Summary
CrescentCore is a newly observed trojan targeting Mac devices worldwide.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, CrescentCore is delivered disguised as the Adobe Flash Player multimedia application, distributed through third-party hosting sites. When downloaded, CrescentCore will check for the presence of anti-virus or virtualisation services, terminating itself if any are detected.
Once installed, CrescentCore will create a LaunchAgent folder to maintain persistence before attempting to redirect browser sessions to redirect the user to advertising sites. Certain CrescentCore variants will also attempt to install malicious Safari browser extensions or other unwanted software.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:48 pm