Threat Advisory

Mac systems turned into proxy exit nodes by AdLoad

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Recent investigations reveal that the AdLoad malware, which first emerged in 2017, continues to pose a persistent threat to Mac systems. This malware employs a package bundler to distribute various payloads, and its latest incarnation has raised alarm due to its conversion of infected Mac devices into a sprawling residential proxy botnet. AdLoad malware remains active and infiltrating systems, introducing a previously unreported payload. Over the past year, approximately 150 distinct samples of AdLoad have been detected in the wild. Suspicious network behavior involving thousands of IPs resembling proxy exit nodes suggests a considerable number of Mac devices might have been compromised and repurposed. The malware's payloads are specific to macOS, but instances affecting Windows systems have also been observed.[/subscribe_to_unlock_form]

Summary:

Recent investigations reveal that the AdLoad malware, which first emerged in 2017, continues to pose a persistent threat to Mac systems. This malware employs a package bundler to distribute various payloads, and its latest incarnation has raised alarm due to its conversion of infected Mac devices into a sprawling residential proxy botnet. AdLoad malware remains active and infiltrating systems, introducing a previously unreported payload. Over the past year, approximately 150 distinct samples of AdLoad have been detected in the wild. Suspicious network behavior involving thousands of IPs resembling proxy exit nodes suggests a considerable number of Mac devices might have been compromised and repurposed. The malware's payloads are specific to macOS, but instances affecting Windows systems have also been observed.[emaillocker id="1283"]

AdLoad, part of a larger group of adware and bundleware loaders affecting macOS, has been operating since 2017. In the last two years, major campaigns have spotlighted its activity, highlighting its role as a downloader for subsequent payloads. Notably, AdLoad has been linked to diverse payloads, ranging from adware and bundleware to backdoors and proxy applications, indicating the malware's adaptability based on various system parameters. The malware's most common behavior involves establishing communication with an AdLoad server during execution on a victim's system. This communication likely facilitates tracking of infected systems for pay-per-install campaigns. A novel discovery by threat analysts suggests AdLoad's recent payloads involve turning compromised Mac systems into proxy exit nodes, forming a sizable proxy botnet.

The infection process involves an intricate series of steps, including downloading and executing a proxy application. The malware establishes communication with command-and-control servers, registering system information and initiating proxy operations. The proxy servers operate over specific ports, frequently used for proxy communications.

To protect against the AdLoad malware and its proxy botnet, take the following steps: Use Yara rules to detect AdLoad samples, examine systems for suricata rules 4002758 and 2038612, remove any questionable files from the 'Application Support' folders, review and remove unnecessary agents from '/Library/LaunchAgents', and closely monitor systems for unusual communication on ports 7000, 7001, and 7002. These measures will help prevent and address potential infections and unauthorized proxy server activity.

The AdLoad malware's continued presence underscores the significance of ongoing vigilance against threats to Mac systems. Users must not underestimate the potential risks posed by malware targeting popular operating systems. The emergence of a proxy botnet from AdLoad-infected systems exemplifies the adaptability of cybercriminals in exploiting compromised devices for malicious purposes. Organizations and individuals alike should prioritize robust cybersecurity practices to mitigate such risks.

Threat Profile:

References:

The following reports contain further technical details:

https://cybersecurity.att.com/blogs/labs-research/mac-systems-turned-into-proxy-exit-nodes-by-adload

[/emaillocker]
crossmenu