Malware Uses Apple Developer Certificate to Infect MacOS and Spy on HTTPS Traffic
Apr 28, 2017 4:31 am PDT by Tim Hardwick
A malware research team has discovered a new piece of Mac malware that reportedly affects all versions of MacOS and is signed with a valid developer certificate authenticated by Apple (via The Hacker News).

The malware has been dubbed "DOK" and is being disseminated through an email phishing campaign which researchers at CheckPoint say is specifically targeting macOS users, making it the first of its kind.


The malware works by gaining administration privileges in order to install a new root certificate on the user's system. This enables it to gain access to all communications between the host Mac and the internet, including traffic flowing through connections encrypted with SSL.

The initial email pretends to be informing the recipient of inconsistencies in their tax return and asks them to download a zip file attachment to their Mac that harbors the malware. Apple's built-in Gatekeeper security feature reportedly fails to recognize it as a threat because of its valid developer certificate, and the malware copies itself to the /Users/Shared/ folder and creates a login item to make itself persistent, even in a rebooted system.

The malware later presents the user with a security message claiming an update is available for the system, for which a password input is required. Following the "update", the malware gains complete control of admin privileges, adjusts the network settings to divert all outgoing connections through a proxy, and installs additional tools that enable it to perform a man-in-the-middle attack on all traffic.


According to the researchers, Mac antivirus programs have yet to update their databases to detect the DOK malware, and advises that Apple revoke the developer certificate associated with the author immediately.

Back in January, researchers discovered a piece of Mac malware called Fruitfly that successfully spied on computers in medical research centers for years before being detected.

The latest discovery of malware, which appears to target predominantly European users, underlines the fact that Macs are not immune to the threat as is sometimes supposed. As always, users should avoid clicking links or downloading attachments in emails from unknown and untrusted sources.


Top Rated Comments

(View all)

18 months ago

The initial email pretends to be informing the recipient of inconsistencies in their tax return and asks them to download a zip file attachment to their Mac that harbors the malware.

People that actually do this should not have admin rights on their machines.
Rating: 25 Votes
18 months ago
Looking at the screenshot in this story, the spelling mistakes are enough for me to not want to click any further.

I received that email earlier today, but it's to an email address that's not associated with the tax people, so I immediately deleted it.

To avoid all this, I have my own domain and use a separate email for each company/service I interact with, i.e. tesco@mydomain.com, amazon@mydomain.com etc. When I receive spam to a given address, say, tesco@... I change the email for that service to tesco2@... and bin all emails that go to the original. It's a little bit of admin, but it cuts spam down a lot.
Rating: 11 Votes
18 months ago

Wow, more and more reports of malware occurring - need to be even more vigilant


The money quote right here, we as Mac users cannot blindly ignore the threat.


The IRS isn't going to email you zip file about your taxes. If fact no one you don't know is going to email you a zip file that is real.
Rating: 7 Votes
18 months ago

People that actually do this should not have admin rights on their machines.


Downloading ANY file in an email from someone you don't know is bad. If everyone knew that, then the internet would be a (slightly) safer place.
Rating: 4 Votes
18 months ago
If People see "OS X Updates available" while on MacOs and still clicking Update All they should think first.

Not only that, always update through the AppStore and you won't get this.
.
.
.
.
.
.
.
Edited: Appsore=Appstore.
Rating: 4 Votes
18 months ago
Another screaming case for cyber education.
Rating: 3 Votes
18 months ago
Wow, more and more reports of malware occurring - need to be even more vigilant

underlines the fact that Macs are not immune to the threat as is sometimes supposed

The money quote right here, we as Mac users cannot blindly ignore the threat.
Rating: 3 Votes
18 months ago

Can't infect anymore, my ***. :p

Anyway, as Apple gains popularity and mainstream use, this day was long time coming.. All we can do is be vigilant, that's it, and it is true for any OS, be it macOS or Windows or Linux.


Even if macOS had the same market share as Windows, Windows would likely still have more malware targeted at it. Windows is built on an overly complex foundation, while macOS is built on a far simpler and streamlined Unix foundation. With greater complexity, comes reduced stability, and security. Microsoft likes to overcomplicate things, and as a result, their software will likely always suffer from these issues. Take a look at RDP for another example of a piece of overly complex technology from Microsoft.
Rating: 3 Votes
18 months ago
Sooo you're only affected if you click/open suspicious links? Ok I'm safe.

Can't believe people believe these IRS emails/scams...
Rating: 3 Votes
18 months ago

If People see "OS X Updates available" while on MacOs and still clicking Update All they should think first.

Not only that, always update through the AppSore and you won't get this.

"STORE" :-) But easier said than done - not every app or utility people need to use are available on the MAS.
Rating: 3 Votes

[ Read All Comments ]
Newer Article Older Article