Categories: SecurityWorkspace

Mac Malware Pretends To Be Share-Trading App

Security researchers have warned that a malware variant is making use of legitimate share-trading software to invade Mac users’ systems.

The two known variants of the malware, which Trend Micro identifies as Trojan.MacOS.GMERA.A and Trojan.MacOS.GMERA.B, both include a copy of Stockfolio, a legitimate application for trading shares and cryptocurrencies.

The malware is, however, signed with the malware developer’s own digital signature.  Apple told Trend the code signing certificate involved was revoked in July of this year.

When users launch the application, it runs as expected, but a hidden app also runs in the background, Trend said.

Data theft

The malware’s main known activity involves sending data from the system to a remote server, but version A also tries to execute a second application file whose purpose remains unknown, since Trend was unable to decrypt the file.

Both variants collect data from the system, including username, IP address, files in the Desktop and Documents folders and screenshots.

Version B also creates a reverse shell on the system, allowing the attacker to remotely run shell commands.

Persistence

In addition, it establishes persistence on the system via a property list (plist) file, which re-creates the reverse shell every 10,000 seconds, or slightly less than three hours.

Trend said the alterations in version B indicate the malware’s developers are “looking for ways to make it more efficient – perhaps even adding evasion mechanisms in the future”.

The company warned users not to download applications from unknown or suspicious websites.

“We recommend that users only download apps from official sources to minimize chances of downloading a malicious one,” the firm said in its advisory.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Tesla Fires Software, Service, Engineering Staff

Tesla lays off software, service, engineering staff after disbanding Supercharger team, as major cull continues

16 hours ago

Grayscale Bitcoin Shares Surge On First Inflow Since January

Dominant Bitcoin ETF Grayscale Bitcoin Trust shows first net inflow since January as investors flock…

17 hours ago

US Crypto Campaign Funding Groups Raise $102m

US campaign funding groups backed by cryptocurrency sector raise more than $102m as firms seek…

17 hours ago

Robinhood Served With SEC Crypto Enforcement Notice

Robinhood Markets says it received SEC enforcement notice over cryptocurrency trading platform amidst ongoing crackdown

18 hours ago

Synopsys Spins Off App Security Unit In $2.1bn Deal

Chip designer Synopsys to sell software integrity unit to private investors to create new independent…

18 hours ago