PULSE NAME
IKITTENS: IRANIAN ACTOR RESURFACES WITH MALWARE FOR MAC (MACDOWNLOADER)
WHITE Charming Kitten AlienVault 2017-02-06 Modified: 2017-02-06
5
IOCs
LOW VOLUME
A macOS malware agent, named MacDownloader, was observed in the wild as targeting the defense industrial base, and reported elsewhere to have been used against an human rights advocate. MacDownloader strangely attempts to pose as both an installer for Adobe Flash, as well as the Bitdefender Adware Removal Tool, in order to extract system information and copies of OS X keychain databases. Based on observations on infrastructure, and the state of the code, we believe these incidents represent the first attempts to deploy the agent, and features such as persistence do not appear to work. Instead, MacDownloader is a simple exfiltration agent, with broader ambitions.
Indicators of Compromise (5)
All FileHash-SHA256 hostname domain URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 7a9cdb9d608b88bd7afce001cb285c2bb2ae76f5027977e8635aa04bd064ffb7 2017-02-06
FileHash-SHA256 52efcfe30f96a85c9c068880c20663db64f0e08346e0f3b59c2e5bbcb41ba73c 2017-02-06
hostname utc.officialswebsites.info 2017-02-06
domain officialswebsites.info 2017-02-06
URL http://46.17.97.37/Servermac.php 2017-02-06