Newly Discovered Mac Malware Captures and Stores Screenshots

New Mac spyware was discovered earlier this week on a computer at the Oslo Freedom Forum, an annual human rights conference. Located by computer security researcher Jacob Appelbaum, the malware, which has been deemed OSX/KitM.A, is currently being investigated by anti-virus company F-Secure, reports CNET.

The malware is a backdoor application called "macs.app," which launches automatically upon login and captures screenshots that it then sends to a MacApp folder in the user's home directory. Two command-and-control servers, located at securitytable.org and docsforum.info, are associated with the malware, but one does not function and the other gives a "public access forbidden" message.

macapp
Interestingly, the malware is signed with an Apple Developer ID, which is designed to prevent the installation of malware. Apps that are unsigned are blocked by default by Apple's Gatekeeper security option.

This bit of malware is somewhat unique in that it is signed with what appears to be a valid Apple Developer ID associated with the name Rajender Kumar. Though not an uncommon name, this may be a reference to the late Bollywood actor of a similar name. Regardless, the use of the ID appears to be an attempt to bypass Apple's Gatekeeper execution prevention technology.

Currently, F-Secure is investigating where the malware originated, and though it does not appear to be widespread, it can be mitigated by removing the macs.app program from the log-in menu. Apple often addresses malware threats quickly, and has the ability to revoke the developer ID to further limit the spread of the software.

Top Rated Comments

VoR Avatar
117 months ago
$99 is a small price to pay for a guaranteed safe install of your latest malware app :)
Score: 22 Votes (Like | Disagree)
shareef777 Avatar
117 months ago
I always liked how Apple's gatekeeper design could be easily bypassed by a $100 Apple Developer account.
Score: 18 Votes (Like | Disagree)
Peace Avatar
117 months ago
I'd put this one in the category of stupid-ware.
Score: 14 Votes (Like | Disagree)
nagromme Avatar
117 months ago
Some bad software is installed on a computer. Just one single computer? Did someone sit down and install it? Or was it spread over the network using some security flaw? If someone sat down and installed it, that's not what I'd call "malware." The origin is the key missing part of the story.

I always liked how Apple's gatekeeper design could be easily bypassed by a $100 Apple Developer account.
Only if Apple can't pull the plug. That is the purpose of the certificate--not prevention of attempts in the first place.

Why is the cert for this not revoked already?
When did Apple receive the details on this? And what do they need to do to verify? (Obviously they can't simply obey any random request to shut a developer down, so there must be some verification steps.)
Score: 11 Votes (Like | Disagree)
kidde Avatar
117 months ago
Why is the cert for this not revoked already?
Score: 11 Votes (Like | Disagree)
Tankmaze Avatar
117 months ago
well how do you get the macs.app downloaded and running in the first place unless it's a pebkac. just use common sense people, this malware seems not to be that harmful, albeit it's annoying.
Score: 6 Votes (Like | Disagree)

Popular Stories

maxresdefault

Samsung's New 32-Inch 'M8' Display vs. Apple's Studio Display

Thursday April 21, 2022 1:14 pm PDT by
Samsung recently introduced the M8, a new 32-inch 4K display that's priced at $700, making it less than half as expensive as the Studio Display from Apple. We picked up one of the displays and thought we'd compare it to the Studio Display in our latest YouTube video to see how it performs and whether you can save some money by going with a cheaper option. Subscribe to the MacRumors YouTube ...
macos server

Apple Discontinues macOS Server

Thursday April 21, 2022 10:30 am PDT by
Apple today announced in a support document that macOS Server is being discontinued as of April 21, 2022. Apple has been phasing out macOS Server for several years now, and the company is finally ready to shut it down for good. macOS Server 5.12.2 will be the last version of the app, and macOS Server services have now been migrated to macOS. Popular macOS Server capabilities that include...
apple cash visa hero

New Apple Cash Accounts Now Branded as Visa Cards

Friday April 22, 2022 5:55 am PDT by
The Apple Cash virtual debit card appears to be switching networks from Discover to Visa, as revealed in some updated images on Apple's website and noted by Twitter user @Kanjo. Since its launch, Apple Cash (originally known as Apple Pay Cash) has been operated through a partnership with Green Dot Bank on the Discover network. Discover is one of the smaller card networks and is accepted in...
USB C Over Lightning Feature

EU Moves One Step Closer to Mandating Apple to Switch iPhone, iPad, and AirPods to USB-C

Thursday April 21, 2022 7:54 am PDT by
Members of the European Parliament this week voted overwhelmingly in support of legislation that will compel Apple to offer a USB-C port on all iPhones, iPads, and AirPods in Europe. The proposal, known as a directive, will force all consumer electronics manufacturers who sell devices in Europe to ensure that all new phones, tablets, laptops, digital cameras, headphones, headsets, handheld...
iphone 13 pro and 14 pro render with background

iPhone 14 Pro Rumored to Feature Rounder Design to Match Larger Rear Camera Array

Thursday April 21, 2022 9:57 am PDT by
The iPhone 14 Pro could feature significantly rounder corners to match the larger rear camera array, according to Apple concept graphic renderer Ian Zelbo. Zelbo, who is best known for creating renders of upcoming Apple devices based on leaked information, including the Mac Studio, Studio Display, rumored mixed-reality headset, and more, believes that the iPhone 14 Pro models are likely to...
anker 735 panels

Anker's New 100W GaN Charger Features Three USB Ports, 34% Smaller Size Than Apple's 96W Charger

Friday April 22, 2022 8:46 am PDT by
Originally announced at CES back in January, the U.S. version of Anker's highly anticipated 736 USB charger is now available through Amazon for $75.99 in black/silver. Using Anker's GaN II technology, the 100-watt 736 charger is 34% smaller than Apple's 96-watt charger, yet offers the flexibility of three USB ports to charge multiple devices when needed. The 736 includes two USB-C ports...
iPhone 14 Purple Feature

iPhone 14 Lineup Color Options to Include All-New Purple Shade, Sketchy Rumor Claims

Friday April 22, 2022 8:01 am PDT by
The iPhone 14 lineup will be available in a refreshed lineup of color options, including an all-new purple color, and feature a new True Tone flash design, according to a sketchy rumor shared by an unverified source (via AppleTrack). The post, which has since been deleted, comes from an unverified source on Chinese social media site Weibo and claimed to reveal the full range of color options ...
Transcend JDL330 2

Transcend Announces 1TB JetDrive Lite 330 Expansion Card for 14-inch and 16-inch MacBook Pro

Thursday April 21, 2022 4:38 am PDT by
Transcend has announced a 1TB version of its JetDrive Lite 330 expansion cards for 14-inch and 16-inch MacBook Pro models, providing users of Apple's latest Macs with an affordable way to increase internal storage capacity. Transcend says the JetDrive Lite 330 cards are built with high-quality NAND flash, offering read and write speeds of up to 95MB/s and 75MB/s, respectively. Once the...
magsafe battery pack on iphone

MagSafe Battery Pack Now Able to Charge at Faster 7.5W Speed After Firmware Update

Wednesday April 20, 2022 1:09 pm PDT by
Apple yesterday released a firmware update designed for the MagSafe Battery Pack, and it turns out the new firmware enables 7.5W charging while on the go, up from the previous 5W limit. In an support document, Apple says that MagSafe Battery Pack owners can update their firmware to the new 2.7.b.0 release to get the faster 7.5W charging capabilities. Updating the MagSafe Battery Pack can...