Το νέο κακόβουλο λογισμικό XLoader κλέβει διαπιστευτήρια από macOS και Windows

Check Point experts μίλησε για a new cross-platform malware XLoader, ένα “subscriptionto which costs only $49 on the darknet. XLoader provides the opportunity to collect credentials, can act as a keylogger and runs malicious files.

XLoader originated from the well-known Formbook malware family, which mainly attacked Windows users, but disappeared from the market in 2018. Σε 2020, Formbook was renamed XLoader.

Νέο κακόβουλο λογισμικό XLoader

XLoader was first spotted last February and has gained popularity by promoting it as a cross-platform (Windows and macOS) botnet with no dependencies. The connection between the two malwares was established after it was discovered that the new malware uses the same executable file as the Formbook earlier. Then the malware vendor explained that the Formbook developer had really contributed a lot to the creation of XLoader. Because of this, malware has very similar functionality (stealing credentials, taking screenshots, κλείσιμο πλήκτρων, and executing malicious files).

Looking at XLoader activity over the past six months, Check Point analysts found that it now targets not only Windows users, but macOS users as well. You can “rent” the version for macOS for $49 a month, having access to a server provided by the seller. By maintaining a centralized management infrastructure, malware authors can control how their clients use XLoader.

The Windows version is more expensive, as for it the the seller asks for $59 per month, ή $129 for three months.

Οπως αναφέρθηκε προηγουμένως, researchers tracked Xloader activity from December 1, 2020 to June 1, 2021, and during this time they recorded requests to buy XLoader from hackers from 69 countries. Εξάλλου, more than half (53%) of malware victims live in the United States.

XLoader is much more sophisticated than its predecessors, and it supports various operating systems, in particular macOS. Historically, macOS threats have not been widespread: they were generally spyware and did not cause too much damage. I think there is a common misconception among macOS users that Apple is more secure than others. Προηγουμένως, we could say that there was a gap between malware for Windows and macOS, but now it is gradually narrowing. Malware for macOS is becoming more and more dangerous and widespread. Our recent research confirms this trend. Cybercriminals are increasingly interested in the macOS platformand personally, I expect to see more cyber threats very soon. The Formbook family is just the beginning. Επομένως, I would think twice before opening attachments from emails that I receive from unknown senders.Yaniv Balmas, Head of Cyber Research at Check Point Software, λέει.

Επιτρέψτε μου να σας υπενθυμίσω ότι το έγραψα και αυτό Οι ερευνητές ανακάλυψαν το κακόβουλο λογισμικό Siloscape που στοχεύει κοντέινερ Windows Server και συμπλέγματα Kubernetes.

Helga Smith

Ενδιαφέρομαι πάντα για τις επιστήμες των υπολογιστών, ειδικά την ασφάλεια δεδομένων και το θέμα, που ονομάζεται σήμερα "επιστημονικά δεδομένα", από τα πρώτα μου χρόνια. Πριν μπείτε στην ομάδα κατάργησης ιών ως αρχισυντάκτης, Εργάστηκα ως ειδικός στον τομέα της ασφάλειας στον κυβερνοχώρο σε πολλές εταιρείες, συμπεριλαμβανομένου ενός από τους εργολάβους της Amazon. Μια άλλη εμπειρία: Έχω διδάξει σε πανεπιστήμια Arden και Reading.

Αφήστε μια απάντηση

Αυτό το site χρησιμοποιεί Akismet να μειώσει το spam. Μάθετε πώς γίνεται επεξεργασία των δεδομένων σας σχόλιο.

Κουμπί Επιστροφή στην κορυφή