FLASHBACK OS X MALWARE
Broderick Ian Aquilino · 2012
Windows has been the target of malware for decades. Over time, the sustained pressure of being an attack target has forced its evolution into a more hardened system, as well as increasing user awareness of computer security. On the other hand, OS X has not needed to go through all the troubles of crime fi ghting until recently. Now, with its growing market share and lower user awareness, it is clear that OS X is becoming more and more attractive to malware authors. In 2011, we saw OS X come under siege by several malware families. Towards the end of the year, we saw new families or variants appear almost every week, where each was more sophisticated than the last. At the forefront of these developments was the Flashback malware. Flashback is the most advanced OS X malware we’ve ever seen. It boasts a series of fifor its kind. It was both the fi rst to be VMware-aware and the fi rst to disable XProtect, OS X’s built-in malware protection program. Both these features were removed from later variants (the former presumably to avoid heuristic detections, and the latter presumably once the authors realized it was unnecessary, as XProtect was not designed to protect against non-quarantine fi les). Their removal indicates that Flashback is actively being reviewed and improved by its authors. Another interesting fi rst is Flashback’s exploitation of an unpatched vulnerability in the Java distribution of OS X, which allowed it to infect more than 650,000 Macs around the world [1]. This made Flashback roughly as common for Macs as Confi cker was for Windows [2]. This means Flashback is not only the most advanced, but also the most successful OS X malware we’ve seen so far. Flashback’s infection strategy is explicitly designed to select unprotected systems and will not infect a machine if certain security software or analysis tools are found. This implies that Flashback’s authors are targeting less security-conscious users, at the expense of the total number of potential targets. This turns out to be an effective strategy, as security researchers had diffi culties getting suffi cient samples from users. It took a mistake on the part of Flashback’s author to alert users to the presence of an infection and subsequently, to lead to the mass discovery of the malware. So what is Flashback? Basically, it is a piece of malware that modifi es targeted web pages displayed in web browsers. In older variants, the targeted web pages and modifi cation were based on the confi gurations retrieved from a remote server during installation. In newer variants, the target and modifi cation have been hard-coded into the binaries.