Home > Threat descriptions >

Backdoor:OSX/MacKontrol.A

Classification

Category: Malware

Type: Backdoor

Aliases: Backdoor:OSX/MacKontrol.A

Summary


Backdoor:OSX/MacKontrol.A connects to a remote server to receive further instructions, without the knowledge or permission from the user.

Removal


Manual Removal Instructions
  • 1. Open Activity Monitor, select launched, and click Quit Process.
  • 2. Open Terminal, then execute the following:
    • rm /Library/launched
    • rm ~/Library/LaunchAgents/com.apple.FolderActionsxl.plist
Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details


Arrival

MacKontrol.A is dropped into the system by malicious Word documents that exploit the vulnerability identified by CVE-2009-0563.

Installation

The malware drops the following copy of itself:

  • /Library/launched

It creates the following launchpoint for the file above:

  • ~/Library/LaunchAgents/com.apple.FolderActionsxl.plist
Payload

The malware connects tofreetibet2012[...].xicp.com[...] to obtain additional commands.

It is capable of performing the following actions:

  • Deleting files
  • Terminating processes
  • Getting system info, such as system version, username, hostname, etc.
  • Getting process lists
  • Opening remote shell
  • Listing files
  • Uploading, downloading and executing files
  • Removing launchpoint