OSX/Crisis has been used as part of a targeted attack

From Botnets.fr
Jump to navigation Jump to search

(Publication) Google search: [1]

OSX/Crisis has been used as part of a targeted attack
Botnet Crisis
Malware
Botnet/malware group
Exploit kits
Services
Feature
Distribution vector
Target
Origin
Campaign
Operation/Working group
Vulnerability
CCProtocol
Date 2012 / 26 juillet 2012
Editor/Conference Intego
Link http://www.intego.com/mac-security-blog/osxcrisis-has-been-used-as-part-of-a-targeted-attack/ (Archive copy)
Author Lysa Myers
Type

Abstract

New information about the OSX/Crisis samples we spotted on VirusTotal is continuing to come to light. It turns out that the samples were submitted by a group of security researchers from DefensiveLab. They were submitting the files on behalf of a customer who was infected by the Trojan. The customer is a Moroccan journalist, and it appears that this infection is part of a larger attack that is being targeted against a group of independent Moroccan journalists who received an award from Google for their efforts during the Arab Spring revolution.

Bibtex

 @misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2012BFR1116,
   editor = {Intego},
   author = {Lysa Myers},
   title = {OSX/Crisis has been used as part of a targeted attack},
   date = {Error: Invalid time.},
   month = Error: Invalid time.,
   year = {2012},
   howpublished = {\url{http://www.intego.com/mac-security-blog/osxcrisis-has-been-used-as-part-of-a-targeted-attack/}},
 }