New Tor-powered backdoor program targets Macs

The Eleanor malware permits attackers to execute instructions and scripts, steal and adjust files and take photos using the webcam The rogue application is referred to as EasyDoc Converter. As Soon As put in it displays a fake interface where Customers can supposedly drag and drop files for conversion, but which in fact would not do anything else.

In The background, the appliance executes a shell script that installs multiple malicious parts in a folder known as "/Customers/$PERSON/Library/.dropbox." The Dropbox Title is used to make the malware harder to identify and has nothing to do with the legit Dropbox file synchronization tool.

The Eleanor malware has three elements: an internet provider with a PHP software, a Tor hidden carrier that permits attackers to connect with the affected methods over the Tor anonymity Community and an agent that posts the Tor get admission to URLs for infected programs to the Pastebin web site.

The PHP application served by the online service is actually a backdoor that enables attackers to view, edit, rename, delete, upload, download and archive information on the system; to execute shell commands and scripts written in PHP, Perl, Python, Ruby, Java and C; to open a reverse shell to the attackers' server; to connect to MySQL, SQLite and different databases; to view the method checklist and to send emails with attachments. As Soon As put in it displays a fake interface where Customers can supposedly drag and drop files for conversion, but which in fact would not do anything else.</p> <p>In The background, the appliance executes a shell script that installs multiple malicious parts in a folder known as “/Customers/$PERSON/Library/.dropbox.” The Dropbox Title is used to make the malware harder to identify and has nothing to do with the legit Dropbox file synchronization tool.</p> <aside class="nativo-promo smartphone" id="" /> <p>The Eleanor malware has three elements: an internet provider with a PHP software, a Tor hidden carrier that permits attackers to connect with the affected methods over the Tor anonymity Community and an agent that posts the Tor get admission to URLs for infected programs to the Pastebin web site.</p> <p>The PHP application served by the online service is actually a backdoor that enables attackers to view, edit, rename, delete, upload, download and archive information on the system; to execute shell commands and scripts written in PHP, Perl, Python, Ruby, Java and C; to open a reverse shell to the attackers’ server; to connect to MySQL, SQLite and different databases; to view the method checklist and to send emails with attachments. Every Other component of this utility allows attackers to seize pictures and videos using the machine’s webcam.</p> <p>The Tor component connects the pc to the Tor Community and makes its rogue Web carrier available by means of a .onion URL. This Sort Of URL can best be accessed from within the Tor Community.</p> <p>The Pastebin agent takes the system’s .onion URL, encrypts it with an RSA public key and posts it on Pastebin where attackers can find it and use it.</p> <aside class="nativo-promo tablet desktop" id="" /> <p>The oldest Pastebin submit identified via the Bitdefender researchers as being created with the aid of the Eleanor backdoor is dated April 19. But The firm may Not establish the overall choice of infected machines, as a result of completely different Eleanor samples upload URLs to different Pastebin money owed they usually do not have the entire samples.</p> <p>The Excellent News is that the app isn’t digitally signed by way of an Apple-authorized certificates, so Users will see Safety warnings on the newest OS X model if they try to put in it. 