Chinese Mac attack aims weaponised files at Apple users. Meh!

Updated happygeek 1 Tallied Votes 555 Views Share

An ongoing attack aimed at users of the Apple Mac platform is being reported by security researchers. AlienVault, which has discovered these weaponised attacks in the wild, warns that regular Mac users without IT security software installed could be at risk of infection and hijacking.

alien The researchers suspect that the attack stems from the same anti-Tibetan, pro-Chinese, hacking group that has been targeting Tibetan activist organisations in recent weeks.

According to the lead researcher who made the discovery, Jaime Blasco, the group is "delivering two different Mac trojans" including a new and improved one called MacControl.

The weaponised files themselves are all MS-Office .doc files, and is quite rare in that malicious Office document files are hardly ever used in an attempt to deliver malware payloads to the Mac platform. AlienVault researchers have detailed how the files use a remote code execution vulnerability of MS-Word file handling of malformed records. Blasco warns that an attacker who successfully exploits this vulnerability can take control of the target Mac along with other networked computers.

I'm not sure just how much of a threat this latest in the wild attack actually is though, considering that for a start any Mac user operating without administrative rights is unlikely to be impacted. Nor, for that matter, are those users who have patched their copy of MS Office with the security updates that Microsoft made available way back in 2009. Yes, really, that long ago. While one has to assume that the hacktivist group in this case has its reasons for targeting Mac users with such an old and already patched, I am hard-pressed to imagine that it's going to be a hugely successful strategy.

Indeed, I have not heard of anyone whose Mac has actually been compromised by the MacControl Trojan either. And that despite 'several versions' of the thing having been coded according to Blasco and his team.

Dani AI

Generated

A few clarifications and practical notes that add to ’s points and address ’s speculation.

The campaign described used malicious Word documents to drop a Mac backdoor (tracked as MaControl / MacControl). Analysis from multiple vendors shows this was a targeted, not a worm-like, campaign aimed at specific activist groups; the operator relied on a remote-code‑execution flaw in Word rather than any Apple OS “backend” compromise. (securelist.com)

Why the risk wasn’t (and often isn’t) huge in practice: the attack needs the victim to open the poisoned .doc and runs with the user’s privileges, so patched Office installs and running as a non‑admin materially reduce risk. Targeted actors re-use older exploits to catch unpatched victims, so “old = harmless” is a dangerous assumption for high‑value targets. (nvd.nist.gov)

About the “inside job” idea: the public forensic indicators (C2 servers, reused backdoor code, social‑engineered attachments) point to remote APT activity rather than an assembly‑line insider inserting firmware or OS backdoors. Hardware assembly in China explains where devices are built, but it does not imply the kind of software backdoor the malware used; supply‑chain insertion is a different, much higher‑effort scenario and would show different traces. (securelist.com)

Practical takeaways:

  • Apply Office and macOS updates (including system data/security updates) and keep automatic updates enabled. (support.apple.com)
  • Don’t open unexpected .doc/.zip attachments; verify senders outside the message.
  • Use least‑privilege accounts and run malware scans/EDR on machines used for sensitive work.
  • High‑risk users (activists, journalists) should use hardened, dedicated systems and strict operational practices.

For historical context and detailed vendor analysis of the MaControl/targeted Mac campaigns, see the Kaspersky writeup and the CVE/NVD entry for the Word SPRM‑records issue. (securelist.com)

Member Avatar for Member #949455
Member #949455

The weaponised files themselves are all MS-Office .doc files, and is quite rare in that malicious Office document files are hardly ever used in an attempt to deliver malware payloads to the Mac platform. AlienVault researchers have detailed how the files use a remote code execution vulnerability of MS-Word file handling of malformed records. Blasco warns that an attacker who successfully exploits this vulnerability can take control of the target Mac along with other networked computers.

I had a friend who is chinese read a article told me it was an inside job meaning someone in the plant ( Apple Manufactured ) knew about backend of the platform.

Was this proofing?

No, the article was just speculation.

The reason because most of the IT products are Manufactured in China.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.