Malware

New variant of UpdateAgent malware infects Mac computers with adware

0

Microsoft has detailed the evolution of a new variant of Mac malware called UpdateAgent which has undergone several iterations since its first appearance in September 2020 and has morphed into a tool for delivering adware and potentially other threats.

One of the latest and most potent features of UpdateAgent is the ability to bypass Apple’s built-in Gatekeeper system that allows only trusted, signed apps to run on Macs.

Microsoft has now flagged the malware as it appears to be under continuous development. It has now installed an “unusually persistent” adware threat called Adload, but Microsoft cautions it could be used to distribute other more dangerous payloads in future.

It requires the victim to install an app disguised as legitimate software, such as a video app or support agent promoted in ad pop-ups, but its ability to bypass Gatekeeper controls is significant. It can also use existing user permissions to delete evidence of its presence on a system.

Initially it started as an information stealer, but with several upgrades it had improved persistence allowing it to remain on a system after users sign in to the affected device.

The malware attempts to infiltrate macOS machines to steal data and it is associated with other types of malicious payloads, increasing the chances of multiple infections on a device.

Adload is capable of opening a backdoor to install other payloads. Once adware is installed, it uses ad injection software and techniques to intercept a device’s online communications and redirect users’ traffic through the adware operators’ servers, injecting advertisements and promotions into webpages and search results.

Adload leverages a Person-in-The-Middle (PiTM) attack by installing a web proxy to hijack search engine results and inject advertisements into webpages, thereby siphoning ad revenue from official website holders to the adware operators.

Microsoft is interested in Mac malware because more enterprises support non-Windows devices on corporate networks. It is encouraging defenders to use its Edge browser on macOS since it supports Microsoft’s Defender SmartScreen for blocking malicious websites.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Wormhole cryptocurrency platform hacked to steal $326 million

Previous article

Russian Gamaredon APT targeted a Western Government Entity in Ukraine

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *