Moke Malware Hops Over From Windows And Linux To Threaten Mac OS X

Moke malware has wormed its way across from Windows and Linux and onto Mac OS X in the form of Backdoor.OSX.Mokes, threatening Apple’s operating system with malicious code.

Discovered by cyber security firm Kaspersky Labs back in January, the Moke family of malware can swipe all manner of data from an infected machine, such as key-strokes, documents, pictures and screenshots.

It also creates a backdoor into the operating systems to allow hackers to execute arbitrary commands on a targeted computer.

“After the discovery of the binaries for Linux and Windows systems, we have now finally come across the OS X version of Mokes.A. It is written in C++ using Qt, a cross-platform application framework, and is statically linked to OpenSSL.” explained Kaspersky security researcher Stefan Ortloff.

Threatening Mac OS X

When Backdoor.OSX.Mokes is executed for the first time is makes copies of itself and spreads to a number of locations in a machine’s operating system library. It lurks in folders containing everyday software such as Apple’s App Store, Google Chrome, Skype and Dropbox.

From there it can tamper with the system to make a connection to a command and control centre server through an HTTP connection on TCP port 80. Once a connection is established the hacker in control of the command server can setup backdoor features that allow for data to be stolen using techniques such as monitoring removable storage on the infected machine and scanning the file system for documents.

Tracking the source of a Moke attack is also particularly tricky as it uses strong AES-256-CBC encryption to effectively hide its activities and communicate with the command server.

Backdoors in Mac OS X are not as common as they are in Windows machines, but they appear to be increasingly uncovered by security researchers. Kaspersky did not detail how widespread the Moke malware or how much of a threat it poses to Macs, but the security firm assumes it is out “in-the-wild” in the same ‘packed’ form as its Linux variant.

Are you a security pro? Try our quiz!

Roland Moore-Colyer

As News Editor of Silicon UK, Roland keeps a keen eye on the daily tech news coverage for the site, while also focusing on stories around cyber security, public sector IT, innovation, AI, and gadgets.

Recent Posts

Tesla To Ask Shareholders To Reinstate Elon Musk’s $56 Billion Package

Tesla shareholders to be asked to reinstate Elon Musk's $56 billion pay package, days after…

9 hours ago

Telegram To Reach One Billion Users Within Year

Catching WhatsApp? Billionaire founder of Telegram claims encrypted platform will reach one billion users within…

10 hours ago

Judge Dismisses Some Harm Claims Against Meta, Zuckerberg

Good news for Mark Zuckerberg as judge dismisses some claims in dozens of lawsuits alleging…

11 hours ago

Google Begins Removal Of California News Ahead Of Proposed Law

Consequences of Assembly Bill 886. Google begins removing California news websites from some search results

12 hours ago

Tim Cook Says Apple Considering Factory In Indonesia

CEO Tim Cook during visit to Jakarta says Apple will look into building a manufacturing…

13 hours ago

Canada To Implement Digital Services Tax This Year

Introduction of digital services tax on tech firms will begin in 2024 Canadian government confirms,…

17 hours ago