Threat Description

Backdoor:​OSX/MacKontrol.A

Details

Aliases:Backdoor:​OSX/MacKontrol.A
Category:Malware
Type:Backdoor
Platform:OSX

Summary



Backdoor:OSX/MacKontrol.A connects to a remote server to receive further instructions, without the knowledge or permission from the user.



Removal



Manual Removal Instructions

  • 1. Open Activity Monitor, select launched, and click Quit Process.
  • 2. Open Terminal, then execute the following:
    • rm /Library/launched
    • rm ~/Library/LaunchAgents/com.apple.FolderActionsxl.plist


Technical Details



Arrival

MacKontrol.A is dropped into the system by malicious Word documents that exploit the vulnerability identified by CVE-2009-0563.

Installation

The malware drops the following copy of itself:

  • /Library/launched

It creates the following launchpoint for the file above:

  • ~/Library/LaunchAgents/com.apple.FolderActionsxl.plist

Payload

The malware connects tofreetibet2012[...].xicp.com[...] to obtain additional commands.

It is capable of performing the following actions:

  • Deleting files
  • Terminating processes
  • Getting system info, such as system version, username, hostname, etc.
  • Getting process lists
  • Opening remote shell
  • Listing files
  • Uploading, downloading and executing files
  • Removing launchpoint





SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Disinfect your Mac

F-Secure Anti-Virus for Mac will disinfect your Mac and remove all harmful files

Learn More