

Two days ago, we intercepted a new APT campaign using a new MacOS X backdoor variant targeted at Uyghur activists. The Dalai Lama is a well known Mac user. The attack is a new, mostly undetected version of the MaControl backdoor (Universal Binary), which supports both i386 and PowerPC Macs. The backdoor is quite flexible its Command and Control servers are stored in a configuration block which has been appended at the end of the file, 0x214 bytes in size. The command and control server address can be read: 61178.178.77*, located in China:”]

Source: https://securelist.com/new-macos-x-backdoor-variant-used-in-apt-attacks/33214/

Exit mobile version