Skip to main content
Question

Detecting iWorm malware

  • October 3, 2014
  • 9 replies
  • 35 views

elliotjordan
Forum|alt.badge.img+12

I'm following this with interest:
http://9to5mac.com/2014/10/02/new-mac-botnet-malware-uses-reddit-to-find-out-what-servers-to-connect-to/

I made an extension attribute to detect the existence of the telltale /Library/Application Support/JavaW folder:
https://gist.github.com/homebysix/5f1e09b7a3e75c229ef1

Anybody seen this in the wild yet?

9 replies

Forum|alt.badge.img+16
  • Valued Contributor
  • October 3, 2014

No. Hopefully one of the security companies tracks down the infection vector soon.

http://www.intego.com/mac-security-blog/iworm-botnet-uses-reddit-as-command-and-control-center/


Forum|alt.badge.img+3
  • New Contributor
  • October 3, 2014

I have not seen it yet but will be watching closely

( i did test the EA. It works well with my test environment so I will be monitoring my smart group.)

@elliotjordan Thanks for the post!!!!


adhuston
Forum|alt.badge.img+9
  • Contributor
  • October 3, 2014

@elliotjordan Thanks for posting this! I was looking closely at how to detect it. I was thinking about putting in a Software Restriction, but since the malware masquerades as a legitimate process, I'm worried about killing it. Anyone else thought of a way to put a software restriction in place to keep the process from running?


Forum|alt.badge.img+3
  • New Contributor
  • October 3, 2014

Maybe use the little script in the EA and only run the kill command on a positive result.


emily
Forum|alt.badge.img+26
  • Hall of Fame
  • October 3, 2014

Sophos released a threat signature, so folks using Sophos Anti-Virus should be okay: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/OSX~iWorm-A.aspx


Forum|alt.badge.img+10
  • Contributor
  • October 3, 2014

@emilykausalik,

Thank you for posting this.

We use Sophos AV - I'll make sure the Sophos security team here gets this.

@elliotjordan, thank you for posting too.


Forum|alt.badge.img+22
  • Honored Contributor
  • October 4, 2014

EA and smart group work perfectly, thx @elliotjordan][/url. So far just my test machine reports positive. I'd be interested to hear what get placed in that javaw folder once someone sees an infection.


farverk
Forum|alt.badge.img+6
  • Contributor
  • October 4, 2014

Currently using this EA. Thanks Elliot!


gskibum
Forum|alt.badge.img+13
  • Valued Contributor
  • October 6, 2014

Looks like Apple released an XProtect update for this.

http://www.mactech.com/2014/10/06/apple-updates-xprotect-malware-list