Mac Version of DNS Locker is Found
Recently, malware has been found that modifies the DNS which is targeting Mac users. Although the source of the distribution is yet confirmed, it is thought to be quite similar to DNS Unlocker, a Windows-based adware discovered in 2016.
This exploitative metod of changing the IP of the DNS server is being used by other malware, such as pharming and adware, and not only by the DNS changing malware programs.
The reason for its popularity is that the changing the IP of the DNS server to a server IP of the malware manufacturer’s choice enables them to easily conduct malicious activity as the computer will always be accessible via the new domain’s DNS server IP.
Also, even if the malware itself removed, it is difficult for the user to recognize the change in the DNS server unless there is a problem while using the Internet; thus users are likely to be still affected without knowing.
The recently discovered Mac malware is thought to be an early version because of its flaws. One of the fundamental indicators of its immaturity is the fact that, code signing is not used which makes the malware highly likely to be blocked by the GateKeeper upon execution.
[Figure 1] Code signing information
If a system is infected, the IP address of the DNS server is changed to 82.163.143.135 and 82.163.142.137, as shown in Figure 2.
[Figure 2] The new DNS server address after infection
When the malware was analyzed, other potential functions besides changing the IP address of the DNS server were found, such as taking screenshots, creating mouse events, downloading files, and command executions, as shown in Figure 3.
[Figure 3] Malware functions
One interesting point is that DNS Unlocker has a similar DNS IP address to Windows malware that has been found in the past.
As shown in Figure 4, the DNS Changer found on the Mac was 82.163.143.135 / 82.163.142.137 and a DNS Unlocker found on Windows around 2016 was 82.163.143.180 / 82.163.142.182. Therefore we assume that these were designed by the same attacker.
[Figure 4] Mac DNS Changer (left) / Windows DNS Unlocker (right)
As mentioned before, DNS changing malware has a high reinfection rate after it’s deleted from the system as it is not easy for the user to figure out that the file has not been totally removed which leads to a continued damage.
Even though this malware is only an early version of a DNS changer, it contains functions to hijack important aspects of a person’s computer like user execution and command execution.
In conclusion, every user has to take precautions whether they are on Macs or they are Windows users, and unidentified files must be treated with caution. Also, users must always apply the security patches and the latest version updates of key applications and operating systems.
The aliases identified by AhnLab’s security solutions are as below:
<Aliases identified by AhnLab V3>
- OSX/Dnschanger.557394
<Aliases identified by AhnLab MDS>
- Malware/ETC.Agent-6419373-0