Skip to main content

Possible Russian hacker network may be responsible for new MacOS malware

google perspective machine learning machack feat
A particularly virulent form of cyberattack was identified when the Stuxnet malware wreaked havoc at Iran’s nuclear processing facilities. Discovered in 2010, the attack resulted in the creation of a new term, “advanced persistent threat” (APT), to designate a cyberattack that is intended to break into a particular target and work over a long period of time at stealing data or breaking down infrastructure.

But the Stuxnet attack was not the first example of an APT. Another, a hacker network dubbed APT28 and linked by some sources with Russian government or criminal elements, has been at work since 2007 targeting a number of industries and sectors in Ukraine, Spain, Russian, Romania, the U.S., and Canada. Anti-malware software company Bitdefender generated a report on APT28 in 2016 and has provided an update on its Bitdefender Labs blog connecting it to new MacOS malware.

The specific malware, called Xagent, is cross-platform software that also attacks iOS devices to steal contact and location information, apps lists, photos, and more. The MacOS version of Xagent is aimed at gaining access to passwords, taking screenshots, and most important breaking into iPhone backups to grab the same data as the iOS version.

Bitdefender has now connected the MacOS version of Xagent with APT28: “Our past analysis of samples known to be linked to APT28 group shows a number of similarities between the Sofacy/APT28/Sednit Xagent component for Windows/Linux and the MacOS binary that currently forms the object of our investigation. For once, there is the presence of similar modules, such as FileSystem, KeyLogger and RemoteShell, as well as a similar network module called HttpChanel.”

In addition, the Xagent sample that Bitdefender’s researchers examined connect to the same command-and-control web address that’s the same as the ones used by APT28. Bitdefender is still conducting its analysis but at least initially it appears that APT28 operators may now have a new tool — compromised MacOS machines — to use in attacking government agencies, political figures, telecommunications, ecrime services, and aerospace companies.

Editors' Recommendations

Mark Coppock
Mark has been a geek since MS-DOS gave way to Windows and the PalmPilot was a thing. He’s translated his love for…
Ranking the best (and worst) versions of macOS from the last 20 years
An Apple iMac from 2019 placed on a desk. The macOS Mojave operating system is on its display.

Apple’s macOS operating system is known for its stability and features, but it wasn’t always this way. Throughout the history of macOS (and OS X before it), there have been some real stinkers that Apple would probably rather we all forgot about. Yet there have also been some classic versions that still live fondly in the memories of Mac users new and old.

In this article, we’ve picked five of the best versions of Apple’s Mac operating system, as well as five of its worst, presented in chronological order. We’ve started with the launch of OS X 10.0 in 2001 and continued right up to the present, past the operating system’s rebranding as macOS in 2016. If Windows is your speed, we've also ranked the best Windows versions of all time. Let’s explore Apple’s greatest hits -- and some of its worst howlers.
Worst: OS X 10.0 Cheetah (2001)

Read more
Common macOS Ventura problems and how to fix them
A MacBook Pro M2 sits on a wooden table with a nice bokeh background.

Apple released macOS Ventura in late October of 2022 bringing several interesting features as well as a few new problems. If you're having trouble after upgrading from macOS Monterey to Ventura, here are some solutions that could help.
AirDrop isn't working

AirDrop is a fantastic feature when it works and incredibly frustrating when it doesn't. A macOS update sometimes leads to AirDrop problems. Luckily a few simple tips can usually correct the problem. The easiest solution is to open the Control Center and toggle AirDrop off and on again. You can also try switching between Contacts Only and Everyone.

Read more
This critical macOS flaw may leave your Mac defenseless
A close-up of a MacBook illuminated under neon lights.

Apple’s macOS operating system has such a strong reputation for security that many people mistakenly believe Macs simply aren’t affected by malware. Well, Microsoft has served up a reminder that that’s not true, as the company has identified a serious vulnerability that affects one of macOS’s most important lines of defense.

According to Bleeping Computer, the bug was first reported by Jonathan Bar Or, Microsoft’s principal security researcher, who named the flaw Achilles. It is now tracked as CVE-2022-42821.

Read more