ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Experts Uncover New CloudMensis Spyware Targeting Apple macOS Users

highMalwareimportance 47CVE-2020-9934

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-9934
Environment Variable Handling Information Disclosure in Apple iOS, iPadOS, and macOS

CVE-2020-9934 is an input validation flaw in the way Apple operating systems handled environment variables, which could allow a local user to view sensitive user information. It is triggered by a local attacker or user with limited privileges running code or commands on a vulnerable device, where the mishandled environment variables leak data. Successful exploitation results in disclosure of confidential information only, with no impact on data integrity or availability per the CVSS scoring. It affects devices running iOS or iPadOS versions before 13.6 and macOS Catalina versions before 10.15.6. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-08, confirming exploitation in the wild, though no public proof-of-concept is known.

Do: Upgrade affected devices to iOS 13.6 / iPadOS 13.6 or later, and macOS Catalina systems to 10.15.6 or later, as required by CISA's KEV listing. Because exploitation requires local access, restrict local user accounts on shared Macs and iOS devices and review who can execute code on them. Use MDM or endpoint inventory to confirm fleet-wide patch levels against these minimum versions.

5.53% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 13.6
  • Apple iPadOS versions prior to iPadOS 13.6
  • Apple macOS (macOS Catalina) macOS Catalina versions prior to 10.15.6
masshundreds of millions of devices (Apple's active iOS/macOS install base exceeds 1 billion, and all devices on pre-fix builds at disclosure were affected)
Full article421 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 19, 2022

Cybersecurity researchers have taken the wraps off a previously undocumented spyware targeting the Apple macOS operating system.

The malware, codenamed CloudMensis by Slovak cybersecurity firm ESET, is said to exclusively use public cloud storage services such as pCloud, Yandex Disk, and Dropbox for receiving attacker commands and exfiltrating files.

"Its capabilities clearly show that the intent of its operators is to gather information from the victims' Macs by exfiltrating documents, keystrokes, and screen captures," ESET researcher Marc-Etienne M.Léveillé said in a report published today.

CloudMensis, written in Objective-C, was first discovered in April 2022 and is designed to strike both Intel and Apple silicon architectures. The initial infection vector for the attacks and the targets remain unknown as yet. But its very limited distribution is an indication that the malware is being used as part of a highly targeted operation directed against entities of interest.

The attack chain spotted by ESET abuses code execution and administrative privileges to launch a first-stage payload that's utilized to fetch and execute a second-stage malware hosted on pCloud, which, in turn, exfiltrates documents, screenshots, and email attachments, among others.

The first-stage downloader is also known to erase traces of Safari sandbox escape and privilege escalation exploits that make use of four now-resolved security flaws in 2017, suggesting that CloudMensis may have flown under the radar for many years.

The implant also comes with features to bypass the Transparency, Consent, and Control (TCC) security framework, which aims to ensure that all apps obtain user consent before accessing files in Documents, Downloads, Desktop, iCloud Drive, and network volumes.

It achieves this by exploiting another patched security vulnerability tracked as CVE-2020-9934 that came to light in 2020. Other functions supported by the backdoor include getting the list of running processes, capturing screenshots, listing files from removable storage devices, and running shell commands and other arbitrary payloads.

On top of that, an analysis of metadata from the cloud storage infrastructure shows that the pCloud accounts were created on January 19, 2022, with the compromises commencing on February 4 and peaking in March.

"The general quality of the code and lack of obfuscation shows the authors may not be very familiar with Mac development and are not so advanced," M.Léveillé said. "Nonetheless a lot of resources were put into making CloudMensis a powerful spying tool and a menace to potential targets."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/07/experts-uncover-new-cloudmensis-spyware.html