{"id":58052,"date":"2021-02-24T10:12:41","date_gmt":"2021-02-24T10:12:41","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=58052"},"modified":"2021-02-24T10:13:22","modified_gmt":"2021-02-24T10:13:22","slug":"malware-authors-already-taking-aim-at-apple-m1-macs","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2021\/02\/24\/malware-authors-already-taking-aim-at-apple-m1-macs\/","title":{"rendered":"Malware authors already taking aim at Apple M1 Macs"},"content":{"rendered":"\n<p><strong><em>The first instance of malicious code native to Apple Silicon M1 Macs emerged a month after the release of devices equipped with the company\u2019s in-house CPUs, writes Amer Owaida, Security Writer at ESET.<\/em><\/strong><\/p>\n\n\n\n<p>In November 2020, Apple debuted a series of Mac computers sporting its new Apple Silicon M1 chips to great acclaim. The release of the new hardware also grabbed the attention of enterprising cybercriminals, who prepared a \u2018little\u2019 debut of their own \u2013 malware that can run specifically on devices fitted with the new Apple chipsets.<\/p>\n\n\n\n<p>Apple\u2019s new M1 processors use ARM-based architecture, a departure from the previous generation of Intel x86 processors that its computers previously came with. This has necessitated for applications developed for Macs to be either translated through Apple\u2019s Rosetta 2 engine or coded anew to work natively on the new chips.<\/p>\n\n\n\n<p>In the meantime, threat actors have been busy in their own way Mac security researcher Patrick Wardle has disclosed details about malicious code that targets specifically computers running on Apple Silicon. Combing through VirusTotal and using specific search modifiers, Wardle was able to identify a macOS program that was written in native M1 code and was identified as malicious. The application, dubbed GoSearch22, was found to be a variant of the Pirrit adware family, a common threat targeting Mac users.<\/p>\n\n\n\n<p>Applications such as GoSearch22 display unwanted coupons, banners and pop-up ads that promote questionable webpages; however, they have also been observed to collect browsing data or other potentially sensitive information.<\/p>\n\n\n\n<p>The new version seems to install itself as a malicious Safari extension and persist as a launch agent. It is worth noting that the malware strain was submitted into VirusTotal at the end of December 2020, a mere month after the launch of the new Mac computers.<\/p>\n\n\n\n<p>\u201cRather awesomely, if we analyse details of the VirusTotal submission, it turns out this sample was submitted (by a user) directly through one of Objective-See\u2019s tools (likely KnockKnock) \u2026after the tool flagged the malicious code, due to its persistence mechanism,\u201d Wardle said. This means that the malware has been detected in the wild and macOS users might have been infected.<\/p>\n\n\n\n<p>\u201cToday we confirmed that malicious adversaries are indeed crafting multi-architecture applications so that their code will natively run on M1 systems. The malicious GoSearch22 application may be the first example of such natively M1 compatible code,\u201d he said.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The first instance of malicious code native to Apple Silicon M1 Macs emerged a month after the release of devices equipped with the company\u2019s in-house CPUs, writes Amer Owaida, Security Writer at ESET. In November 2020, Apple debuted a series of Mac computers sporting its new Apple Silicon M1 chips to great acclaim. The release [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":58059,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,517,36,13],"tags":[12972,12971,12970],"class_list":["post-58052","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-hardware","category-intelligent-technology","category-top-stories","tag-apple-m1-macs","tag-apple-silicon-m1-chips","tag-arm-based-architecture"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/58052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=58052"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/58052\/revisions"}],"predecessor-version":[{"id":58062,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/58052\/revisions\/58062"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/58059"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=58052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=58052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=58052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}