MacDownloader is a malicious software (malware) believed to have been created by Iranian hackers, specifically targeting the US defense industry. The malware was first observed in an active stage linked from a website impersonating the aerospace firm "United Technologies Corporation," a site thought to be maintained by Iranian actors for spreading Windows malware. This deceptive site would trick users into downloading a fake Adobe Flash update, which instead of being a legitimate version of Flash, was either Windows or Mac malware based on the detected operating system. Once downloaded and run, the user's device becomes infected with MacDownloader.
The primary function of MacDownloader is to harvest information from the infected system, including details from the user's active keychains. Keychains store sensitive data such as usernames, passwords, PINs, and credit card numbers. This harvested information is then uploaded to the command and control server (C2). The malware also documents running processes, installed applications, and acquires the username and password through a fake System Preferences dialog. When the user is prompted to click to “remove” the adware, MacDownloader attempts to transmit this stolen data to a remote server.
Proofpoint, a cybersecurity company, attributes the attack to the Iranian group with high confidence, based on code similarities between GorjolEcho and NokNok and malware previously attributed to the group, including GhostEcho, CharmPower, and MacDownloader. As noted by cybersecurity researchers Claudio and Collin, MacDownloader infections typically begin with a phishing email. The malware represents a significant threat due to its ability to steal sensitive personal information and its targeted focus on the defense industry.
Description last updated: 2024-05-05T06:48:02.288Z