Summary:
The traditional method of delivering malware through cracked software has persisted as a prominent threat, targeting users seeking free versions of paid applications. Recently, a discovery has been made concerning hacked macOS applications distributed through pirated sites, which contain a proxy Trojan. Users downloading and installing such compromised software willingly expose themselves to potential threats by bypassing security measures. Unlike genuine applications distributed as disk images, these infected versions are distributed as .PKG installers, allowing the execution of scripts before and after installation.[/subscribe_to_unlock_form]
Summary:
The traditional method of delivering malware through cracked software has persisted as a prominent threat, targeting users seeking free versions of paid applications. Recently, a discovery has been made concerning hacked macOS applications distributed through pirated sites, which contain a proxy Trojan. Users downloading and installing such compromised software willingly expose themselves to potential threats by bypassing security measures. Unlike genuine applications distributed as disk images, these infected versions are distributed as .PKG installers, allowing the execution of scripts before and after installation.[emaillocker id="1283"]
The malicious script embedded in these .PKG installers reveals a sophisticated attack. The script deletes specific files from the user's system and replaces them with counterparts from the installer's resources folder, providing the malicious files with administrator rights. The configuration file, p.plist, masquerades as a Google configuration file and initiates the autorun of the WindowServer file after system startup, appearing as a legitimate system process. The WindowServer Trojan, despite escaping detection by antivirus vendors, creates log files, uses DNS-over-HTTPS for covert communication with a command and control (C&C) server, and connects via the WebSocket protocol to receive commands for various operations.
The Trojan's capabilities include message processing, pausing and continuing command processing, and waiting for the next command. Despite various versions with differences in functionality, all share the objective of creating proxy servers and can be used for illicit activities, such as launching attacks or facilitating the acquisition of illegal goods. Furthermore, the malware connects to the C&C server through WebSocket, sending its version and expecting commands in return. The Trojan is designed to handle commands for establishing connections, supporting both TCP and UDP protocols.
The proxy Trojan-infected macOS applications highlights the ongoing threat posed by malware distributed through cracked software. Users engaging in the download and installation of illicit software expose themselves to potential compromise, allowing attackers to execute various malicious activities on their systems. The Trojan's ability to connect with a C&C server, receive commands, and perform diverse operations underscores the importance of user vigilance and the need for robust cybersecurity practices to mitigate such threats effectively. As technology evolves, so too must the awareness and defenses against sophisticated malware campaigns.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]