Summary:
Researchers have taken the wraps off a previously undocumented spyware targeting the Apple macOS operating system. The malware, codenamed CloudMensisis said to exclusively use public cloud storage services such as pCloud, Yandex Disk, and Dropbox for receiving attacker commands and exfiltrating files. CloudMensis, written in Objective-C, discovered in April 2022 and is designed to strike both Intel and Apple silicon architectures. The initial infection vector for the attacks and the targets remains unknown as yet. But its limited distribution is an indication that the malware is being used as part of a highly targeted operation directed against entities of interest. The attack chain spotted by ESET abuses code execution and administrative privileges to launch a first-stage payload that's utilized to fetch and execute a second-stage malware hosted on pCloud, which, in turn, exfiltrates documents, screenshots, and email attachments, among others.[/subscribe_to_unlock_form]
Summary:
Researchers have taken the wraps off a previously undocumented spyware targeting the Apple macOS operating system. The malware, codenamed CloudMensisis said to exclusively use public cloud storage services such as pCloud, Yandex Disk, and Dropbox for receiving attacker commands and exfiltrating files. CloudMensis, written in Objective-C, discovered in April 2022 and is designed to strike both Intel and Apple silicon architectures. The initial infection vector for the attacks and the targets remains unknown as yet. But its limited distribution is an indication that the malware is being used as part of a highly targeted operation directed against entities of interest. The attack chain spotted by ESET abuses code execution and administrative privileges to launch a first-stage payload that's utilized to fetch and execute a second-stage malware hosted on pCloud, which, in turn, exfiltrates documents, screenshots, and email attachments, among others.[emaillocker id="1283"]
References:
The following reports contain further technical details:
https://thehackernews.com/2022/07/experts-uncover-new-cloudmensis-spyware.html
https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
[/emaillocker]