New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

UpdateAgent malware variant impersonates legitimate macOS software

New York Tech Editorial Team by New York Tech Editorial Team
October 22, 2021
in Cybersecurity
0
UpdateAgent malware variant impersonates legitimate macOS software
Share on FacebookShare on Twitter

The new variant of UpdateAgent malware is also capable of dropping adware against macOS.

The IT security researchers at Microsoft Security Intelligence have discovered a new variant of  UpdateAgent (aka WizardUpdate) malware targeting Mac devices. UpdateAgent was originally discovered in November 2020 targeting macOS.

New variant, new capabilities, new adware

In a series of tweets, Microsoft explained that the variant is equipped with new capabilities including increased persistence and evasion tactics. This indicates that the malware is not only difficult to detect but also hard to get rid of.

Another malicious capability of the malware includes the abuse of public cloud infrastructure to host additional payloads. For instance, upon infection, UpdateAgent installs new adware called Adload.

According to researchers, although, the malware collects and sends system information to a C2 server, one of the most notable additions to the malware’s capabilities is its ability to bypass Apple’s Gatekeeper security feature. It does so by removing the downloaded file’s quarantine attributes.

The screenshot below shows the evolution of Trojan:MacOS/UpdateAgent.B (aka WizardUpdate):

UpdateAgent malware variant impersonates legitimate macOS software

Evolution of Trojan:MacOS/UpdateAgent.B (aka WizardUpdate):

For your information, Gatekeeper is the backbone of macOS’ security as it verifies downloaded applications and enforces code signing before allowing them to run on Macbooks. This reduces the possibility of malware execution.

However, like OSX/Dok malware, UpdateAgent also bypasses the Gatekeeper security feature making it a persistent threat. 

The malware also leverages existing user permissions to create folders on the affected device. It uses PlistBuddy to create and modify Plists in LaunchAgent/LaunchDeamon for persistence. It then covers its tracks by deleting created folders, files, and other artifacts, researchers tweeted.

UpdateAgent malware Impersonates legitimate software

The modus operandi of the new variant involves impersonating legitimate software. For now, Microsoft did not reveal precisely which software are being impersonated by the malware. However, the company believes that the new variant is being distributed via drive-by downloads.

A drive-by download attack refers to the unintentional download of malware or malicious code by users on their computers. Simply put: Software downloaded with the user’s permission without understanding its consequences (virus mimicking gaming mods for example) is called a drive-by download.

New variant of UpdateAgent Mac malware

How to protect your Mac devices from cyber attacks?

Most software for macOS are paid therefore it is easy to lure unsuspecting users into downloading malicious software by impersonating legitimate ones. That is why it is important to refrain from downloading pirated programs or software from third-party websites/marketplaces. 

Nevertheless, since Mac devices are constantly under cyber attacks it is vital that users master the art of protecting their devices. Here are some simple tips to follow:

  • Use a VPN software
  • Disable Remote Login
  • Use Two built-in firewalls
  • Disable Automatic user login
  • Update your Mac OS X regularly
  • Install reliable Mac Anti-Virus software
  • Set GateKeeper to prevent digitally unsigned apps
  • Turn off Java and auto-download in Safari browser.

Did you enjoy reading this article? Like our page on Facebook and follow us on Twitter.


Credit: Source link

Previous Post

Robots Take Over Major Casual Dining Chains

Next Post

Corps begins fielding remotely operated underwater EOD vehicle

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Corps begins fielding remotely operated underwater EOD vehicle

Corps begins fielding remotely operated underwater EOD vehicle

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025
Magnus Almqvist, new CEO of Exberry

Exberry Appoints Magnus Almqvist as CEO to Drive Next Phase of Strategic Growth

March 5, 2025
Expert Family Law Firms in New York: Your Essential Guide to Legal Help

Expert Family Law Firms in New York: Your Essential Guide to Legal Help

March 3, 2025

Recommended

Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up startupnation Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media