Threat: oRAT
Affects: A new macOS malware variant was recently discovered by Trend Micro researchers, dubbed oRAT. This malware has been attributed to a new APT group that targets gambling sites. oRAT malware was developed using the Go language and is capable of infecting Windows and macOS.
Prevented by:Jamf Protect threat prevention blocks the execution of this malware.
IOCs:
SHA1 Hashes26ccf50a6c120cd7ad6b0d810aca509948c8cd78 - UPX packed9b4717505d8d165b0b12c6e2b9cc4f58ee8095a6 - unpacked911895ed27ee290bea47bca3e208f1b302e98648 - preinstall scriptMalicious URLs (as published by Trend Micro):
In-the-Wild URLshttps://d[.]github.wiki/mac/darwinx64https://mmimdown[.]oss-cn-hongkong.aliyuncs.com/mac/mmchat-1.1.6.3.dmg----------Domains1.googie[.]ph12371829hkdanm[.]fbi.am139[.]5.202.82149[.]28.31.1661qw6etagydbn2peifj8hf[.]fbi.am2.googie[.]ph3.googie[.]ph42[.]200.181.11645[.]76.199.11945[.]77.22.215adobe-flash[.]wikiadobe[.]nameagph[.]ivi66.netbos[.]github.wikicaonimade[.]11i.med[.]github.wikidarknet[.]rootkit.toolsdarwin[.]github.wikidownload[.]mircrosoftscoulds.comdust[.]github.wikiexmail[.]googie.com.phfbi[.]fuckbc.comflash[.]wy886066.comfuckeryoumm[.]nmb.betfuckyou[.]fbi.amgb[.]googie.phhelloword[.]11i.mehelloword[.]daj8.mehk.whoamis[.]infohkdust[.]github.wikihuaidan[.]fbi.amlinux[.]daj8.melinux[.]daji8.melinux[.]shopingchina.netlinux[.]wy01.comlinux[.]wy01.viplinux1[.]shopingchina.netlinux2[.]shopingchina.netlist[.]whoamis.infolocalhost[.]11i.memail[.]whoamis.infommimdown[.]oss-cn-hongkong.aliyuncs.commmr[.]whoamis.infopoer[.]whoamis.inforc[.]dajuw.comrootkit[.]toolsshopingchina[.]netsteam[.]dajuw.comtest[.]mircrosoftscoulds.comtools[.]daji8.meupdate[.]adobe.wikiwin[.]googie.phwmgnews[.]daji8.mewps[.]daj8.mewpsup[.]daj8.mewww[.]adobe.namewww[.]whoamis.infoyabo[.]googie.ph
Don't get bitten by 'oRAT', secure your endpoints to stop the threat before it infests your environment.
Contact Jamf or your preferred representative to begin your trial of Jamf Protect today.
Subscribe to the Jamf Blog
Have market trends, Apple updates and Jamf news delivered directly to your inbox.
To learn more about how we collect, use, disclose, transfer, and store your information, please visit our Privacy Policy.
Tags: