• Latest
  • Trending
Dridex Malware is now attacking macOS systems with a new infection… – The Hacker News

Dridex Malware is now attacking macOS systems with a new infection… – The Hacker News

19.03.2023
MAFS reunion: Makeup-free Bronte looks fierce as she flies to Sydney

MAFS reunion: Makeup-free Bronte looks fierce as she flies to Sydney

30.03.2023
Paul O’Grady death – latest news: Joe Lycett and Elton John pay tribute as Dominic Raab blunders at PMQs – Reuters

Paul O’Grady death – latest news: Joe Lycett and Elton John pay tribute as Dominic Raab blunders at PMQs – Reuters

30.03.2023
Representatives Jamaal Bowman and Thomas Massie tussle over gun control after Nashville shooting – Reuters

Representatives Jamaal Bowman and Thomas Massie tussle over gun control after Nashville shooting – Reuters

30.03.2023
Why did these 3 Bitcoin miners soar over 8% today?

Why did these 3 Bitcoin miners soar over 8% today?

30.03.2023
AutoCAD and Maya now run natively on Apple Silicon Macs – 9to5Mac

AutoCAD and Maya now run natively on Apple Silicon Macs – 9to5Mac

30.03.2023
Khloe Kardashian Jokes That She’s NOT Missing Her Old Face

Khloe Kardashian Jokes That She’s NOT Missing Her Old Face

30.03.2023
Marvel’s ‘Thunderbolts’ Adds ‘Beef’ Creator Lee Sung Jin As Writer (EXCLUSIVE) – Variety

Marvel’s ‘Thunderbolts’ Adds ‘Beef’ Creator Lee Sung Jin As Writer (EXCLUSIVE) – Variety

30.03.2023
The FDIC faces costs of $23 billion due to bank failures.  He wants big lenders to pay – Yahoo Finance

The FDIC faces costs of $23 billion due to bank failures. He wants big lenders to pay – Yahoo Finance

30.03.2023
6 Social Gaming Apps Like GamePigeon For Android Phones

6 Social Gaming Apps Like GamePigeon For Android Phones

30.03.2023
Katie Holmes looks casual chic in a quilted jacket as she strolls through New York with her daughter Suri Cruise

Katie Holmes looks casual chic in a quilted jacket as she strolls through New York with her daughter Suri Cruise

30.03.2023

4 American Values ​​That Are Fading Fast – Money Talks News

30.03.2023
Scheana Shay leaves court in absence of Raquel Leviss dropping restraining order – Page Six

Scheana Shay leaves court in absence of Raquel Leviss dropping restraining order – Page Six

30.03.2023
Thursday, March 30, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » Dridex Malware is now attacking macOS systems with a new infection… – The Hacker News

Dridex Malware is now attacking macOS systems with a new infection… – The Hacker News

19/03/2023 13:49:23
in Technology
0

Related posts

AutoCAD and Maya now run natively on Apple Silicon Macs – 9to5Mac

AutoCAD and Maya now run natively on Apple Silicon Macs – 9to5Mac

30.03.2023
6 Social Gaming Apps Like GamePigeon For Android Phones

6 Social Gaming Apps Like GamePigeon For Android Phones

30.03.2023

January 06, 2023Ravie LakshmananEndpoint Security/Malware

According to the latest research, a variant of the infamous Dridex banking malware has set its sights on Apple’s macOS operating system using a previously undocumented infection method.

It “adopted a new technique to provide users with documents containing malicious macros without having to impersonate invoices or other company-related files,” Trend Micro researcher Armando Nathaniel Pedragoza said in a technical report.

Dridex, also known as Bugat and Cridex, is an information stealer known for harvesting sensitive data from infected machines and delivering and executing malicious modules. It is attributed to a cybercrime group known as Evil Corp (aka Indrik Spider).

The malware is also considered a successor to Gameover Zeus, itself a successor to another banking trojan called Zeus. Previous Dridex campaigns targeting Windows used macro-enabled Microsoft Excel documents sent via phishing emails to deploy the payload.

A law enforcement operation orchestrated by Europe and the United States disrupted the botnet in October 2015 and a Moldovan national by the name of Andrey Ghinkul was arrested for his role as administrator of the operation. In December 2018, Ghinkul was sentenced to time served in US federal court following his extradition in February 2016.

Subsequently, in December 2019, the US Treasury Department imposed sanctions on Evil Corp and announced a $5 million bounty against two key members Maksim Yakubets and Igor Turashev. Despite these efforts, Dridex has continued to evolve, proving to be a resilient threat.

Trend Micro’s analysis of Dridex samples involves a Mach-O executable file, the oldest of which was submitted to VirusTotal in April 2019. Since then, another 67 artifacts have been detected in the wild, some as recent as December 2022.

The artifact, for its part, contains a malicious embedded document – first detected in 2015 – that embeds an auto-open macro that runs automatically when opening a Word document.

Additionally, the Mach-O executable is designed to find and overwrite all “.doc” files in the current user directory (~/User/{username}) with malicious macro code copied from the document embedded in the form of a hexadecimal dump.

“Although Microsoft Word’s macro functionality is disabled by default, the malware will overwrite all current user’s document files, including own files,” Pedragoza explained. “This makes it harder for the user to determine if the file is malicious because it is not from an external source.”

ONLINE SEMINAR

Discover the hidden dangers of third-party SaaS applications

Are you aware of the risks associated with third-party access to your company’s SaaS applications? Join our webinar to learn more about the types of permissions granted and how to minimize risk.

RESERVE YOUR PLACE

The macros included in the overwritten document are designed to contact a remote server to retrieve additional files, which include a Windows executable file that won’t run on macOS, indicating the attack chain could be a work in progress. The binary, in turn, attempts to download the Dridex loader onto the compromised machine.

While documents containing booby-trapped macros are typically delivered via social engineering attacks, the results once again show that Microsoft’s decision to block macros by default prompted threat actors to refine their tactics and find more efficient methods of entry.

“Currently, the impact to macOS users for this Dridex variant is minimized since the payload is an .EXE file (and therefore not compatible with macOS environments),” Trend Micro said. “However, it still overwrites document files which now carry the malicious Dridex macros.”

Did you find this article interesting ? follow us on Twitter  and LinkedIn to read more exclusive content we publish.



Related

Previous Post

What is r/NBA? Top 5 NBA Subreddit Moments List – Sportskeeda

Next Post

Conor McGregor praises UFC 286 winner as ‘one of the greatest’ and it’s not Leon Edwards or Justin Gaethje

Related Posts

AutoCAD and Maya now run natively on Apple Silicon Macs – 9to5Mac
Technology

AutoCAD and Maya now run natively on Apple Silicon Macs – 9to5Mac

30.03.2023
0

It's been almost three years since Apple announced the transition from Intel Macs to Apple Silicon. Since then, many developers...

Read more
6 Social Gaming Apps Like GamePigeon For Android Phones

6 Social Gaming Apps Like GamePigeon For Android Phones

30.03.2023
These once-rare oysters are making a comeback – and could help double biodiversity

These once-rare oysters are making a comeback – and could help double biodiversity

30.03.2023

TOP INVESTOR ADVISOR ROSEN Encourages Rite Aid Corporation Investors to Get Advice Ahead of Important Deadline in Firm’s Securities Class Action Lawsuit – RAD

30.03.2023

Huawei Mobile Cloud PC client expands to global markets including South Africa

30.03.2023

How to Reinstall MacOS Monterey

30.03.2023
Load More
Next Post
Conor McGregor praises UFC 286 winner as ‘one of the greatest of all time’ and it’s not Leon Edwards

Conor McGregor praises UFC 286 winner as 'one of the greatest' and it's not Leon Edwards or Justin Gaethje

Recent Posts

  • MAFS reunion: Makeup-free Bronte looks fierce as she flies to Sydney
  • Paul O’Grady death – latest news: Joe Lycett and Elton John pay tribute as Dominic Raab blunders at PMQs – Reuters
  • Representatives Jamaal Bowman and Thomas Massie tussle over gun control after Nashville shooting – Reuters
  • Why did these 3 Bitcoin miners soar over 8% today?
  • AutoCAD and Maya now run natively on Apple Silicon Macs – 9to5Mac

Archives

  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • 0
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.