Snake: Coming soon in Mac OS X flavour
ID: c856bbfd-e23a-5270-9885-a436540e5d67
STIX ID: report--c856bbfd-e23a-5270-9885-a436540e5d67
Feed Name: Fox-IT blog
Fox-IT analyzed a Mac OS X port of the Snake (Turla) targeted-attack framework — a sophisticated APT toolkit previously used against government, military and large corporate targets — finding a backdoored “Install Adobe Flash Player.app” signed with a likely stolen Developer ID (signed 21 Feb 2017) that installs components under /Library/Scripts and a LaunchDaemon for persistence; the sample contains debug strings and placeholder/obfuscated values indicating it may not yet be operational, but includes queue-configured transport chains, IOCs (file paths and SHA256 hashes), and a configured domain (car-service.effers.com resolving to 83.229.87.11); Fox-IT notified Apple to revoke the certificate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
