macOS hit by 'MaMi' malware
By MYBRANDBOOK
Way back in 2012, we faced DNSChanger malware which affected millions of Windows PCs and in the first week of 2018 we have observed the emergence of a DNSChanger malware for MacOS. The threat was first discovered by Patrick Wardel and has been named as MaMi.
Similar to DNSChanger, MaMi's infection vector involves various recently registered domains from where it is downloaded and subsequently installed. Post infection, MaMi forcibly changes the DNS entry and also installs a root certificate. Furthermore, it is highly persistent and reverts back to malicious DNS entries, when victims manually try to change it.
Previously, there existed another malware which infected windows Systems "DNSUnlocker" incidentally used the same subnet. Furthermore, the root certificates which are installed on the victim’s systems too are similar.
How does MaMi function?
* Installs a local certificate – Installation of root certificate allows the threat to perform an effective MITM attack, which may range from stealing logon credentials to ad insertions.
* Set up custom DNS settings – The DNS IP added by MaMi are under the control of the criminals and they may resolve every request by the victims and redirect them to malicious domains or advertisements controlled by the criminals.
* Take screenshots – of the desktop
* Run AppleScripts – Ability to execute script allows the Trojan to execute tasks, as per the defined payload
* Get OS launch persistence – At system start-up load itself
* Download and upload files – Allows to steal sensitive files and in all probability download additional modules / scripts
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
NETWEB TECHNOLOGIES INDIA LTD.
VEHERE INTERACTIVE PVT. LTD.
HP INDIA SALES PVT. LTD.
DRUVA SOFTWARE PVT. LTD.
Icons Of India : Arjun Malhotra
Arjun Malhotra, the Chairman of Magic Software Inc., is widely recogni...
Icons Of India : Kumar Mangalam Birla
Aditya Birla Group chairman Kumar Mangalam Birla recently made a comeb...
Icons Of India : B.V.R. Subrahmanyam
A 1987 batch (Chhattisgarh cadre) Indian Administrative Service Office...
BSE - Bombay Stock Exchange
The Bombay Stock Exchange (BSE) is one of India’s largest and oldest...
HPCL - Hindustan Petroleum Corporation Ltd.
HPCL is an integrated oil and gas company involved in refining, market...
PFC - Power Finance Corporation Ltd
PFC is a leading financial institution in India specializing in power ...
Indian Tech Talent Excelling The Tech World - Sundar Pichai, CEO- Alphabet Inc.
Sundar Pichai, the CEO of Google and its parent company Alphabet Inc.,...
Indian Tech Talent Excelling The Tech World - Steve Sanghi, Executive Chair, Microchip
Steve Sanghi, the Executive Chair of Microchip Technology, has been a ...
Indian Tech Talent Excelling The Tech World - ANJALI SUD, CEO – Tubi
Anjali Sud, the former CEO of Vimeo, now leads Tubi, Fox Corporation...