macOS hit by 'MaMi' malware
By MYBRANDBOOK
Way back in 2012, we faced DNSChanger malware which affected millions of Windows PCs and in the first week of 2018 we have observed the emergence of a DNSChanger malware for MacOS. The threat was first discovered by Patrick Wardel and has been named as MaMi.
Similar to DNSChanger, MaMi's infection vector involves various recently registered domains from where it is downloaded and subsequently installed. Post infection, MaMi forcibly changes the DNS entry and also installs a root certificate. Furthermore, it is highly persistent and reverts back to malicious DNS entries, when victims manually try to change it.
Previously, there existed another malware which infected windows Systems "DNSUnlocker" incidentally used the same subnet. Furthermore, the root certificates which are installed on the victim’s systems too are similar.
How does MaMi function?
* Installs a local certificate – Installation of root certificate allows the threat to perform an effective MITM attack, which may range from stealing logon credentials to ad insertions.
* Set up custom DNS settings – The DNS IP added by MaMi are under the control of the criminals and they may resolve every request by the victims and redirect them to malicious domains or advertisements controlled by the criminals.
* Take screenshots – of the desktop
* Run AppleScripts – Ability to execute script allows the Trojan to execute tasks, as per the defined payload
* Get OS launch persistence – At system start-up load itself
* Download and upload files – Allows to steal sensitive files and in all probability download additional modules / scripts
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
ICONS OF INDIA : SANJAY GUPTA
Sanjay Gupta is the Country Head and Vice President of Google India an...
ICONS OF INDIA : S KRISHNAN
S Krishnan as the secretary for the electronics and information techno...
Icons Of India : Arundhati Bhattacharya
Arundhati Bhattacharya serves as the Chairperson and CEO of Salesforce...
PFC - Power Finance Corporation Ltd
PFC is a leading financial institution in India specializing in power ...
BSE - Bombay Stock Exchange
The Bombay Stock Exchange (BSE) is one of India’s largest and oldest...
UIDAI - Unique Identification Authority of India
UIDAI and the Aadhaar system represent a significant milestone in Indi...
Indian Tech Talent Excelling The Tech World - Sundar Pichai, CEO- Alphabet Inc.
Sundar Pichai, the CEO of Google and its parent company Alphabet Inc.,...
Indian Tech Talent Excelling The Tech World - Aman Bhutani, CEO, GoDaddy
Aman Bhutani, the self-taught techie and CEO of GoDaddy, oversees a co...
Indian Tech Talent Excelling The Tech World - Steve Sanghi, Executive Chair, Microchip
Steve Sanghi, the Executive Chair of Microchip Technology, has been a ...