Author Topic: Fruitfly: the first Mac malware of 2017  (Read 1667 times)

Offline kimmer

  • Administrator
  • TS Addict
  • *****
  • Posts: 9086
    • View Profile
Fruitfly: the first Mac malware of 2017
« on: January 18, 2017, 11:08:07 AM »
Malwarebytes finds the ‘first Mac malware of 2017,’ Apple calls it ‘Fruitfly’

https://blog.malwarebytes.com/threat-analys...ntiquated-code/

https://9to5mac.com/2017/01/18/malware-macos-fruitfly/

According to Malwarebytes, “We still don't know how it gets installed. All samples so far have been observed installed in user space, so running in a standard user account will not protect against this.”

QUOTE
Malwarebytes will detect this malware as OSX.Backdoor.Quimitchin. (Why the name? Because the quimitchin were Aztec spies who would infiltrate other tribes. Given the “ancient” code, we thought the name fitting.) Apple calls this malware Fruitfly and has released an update that will be automatically downloaded behind the scenes to protect against future infections.

Offline Jack W

  • TS Addict
  • *****
  • Posts: 2597
    • View Profile
Fruitfly: the first Mac malware of 2017
« Reply #1 on: January 18, 2017, 01:55:47 PM »
QUOTE(kimmer @ Jan 18 2017, 12:08 PM) <{POST_SNAPBACK}>
Malwarebytes finds the ‘first Mac malware of 2017,’ Apple calls it ‘Fruitfly’

https://blog.malwarebytes.com/threat-analys...ntiquated-code/

https://9to5mac.com/2017/01/18/malware-macos-fruitfly/

According to Malwarebytes, “We still don't know how it gets installed. All samples so far have been observed installed in user space, so running in a standard user account will not protect against this.”

QUOTE
Malwarebytes will detect this malware as OSX.Backdoor.Quimitchin. (Why the name? Because the quimitchin were Aztec spies who would infiltrate other tribes. Given the “ancient” code, we thought the name fitting.) Apple calls this malware Fruitfly and has released an update that will be automatically downloaded behind the scenes to protect against future infections.


I ran FindAnyFile and entered ce07 and came up with a number of files containing that string.
They were all in a folder titled PubSub in my ~/Library folder:

[attachment=3355:PubSub_Folder.jpg]

Any relation to this Malware?

I have MalwareBytes in my Mavs partition, but not in my SL partition where these files appear.

Jack
Good to be Here.

My Macs: 2010 27" alum iMac 2.8GHz, Snow Leopard 10.6.8/Mavericks 10.9.5, 4GB SDRAM (Workhorse),
13” Late 2010 MacBook Pro 2.4GHz, 10.6.8, 2GB SDRAM,
(2) External HD - Firewire/USB Macally Enclosures  with 1TB Hitachi Drives,
Time Machine external drive - ditto above - 1/2 TimeMac

Offline kimmer

  • Administrator
  • TS Addict
  • *****
  • Posts: 9086
    • View Profile
Fruitfly: the first Mac malware of 2017
« Reply #2 on: January 18, 2017, 02:02:24 PM »
QUOTE(Jack W @ Jan 18 2017, 12:55 PM) <{POST_SNAPBACK}>
I ran FindAnyFile and entered ce07 and came up with a number of files containing that string.
They were all in a folder titled PubSub in my ~/Library folder:

[attachment=3355:PubSub_Folder.jpg]

Any relation to this Malware?

I have MalwareBytes in my Mavs partition, but not in my SL partition where these files appear.

Jack

No clue, Jack. I'd use MalwareBytes on your SL partition to be safe.

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Fruitfly: the first Mac malware of 2017
« Reply #3 on: January 18, 2017, 02:51:33 PM »
You might have better luck searching for "com.client.client". just searching for a few letters that made up the SHA 'code' will surely turn up dozens of the randomly created names for temporary files. You could simply open your ~/Library/LaunchAgents directory and look for "com.client.client". My bet is you'll not find it, unless you've been installing stuff from sites you shouldn't even visit, much less download from! laughhard.gif nono.gif
« Last Edit: January 18, 2017, 02:52:26 PM by Xairbusdriver »
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline jchuzi

  • TS Addict
  • *****
  • Posts: 3094
    • View Profile
Jon

macOS 11.7.10, iMac Retina 5K 27-inch, late 2014, 3.5 GHz Intel Core i5, 1 TB fusion drive, 16 GB RAM, Epson SureColor P700, Photoshop CC, Lightroom CC, MS Office 365

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Fruitfly: the first Mac malware of 2017
« Reply #5 on: January 18, 2017, 05:09:28 PM »
Had a Security Update just after I posted above. thumbup.gif
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline Jack W

  • TS Addict
  • *****
  • Posts: 2597
    • View Profile
Fruitfly: the first Mac malware of 2017
« Reply #6 on: January 19, 2017, 08:07:35 AM »
QUOTE(Xairbusdriver @ Jan 18 2017, 03:51 PM) <{POST_SNAPBACK}>
You might have better luck searching for "com.client.client". just searching for a few letters that made up the SHA 'code' will surely turn up dozens of the randomly created names for temporary files. You could simply open your ~/Library/LaunchAgents directory and look for "com.client.client". My bet is you'll not find it, unless you've been installing stuff from sites you shouldn't even visit, much less download from! laughhard.gif nono.gif

Not in there.
Besides, I have SL set to notify m if anything attempts to put something in the LaunchAgents.
Just a simple security measure.

Jack
Good to be Here.

My Macs: 2010 27" alum iMac 2.8GHz, Snow Leopard 10.6.8/Mavericks 10.9.5, 4GB SDRAM (Workhorse),
13” Late 2010 MacBook Pro 2.4GHz, 10.6.8, 2GB SDRAM,
(2) External HD - Firewire/USB Macally Enclosures  with 1TB Hitachi Drives,
Time Machine external drive - ditto above - 1/2 TimeMac