Automatically translated.View original post

MacOS beware of the new malware, Crash Stealer.

MacOS Beware of New Malware Silky Crash Stealer Disguised as Crash Report App

According to a report by the website, ITnews has mentioned the detection of malware thieves from the victim's machine, or a new Infostealer specifically focused on macOS users called Crash Stealer, with the work of a research team from Jamf, a security expert on Apple's device. The research team said that the malware is based on an impersonation application called Werkbit, which is a collaborative application on the team. On the website of the fake application, the impersonation of brands and companies that are famous for using the application is reliable, but the website is actually dependent. Registration in the last June, and importantly, this fake application does not have any interoperability. The functions on the machine are only more difficult to verify. The application was signed in the name of the developer (Apple Developer) called "Emil Grigorov" to avoid being detected by the Gatekeeper protection system on macOS. Apple later canceled the account, allowing the Gatekeeper to detect applications related to the developer account.

But in fact, the application acts as a dropper to release the real malware on the victim's machine. The installed file is a Disk Image file for the macOS operating system. A DMG with a file name called Werkbit.dmg that requires a PIN code to be opened. After the victim runs, it will lead to Fetch, a payload file from GitHub's Repo or Repository, and a Component file from other sources to be installed on the machine. The downloaded element will come in a 3-layer base-34 encoded version to confuse the protection system when trying to check for a Filesystem file inside.

This decoded Payload file is a disk image called CrashReporter.dmg inside a hidden folder called / tmp. This file is disguised as an application within macOS for reporting macOS (Crash Reporting). It has copied both the Identifier, the icon, and the Launch Agent called com.apple crashreporter.helper. If the victim opens, the fake app will trick the login code. If the victim enters, it will ultimately lead to the theft of the password inside the Key. In addition to the data in the Keychain, the Crash Stealer malware also searches for data in the Documents, Downloads, and other similar folders to steal Sensitive Data inside not only malware, but also malware.

It steals the data of the password saved within the web browser, Password Manager, and Cryptocurrency Wallet. All the data is encrypted and sent to the C2 or Command and Control server.

# Trending # lemon 8 diary # Lemon 8 Howtoo # macos # freedomhack

1 week agoEdited to

... Read moreจากประสบการณ์ส่วนตัวที่ใช้ macOS มาหลายปี สิ่งหนึ่งที่ผู้ใช้หลายคนมักมองข้ามคือความเสี่ยงจากมัลแวร์ที่แฝงตัวมาในรูปแบบของแอปพลิเคชันที่ดูเหมือนจะปลอดภัย เช่นกรณีของมัลแวร์ Crash Stealer ที่เนียนปลอมเป็นแอปรายงานอาการค้าง (Crash Report) และแอปทำงานร่วมกันชื่อ Werkbit ซึ่งจริง ๆ แล้วเป็นเพียงมุขหลอกเพื่อให้ผู้ใช้หลงเชื่อและติดตั้งมัลแวร์ สิ่งที่น่ากังวลคือมัลแวร์จะเข้าถึงข้อมูลสำคัญในเครื่อง อย่างรหัสผ่านใน Keychain, ข้อมูลในเว็บเบราว์เซอร์, โปรแกรมจัดการรหัสผ่าน และกระเป๋าเงินคริปโต ซึ่งล้วนแต่เป็นข้อมูลที่อาจถูกขโมยและนำไปใช้ในทางที่ผิด นอกจากนี้ยังมีการใช้เทคนิคเข้ารหัสแบบหลายชั้นเพื่อหลีกเลี่ยงการตรวจจับจากระบบความปลอดภัยอย่าง Gatekeeper และการซ่อนไฟล์มัลแวร์ในโฟลเดอร์ระบบที่มองไม่เห็น ทำให้การตรวจสอบด้วยตนเองแทบจะเป็นไปไม่ได้ถ้าไม่มีเครื่องมือพิเศษ จากที่เคยเจอเหตุการณ์คล้ายกัน การป้องกันที่ดีที่สุดคือเลี่ยงการดาวน์โหลดและติดตั้งแอปจากแหล่งที่ไม่เชื่อถือ รวมถึงตรวจสอบสิทธิ์ของแอปที่จะติดตั้งให้ละเอียด และอัปเดตระบบปฏิบัติการและซอฟต์แวร์รวมถึงฐานข้อมูลความปลอดภัยเสมอ การใช้โปรแกรมแอนตี้มัลแวร์ที่น่าเชื่อถือบน macOS ก็ช่วยตรวจจับภัยคุกคามเหล่านี้ได้ดีขึ้น แนะนำให้ผู้ใช้ macOS หมั่นตรวจสอบกระบวนการที่ทำงานบนเครื่อง และถ้าพบแอปที่ไม่รู้จักโดยเฉพาะที่ขอรหัสผ่านหรือสิทธิ์ที่ไม่เกี่ยวข้อง ควรลบออกทันที ไม่ป้อนข้อมูลส่วนตัวโดยไม่มั่นใจ และระวังเว็บไซต์ที่ส่งลิงก์แปลก ๆ ให้ดาวน์โหลดไฟล์ .DMG พร้อมรหัส PIN ที่ไม่เคยขอมาก่อน สุดท้าย การรับรู้และรู้เท่าทันเทคโนโลยีใหม่ ๆ รวมถึงวิธีป้องกันมัลแวร์ การวางแผนสำรองข้อมูลสำคัญไว้อย่างปลอดภัย จะช่วยให้คุณมั่นใจและใช้ macOS ได้อย่างปลอดภัยมากขึ้น