Automatically translated.View original post

AI-Empowered Malware for Attacking macOS

AI-Empowered Malware for Attacking macOS "MonetaStealer"

MacOS, which was historically said to be the most secure operating system, is still cheap in this era, but it's not always true, because there are many malware that have the ability to detect vulnerabilities to emanate or hide from those new security systems every day.

According to a report by the Cyber Security News website, it mentions the detection of malware from the victim's machine, or a new Infostealer, "MonetaStealer," which this malware will focus on attacks on users who use the macOS operating system. A research team from Iru, an expert in the development of endpoint security tools (Endpoints), detected the malware from a Mach-o Binary file. It was suspected on January 6. The file, although it is a macOS file, was named as a hoax. For runs used on the Windows operating system (.Exe file genus) as Portfolio _ Review.exe

The malware focuses its attacks on a group of macOS users working in the professional industry who often receive Portfolio files from customers. Hackers can use this channel to release malware to the machine. The malware has the ability to steal a variety of data ranging from system information, passwords logged in web browsers, data of krypto kerrency wallets, Wi-Fi codes, SSH keys, and financial documents. In addition to this ability, the malware has the ability to determine if it is running on macOS using commands.

If sys.platform! = 'darwin'

This command can only be run on macOS. In addition, the research team also found that the code is written through an AI or Artificial Intelligence tool developed with ML or Machine Learning, but many of the things detected have led the research team to assume that the malware is only in the early stages of development.

But what's even scarier than using AI to develop it is that after the research team tested the malware through a website for high-performance virus files like VirusTotal, no tool was able to detect this malware (Zero-Detection Rate), and in examining the elements of the malware, the research team found that the main file of the malware (Payload) was named portfolio _ app.pyc. This file is hidden in an Installer file in Pyinstaller format, where the logic of the malware is hidden within the compressed CArchive structure again, allowing it to Easily evade being detected by static file scanners (Static).

After the research team decompiling the malware files, the code was found in Russian, which made it possible to predict that this malware may have been developed by a group of Russian hackers, and that the code for detecting or analyzing (Obfuscation) was not yet found, making it assumed that the developer may focus on the functionality rather than Stealth. In addition, it was found that during the run of this malware, the malware displayed a banner that read "PROFESSIONAL MACOS STEALER v2.0," and the report was the page of the Module for Stealing a variety of files, modules, too.

The research team also delved into the system of stealing files from the Google Chrome web browser, which is the key target of this malware. It starts by temporarily copying SQLite databases (Databases) to avoid locking files and then executing commands.

Security find-generic-password -w -a "Chrome."

In order to extract the Master Key in Chrome's Base64 format from macOS Keychain to decryption the password saved on the web browser, there is still a risk that this operation will lead to a screen bounce to allow the user to enter the password to unlock the Keychain's Password so that this operation can resume. This may cause the user to wonder what is going on inside the system. But if the user accidentally inserts the password for approval, it will cause the malware to send a Queries request to retrieve the password for logging in, Session Cookies and Website Visit History via the SQL command. The search will focus on Cookies files named "bank," "crypto," "exchange," and "paypal" in order to obtain files on the victim's access to the financial services. The theft command will look like this:

Print ('[+] Stealing Chrome Cookies...')

Trying:

Host, name, path, encrypted _ value = row

If any (keyword in host.lower () for keyword in ['bank', 'crypto',

'exchange ',' paypal ']) and self.steal _ data [' browser '] [' cookies'] .append ({'host':

Host, 'name': name, 'path': path}):

Passed.

Conn. Close ()

Except Exception as e:

Print (f 'X Error: {e}')

As for the theft of website traffic data, it covers the URL of the page, the page name, and the frequency of visits. These data indicate the victim's interest to be useful for the next wave of attacks. All stolen data is sent to a hacker bot on the Telegram chat service called "b746 _ mac _ collector _ bot" with Bot ID 8384579537.

# lemon 8 diary # Trending # Malware # macos # freedomhack

2/4 Edited to

... Read moreจากประสบการณ์ส่วนตัวและจากข้อมูลวิจัยล่าสุด การโจมตีของมัลแวร์ MonetaStealer นั้นแสดงให้เห็นว่าแม้ระบบ macOS จะมีชื่อเสียงเรื่องความปลอดภัยสูง แต่อาชญากรไซเบอร์ก็ยังสามารถใช้เทคนิคร่วมกับ AI และ Machine Learning เพื่อพัฒนามัลแวร์ที่หลบหลีกการตรวจจับได้อย่างมีประสิทธิภาพ สิ่งที่น่าสนใจคือมัลแวร์นี้ถูกออกแบบมาให้เจาะกลุ่มผู้ใช้งานในสายอาชีพที่มักใช้ไฟล์ Portfolio ในการทำงาน ซึ่งเปิดโอกาสให้แฮกเกอร์แอบแฝงมัลแวร์ได้ง่าย โดย MonetaStealer ไม่เพียงแค่ขโมยรหัสผ่านในเบราว์เซอร์ แต่ยังดึงข้อมูลจาก keychain ของ macOS อย่างเช่นรหัส Wi-Fi หรือกุญแจ SSH ซึ่งเป็นข้อมูลที่สำคัญมากและมักจะถูกใช้ในการเข้าถึงระบบอื่นๆ อีกจุดที่ทำให้มัลแวร์นี้น่ากลัวคือ สามารถทำงานได้โดยที่เครื่องสแกนไวรัสหลายแห่งไม่พบ เนื่องจากการซ่อนโค้ดในรูปแบบ Pyinstaller และโครงสร้างไฟล์แบบ CArchive ที่บีบอัด รวมถึงการไม่ใส่โค้ดกวนการวิเคราะห์ (Obfuscation) แต่เน้นประสิทธิภาพการทำงานแทน นอกจากนี้ ผู้ใช้ macOS อาจเห็นหน้าต่างปลอมที่ขอรหัสผ่านเพื่อปลดล็อก keychain ซึ่งถ้านำไปใส่รหัสผ่านตามคำขอ จะช่วยให้มัลแวร์ถอดรหัสข้อมูลสำคัญต่างๆ ได้ทันที สิ่งที่แนะนำสำหรับผู้ใช้ macOS คืออย่ากดเปิดไฟล์ที่ไม่น่าเชื่อถือหรือไม่ได้มาจากแหล่งที่ชัวร์ โดยเฉพาะไฟล์ที่ชื่อดูผิดปกติ เช่นไฟล์ .exe บน macOS ควรใช้ซอฟต์แวร์ป้องกันมัลแวร์ที่อัปเดตเสมอ และตั้งค่าความปลอดภัยให้เข้มงวด รวมถึงควรใช้รหัสผ่านที่แข็งแรง และมีการตรวจสอบหลายชั้น (2FA) กับบริการต่างๆ เพื่อป้องกันความเสียหายเมื่อเกิดเหตุการณ์ข้อมูลรั่วไหล ในฐานะผู้ใช้ macOS ที่เคยเจอข่าวมัลแวร์เจาะระบบระดับนี้ รู้สึกได้ว่าเทคโนโลยี AI แม้จะช่วยเราสร้างสรรค์ผลงานได้มากมาย แต่ก็ถูกนำไปใช้สร้างมัลแวร์ที่ซับซ้อนขึ้นเรื่อยๆ เราจึงต้องเพิ่มความรู้ความระมัดระวังตัวเองในด้านความปลอดภัยไซเบอร์ และไม่ประมาทในการใช้งานระบบเพื่อป้องกันการถูกโจมตีในยุค AI นี้อย่างแท้จริง