Mac spyware discovered on Angolan dissident's computer at Oslo Freedom Forum

Share this article:
FBI ransomware scam finds new home on the Mac
FBI ransomware scam finds new home on the Mac

Security researchers are studying an apparent new strain of Mac spyware that turned up on the computer of a participant at the just-concluded Oslo Freedom Forum, an annual human rights conference.

The backdoor was discovered by noted privacy and security researcher Jacob Appelbaum, who tweeted Thursday that it targeted the machine of an Angolan dissident. Angola is a southern African nation that has faced steep criticism for human rights abuses.

Analysts at security firm F-Secure studied the virus sample and learned that it was signed with a seemingly valid Apple Developer ID, steals screen shots and communicates with two command-and-control servers. F-Secure dubbed the malware OSX/KitM.A.

The spyware was discovered during a workshop that Appelbaum ran in which he instructed audience members on how to protect themselves from government surveillance.

The Oslo Freedom Forum event brings together "Influential dissidents, innovators, journalists, philanthropists, and policymakers" from around the world, according to the event's website.

Espionage malware built to run on Mac OS X machines is becoming increasingly common as more targets use the operating system.

UPDATE: Appelbaum said in a tweet that the activist's Mac was hit with the malware via a spear phishing attack.

UPDATE TWO: The SANS Internet Storm Center explained how it's possible to "verify and extract signatures and certificates on an Apple .app" as the attacker did in this instance.

Share this article:

Sign up to our newsletters

More in News

Errors in ZeroLocker means paying ransom may not decrypt files

A piece of ransomware known as ZeroLocker contains various errors that may prevent files from being decrypted even if the ransom is paid.

Rogue AV scammers find success with new tatics

Although the number of rogue anti-virus malware campaigns have decreased overall, the threat isn't totally gone, according to researchers at Microsoft.

Medical transcription provider settles data security charges

GMR Transcription Services in California agreed to settle FTC charges related to its security practices.