New backdoor malware tries to gain control of Macs


Bitdefender Labs is reporting a new malware was found in the wild. Called Backdoor.MAC.Elanor, the software attempts to gain hidden access to macOS machines. The software was discovered on a software update site and called EasyDoc Converter.

• File manager (view, edit, rename, delete, upload, download, and archive files)
• Command execution (execute commands)
• Script execution (execute scripts in PHP, PERL, Python, Ruby, Java, C)
• Shell via bind/reverse shell connect (remotely execute root commands)
• Simple packet crafter (probe firewall rule-sets and find entry points into a targeted system or network)
• Connect and administer databases
• Process list/Task manager (access the list of processes and applications running on the system)
• Send emails with attached files

I recommend users checkout BlockBlock, which guards macOS's services directories. If software attempts to install itself within the OS, the user is alerted and asked whether the installation should be permitted. This adds a level of transparency on what's going on behind the scenes.