Menu
New Tor-powered backdoor program targets Macs

New Tor-powered backdoor program targets Macs

The Eleanor malware allows attackers to execute commands and scripts, steal and modify files and take pictures using the webcam

Security researchers have found a new backdoor program that allows attackers to hijack Mac systems and control them over the Tor network.

The new malware has been dubbed Backdoor.MAC.Eleanor by researchers from antivirus vendor Bitdefender and is distributed as a file converter application through reputable websites that offer Mac software.

The rogue application is called EasyDoc Converter. Once installed it displays a fake interface where users can supposedly drag and drop files for conversion, but which in reality doesn't do anything.

In the background, the application executes a shell script that installs multiple malicious components in a folder called “/Users/$USER/Library/.dropbox." The Dropbox name is used to make the malware harder to spot and has nothing to do with the legitimate Dropbox file synchronization software.

The Eleanor malware has three components: a Web service with a PHP application, a Tor hidden service that allows attackers to connect to the affected systems over the Tor anonymity network and an agent that posts the Tor access URLs for infected systems to the Pastebin website.

The PHP application served by the Web service is actually a backdoor that allows attackers to view, edit, rename, delete, upload, download and archive files on the system; to execute shell commands and scripts written in PHP, Perl, Python, Ruby, Java and C; to open a reverse shell to the attackers' server; to connect to MySQL, SQLite and other databases; to view the process list and to send emails with attachments. Another component of this application allows attackers to capture images and videos using the system's webcam.

The Tor component connects the computer to the Tor network and makes its rogue Web service accessible via a .onion URL. This type of URL can only be accessed from within the Tor network.

The Pastebin agent takes the system's .onion URL, encrypts it with an RSA public key and posts it on Pastebin where attackers can find it and use it.

The oldest Pastebin post identified by the Bitdefender researchers as being created by the Eleanor backdoor is dated April 19. But the company could not establish the total number of infected machines, because different Eleanor samples upload URLs to different Pastebin accounts and they don't have all the samples.

The good news is that the app is not digitally signed by an Apple-approved certificate, so users will see security warnings on the latest OS X version if they try to install it. On OS X El Capitan (10.11) users would actually need to perform a manual override in order to install the application.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments