Article Lead Image

Screengrab via AppleInsider/YouTube

The Russian malware that took down the DNC can now infect Apple computers

URGENT: Download antivirus software.


Phillip Tracy


Posted on Feb 15, 2017   Updated on May 25, 2021, 12:00 am CDT

There is now a Mac OS X version of the Russian malware used to hack the Democratic National Committee last year and ultimately helped Donald Trump win the presidential election.

Researchers at Bitdefender Labs found a sample of a Mac-native version of the malware linked to Russian threat group APT28, the government-linked hackers who took down the DNC. It allows them to obtain passwords, capture screenshots, and even steal iPhone backups stored on an infected Mac.

“The analysis reveals the presence of modules that can probe the system for hardware and software configurations, grab a list of running processes and run additional files, as well as get desktop screenshots and harvest browser passwords,” the Bitdefender Labs report reads. “The most important module, from an intelligence-gathering perspective, is the one that allows the operator(s) to infiltrate iPhone backups stored on a compromised Mac.”

The research group believes this discovery in Mac is linked to the APT28 group because of similarities in the Xagent malware agent found in the Windows/Linux attack. It says the presence of similar modules, like FileSystem, KeyLogger, and RemoteShell, also suggests the malware comes from the same group.

It also said the malware reports to the same command-and-control URL used by APT28 for its other ‘Komplex’ malware tool.

We don’t know much else about the malicious software. Bitdefender Labs is still analyzing the modules it found in the malware and plans to release a full report soon.

In the meantime, do yourself a favor and install some antivirus software.

H/T Engadget

Share this article
*First Published: Feb 15, 2017, 2:22 pm CST