New malware found on 30,000 Macs

With no payload, analysts are struggling to learn what this mature malware does.

A previously undetected piece of malware found on almost 30,000 Macs worldwide is generating intrigue in security circles, and security researchers are still trying to understand precisely what it does and what purpose its self-destruct capability serves.

Once an hour, infected Macs check a control server to see if there are any new commands the malware should run or binaries to execute. So far, however, researchers have yet to observe delivery of any payload on any of the infected 30,000 machines, leaving the malware’s ultimate goal unknown. The lack of a final payload suggests that the malware may spring into action once an unknown condition is met.

Also curious, the malware comes with a mechanism to completely remove itself, a capability that’s typically reserved for high-stealth operations. So far, though, there are no signs the self-destruct feature has been used, raising the question of why the mechanism exists.

Besides those questions, the malware is notable for a version that runs natively on the M1 chip that Apple introduced in November, making it only the second known piece of macOS malware to do so. The malicious binary is more mysterious still because it uses the macOS Installer JavaScript API to execute commands. That makes it hard to analyze installation package contents or the way that package uses the JavaScript commands.

The malware has been found in 153 countries with detections concentrated in the US, UK, Canada, France, and Germany. Its use of Amazon Web Services and the Akamai content delivery network ensures the command infrastructure works reliably and also makes blocking the servers harder. Researchers from Red Canary, the security firm that discovered the malware, are calling the malware Silver Sparrow.

Reasonably serious threat

“Though we haven’t observed Silver Sparrow delivering additional malicious payloads yet, its forward-looking M1 chip compatibility, global reach, relatively high infection rate, and operational maturity suggest Silver Sparrow is a reasonably serious threat, uniquely positioned to deliver a potentially impactful payload at a moment’s notice,” Red Canary researchers wrote in a blog post published on Friday. “Given these causes for concern, in the spirit of transparency, we wanted to share everything we know with the broader infosec industry sooner rather than later.”

Silver Sparrow comes in two versions—one with a binary in mach-object format compiled for Intel x86_64 processors and the other Mach-O binary for the M1. The image below offers a high-level overview of the two versions:

So far, researchers haven’t seen either binary do much of anything, prompting the researchers to refer to them as “bystander binaries.” Curiously, when executed, the x86_64 binary displays the words “Hello World!” while the M1 binary reads “You did it!” The researchers suspect the files are placeholders to give the installer something to distribute content outside the JavaScript execution. Apple has revoked the developer certificate for both bystander binary files.

FURTHER READING

Silver Sparrow is only the second piece of malware to contain code that runs natively on Apple’s new M1 chip. An adware sample reported earlier this week was the first. Native M1 code runs with greater speed and reliability on the new platform than x86_64 code does because the former doesn’t have to be translated before being executed. Many developers of legitimate macOS apps still haven’t completed the process of recompiling their code for the M1. Silver Sparrow’s M1 version suggests its developers are ahead of the curve.

Once installed, Silver Sparrow searches for the URL the installer package was downloaded from, most likely so the malware operators will know which distribution channels are most successful. In that regard, Silver Sparrow resembles previously seen macOS adware. It remains unclear precisely how or where the malware is being distributed or how it gets installed. The URL check, though, suggests that malicious search results may be at least one distribution channel, in which case, the installers would likely pose as legitimate apps.

Among the most impressive things about Silver Sparrow is the number of Macs it has infected. Red Canary researchers worked with their counterparts at Malwarebytes, with the latter group finding Silver Sparrow installed on 29,139 macOS endpoints as of Wednesday. That’s a significant achievement.

“To me, the most notable [thing] is that it was found on almost 30K macOS endpoints… and these are only endpoints the MalwareBytes can see, so the number is likely way higher,” Patrick Wardle, a macOS security expert, wrote in an Internet message. “That’s pretty widespread… and yet again shows the macOS malware is becoming ever more pervasive and commonplace, despite Apple’s best efforts.”

For those who want to check if their Mac has been infected, Red Canary provides indicators of compromise at the end of its report.

From: DAN GOODIN – 2/20/2021 – Original Article

Safe and Ad Free Browsing

Ever since my bad experience with Facebook and their other products, I have been working on ways to minimize my digital footprint. I moved over to other social media sites that have no ads and don’t ask or use your private information. With the demise of Google Plus in April (2019), I decided that it was the perfect opportunity to research and move to other products that decrease my digital footprint and at least work to safe guard my web browsing. This is a living post, per-se, that I will be maintaining with new and updated information.

Ad Free DNS

AdGuard DNS is a free Domain Name System service provided by the AdGuard company. You can use this DNS service to block advertising and trackers. It works like this: when a website sends a request to an ad network, the DNS sends back a “null” response. For example, when a web page looks up the domain name “ads.facebook.com” the DNS will not find that name. This means all networks request are never loaded — this is the most efficient way to block them. This blocking may even speed up your web browser slightly.

Besides blocking advertising, AdGuard DNS will also blocks trackers and malware phishing sites.

Default Ad-Blocking DNS

Use these servers to block ads, tracking and phishing:

  • 176.103.130.130
  • 176.103.130.131

Or use IPv6 addresses:

  • 2a00:5a60::ad1:0ff
  • 2a00:5a60::ad2:0ff

Family Protection DNS

Default + blocking adult (porn) websites + safe search:

  • 176.103.130.132
  • 176.103.130.134

Or use IPv6 addresses

  • 2a00:5a60::bad1:0ff
  • 2a00:5a60::bad2:0ff

For more information on AdGuard DNS, click here.

Web Browsers

Your web browser knows a lot about you, and tells the sites you visit a lot about you as well—if you let it. I have been testing out a number of browsers that specifically caters to those that want safer browsing experience and free of most ads.

Brave Browser

Here is one that I have been using for a while and it works pretty well, when used with the AdGuard DNS protection.

Brave is the latest unique browser to join the ever-expanding market. The open source and free browser from Brave Software Inc. has positioned itself as the browser that loads faster with better privacy protection. The firm was co-founded by Brendan Eich, the creator of JavaScript and a co-founder of Mozilla. Brave keeps data safe and provides users with the power to save or delete it. It features a built-in ad tracker and blocker. Unlike most common browsers, Brave also helps to fight phishing and malware.

Brave blocks ads automatically. Users are no longer required to search the web for a perfect ad blocker. The auto-blocking protects your device from malware and extensive tracking by advertisers. Brave is also working on a plan to replace ads that appear harmful.

Tracking ads by Brave is accurate. Users are served with the right ads because Brave does the tracking using local data. If an ad is irrelevant to the user, it is pulled down. You get the appropriate ads based on this model. A user’s data stays within the device since they have no third parties involved.

While Brave blocks third-party cookies, the first party cookies are not blocked by default. Users have the option to prevent or enable cookies on a given website.

However, Brave does not block ads displayed in search results. You will be able to see AdWords advertisements within Google’s results. This is because Ad blocking extensions don’t stymie search ads either.

Blocking of malicious ads automatically allows safe browsing. Brave does not have access to identifiable user data. The anonymity aggregated ad campaign related data is used for accounting. However, this data cannot be traced back to a user’s device.

Brave also comes with additional tactics to boost privacy while browsing. The incorporation of HTTPS everywhere allows usage of web encryption whenever available.

The fingerprinting feature bars third parties from tracking your activity. This feature can be activated in the settings tab.

Brave offers a clean and crisp interface that is intuitive to use. It has all the elements you would expect in your ideal browser. Furthermore, Brave’s individual tabs sport icons for quick identification, and hovering the cursor over a tab offers details on the page in that tab without having to click on the tab and activate it.

The browser also displays statistics about the content the browser has blocked. These statistics are very useful. Furthermore, it displays photos, the current time and shortcuts to your favorite sites. Like other websites, one would expect these features to have an effect on speed. However, this is not the case. Brave is very easy to use, with a streamlined design and the useful option to preview the content of tabs.

Brave’s load speeds emerge on top. The fast browsing is supported by Brave’s lack of thirds party ads. You, therefore, have less content to download before accessing your favorite website. However, Brave’s rendering speeds come a bit after Google Chrome and Mozilla.

Brave is set up on the Chromium platform. Chromium is an open-source system that also powers popular browsers like Google Chrome and soon Microsoft Edge. Based on the Chromium capability, you can almost use all Chrome extensions on Brave. The extensions on Chrome can be added to Brave through the Chrome Web Store.

For more information and downloads, click here.