News: 1613952021

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Malware monsters target Apple’s M1 silicon with ‘Silver Sparrow’

(2021/02/22)


US security consultancy Red Canary says it’s found MacOS malware written specifically for the shiny new M1 silicon that Apple created to power its post-Intel Macs.

Red Canary has named the malware “Silver Sparrow” and [1]says it had found its way onto almost 30,000 MacOS devices as of February 17th.

[2]

Red Canary’s post says it has analysed two samples of the malware, one targeting x86 and the other targeting X86 and Apple’s own M1 silicon. The form says both samples “leverage the macOS Installer JavaScript API to execute suspicious commands.” That’s not unusual behaviour for a legitimate software installer package, but Red Canary says it’s not spotted it in malware before.

Once the scripts run, a Mac will have two new and nasty files one of which phones home to the malware’s authors to report it was installed.

[3]

LibreOffice 7.1 Community released with support for M1 Arm Mac and 'user interface variants' [4]READ MORE

The other script is driven by a persistent LaunchAgent that runs it hourly to connect with a server and request more information from whoever controls the malware.

Red Canary says that hourly request “tells launchd to execute a shell script that downloads a JSON file to disk, converts it into a plist , and uses its properties to determine further actions.”

The firm’s researchers ran the malware for a week and never saw that request result in a download, leading them to suggest the malware currently lacks a payload.

[5]

How the malware is distributed remains a mystery, but Red Canary’s researchers have divined that it uses resources in AWS and Akamai’s content distribution network. The firms suggests Silver Canary’s authors therefore appear to have a decent understanding of how working in a public cloud and CDN makes it harder to defend against malware because organisations often have very good reasons to welcome traffic from large public clouds. ®

Get our [6]Tech Resources



[1] https://redcanary.com/blog/clipping-silver-sparrows-wings/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDM6ayJben3CLsDwU8uLEAAAAMk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDM6ayJben3CLsDwU8uLEAAAAMk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/02/04/libreoffice_71_released_with_user/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDM6ayJben3CLsDwU8uLEAAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://whitepapers.theregister.com/

This cannot be true!!!

Anonymous Coward

Apple devices have "Security. Built right in." They told us we were safe!!!

This cannot be.

Re: This cannot be true!!!

WolfFan

30,000 installs out of how many millions? Yeah, the sky sure is falling.

Re: This cannot be true!!!

chivo243

Since some are on new Apple Silicon, are we seeing another SolarWinds compromise? Build servers have been infiltrated?

Re: This cannot be true!!!

ThomH

Kneejerk comments aside, this sounds like a trojan horse attack? If so then I'd rather that be a risk than have Apple go full-iOS on us and prevent users from downloading and running software.

As a real-life Mac user I've already looked up how I can check whether I have this malware, and checked. Nobody, anywhere in the whole of the world, seriously believes that Macs are invulnerable.

The curse of popularity

HildyJ

No chip or OS is invulnerable. And hackers follow the news.

Intel x86 and Windows were the usual targets because of their popularity. With the rise in Mac popularity, especially with OSx and the M1, they have become popular enough to be a target as well.

Don't assume that the security that's built a chip or OS is sufficient.

C:\WINDOWS\RUN C:\WINDOWS\CRASH C:\ME\FDISK /usr/src/linux

-- From a Slashdot.org post