Virtual Event: CodeSecCon - Learn to Secure Your Software > View Sessions
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Uyghur Activists Once Again Targeted by Mac OS Malware

A malicious campaign that started last summer is once again targeting Uyghur activist groups in China. The latest developments in this year-long fight is a new variant of the documents used to target the activists earlier this year.

A malicious campaign that started last summer is once again targeting Uyghur activist groups in China. The latest developments in this year-long fight is a new variant of the documents used to target the activists earlier this year.

F-Secure reported that the variant was submitted to VirusTotal April 11 in China. The malicious email attachment uses an author tag of IUHRDF, which could be the International Uyghur Human Rights & Democracy Foundation. The payload itself is the same, a backdoor that targets Max OS X, and it targets vulnerabilities in Microsoft Word.

This latest attack has a history, as it’s tied to the “Luckycat” attacks that were discovered over a year ago by Kaspersky Lab and Trend Micro targeting Tibetan activists as well as people connected to military research, and aerospace and energy companies in India and Japan. Unlike this recent attack, the earliest version of the campaign targeted Java vulnerabilities.

While the payload remains the same, the method of infection changes depending on the latest software vulnerabilities. In June 2012, the person(s) controlling the campaign targeted activists by embedding a malicious JPEG photo and OS X application within a ZIP file.

Additional levels of attack against the activists also include malicious Android packages (APK), which were delivered last month. This twist targeted both Windows and Mac users. That campaign referenced the “World Uyghur Congress.” Shortly before Android, the attackers focused on PDF vulnerabilities.

“Although some of these attacks were observed during 2012, we’ve noticed a significant spike in the number of attacks during Jan 2013 and Feb 2013, indicating the attackers are extremely active at the moment,” Kaspersky’s Costin Raiu said of the previous version of this latest attack.

Advertisement. Scroll to continue reading.

“With these attacks, we continue to see an expansion of the APT capabilities to attack Mac OS X users. In general, Mac users operate under a false sense of security which comes from the years old mantra that ‘Macs don’t get viruses’…”

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

UltraViolet Cyber has named Andrew Park Chief Information Security Officer.

Glow has appointed Patti Degnan as Chief Information Security Officer.

Daniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.