SabPub Mac OS X Backdoor: Java Exploits, Targeted Attacks and Possible APT linkLast week, Apple released two urgent updates to Mac OS X to: <p> 1. Remove the Flashback malware about which we have already <a href="http://www.securelist.com/en/blog/208193441/Flashfake_Mac_OS_X_botnet_confirmed">written</a> <p> 2. Automatically deactivate the Java browser plugin and Java Web Start, effectively disabling java applets in browsers <p> Particularly, the second step shows the severity of the <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0507">CVE-2012-0507 vulnerability</a> exploited by Flashback to infect almost 700,000 users via drive-by malware downloads. <p> Actually, it was the right decision because we can confirm yet another Mac malware in the wild - <b>Backdoor.OSX.SabPub.a</b> being spread through Java exploits. <p> This new threat is a custom OS X backdoor, which appears to have been designed for use in targeted attacks. After it is activated on an infected system, it connects to a remote website in typical C&C fashion to fetch instructions. The backdoor contains functionality to make screenshots of the user’s current session and execute commands on the infected machine. <p> <p class=c><img src="images/pictures/klblog/208193468.png" border="1" alt="" title="Backdoor connects to remote server to fetch work"></p>
Source:
SabPub Mac OS X Backdoor: Java Exploits, Targeted Attacks and Possible APT link