Mac Backdoors Leveraging Firefox Zero-Day Vulnerability
New variants of two backdoors, Netwire and Mokes, have been observed leveraging a zero-day vulnerability in the Mozilla Firefox web browser to infect macOS devices.
Summary
New variants of two backdoors, Netwire and Mokes, have been observed leveraging a zero-day vulnerability in the Mozilla Firefox web browser to infect macOS devices.
Affected platforms
The following platforms are known to be affected:
Threat details
Both backdoors are delivered via email containing links to a malicious site. When a user browses to the site using a vulnerable version of Firefox, the vulnerability is exploited to downloaded the malware. By leveraging this vulnerability the malware is able to bypass some of the security features built-in to macOS. Once deployed on a user's system, the backdoors persist as launch agents so that the malware is loaded each time the user logs in.
Both observed variants allow an attacker to execute arbitrary commands, take screenshots and steal system information from an infected machine. In addition, the Mokes variant has the capability to capture audio and video, steal documents and record keystrokes.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection by Netwire or Mokes, ensure that:
|
CVE Vulnerabilities
Last edited: 14 February 2020 2:50 pm