UPDATED 09:00 EDT / FEBRUARY 23 2023

SECURITY

Largely undetected malware family targets pirated macOS applications

Security researchers at Apple Inc. enterprise management firm Jamf Holding Corp. today detailed a largely undetected family of malware that infects pirated macOS applications to mine cryptocurrency secretly.

The malware uses XMRig, an open-source command line cryptomining tool commonly used for legitimate purposes, for nefarious intent. XMRig was first found by the researchers bundled in a pirated copy of Apple’s video editing software Final Cut Pro.

At the time of the discovery, the sample was not being detected as malicious by any security vendors on VirusTotal,free service that analyzes files and URLs for viruses, worms, trojans and other kinds of malicious content. Some vendors were later noted as detecting the malware in January, but some of the maliciously modified applications continue to go unidentified.

A hacked version of Final Cut Pro does not make for much of a concern by itself, but the researchers dug further and identified that the malware was making use of the Invisible Internet Project for communication. I2P is a private network layer that anonymizes traffic, making it a less noticeable alternative to a similar service called Tor.

Looking for other examples of malware using I2P, the researchers traced related malware and then discovered a reference to a similar example reported by Trend Micro Inc. in early February, a pirated version of the Mac version of Adobe Photoshop. The key similarity is both the malicious versions of Final Cut Pro and Photoshop tracked back to the same person with a years-long track record of sharing pirated software on The PirateBay.

“This discovery presented a rare opportunity to trace the evolution of a malware family,” researchers explain. “What started as a rudimentary and conspicuous scheme had iterated through three distinct stages of evolution into something with creative evasion techniques. As far as we could tell, only samples from the first generation of this malware family have been reported on.”

Interestingly, the pirated version of Final Cut Pro doesn’t work in macOS Ventura because of an error in the coding of the malware, but it’s an error that will likely be addressed in future malware releases.

The researchers warn that, given that cryptomining requires a significant amount of processing power, it’s likely that the ongoing advancements in Apple Arm processors will make macOS devices even more attractive targets for cryptojacking in the future.

Image: Jamf

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU