mac os x malware: from myth to mainstream

29
Vicente Diaz, Senior Security Analyst, Global Research & Analysis Team, Kaspersky Lab Kaspersky Security for Mac Launch Event, Moscow, 14-16, May 2012 Mac OS X Malware: From Myth to Mainstream

Upload: imagazinepl

Post on 30-Nov-2014

1.421 views

Category:

Technology


0 download

DESCRIPTION

 

TRANSCRIPT

Page 1: Mac OS X Malware: From Myth to Mainstream

Vicente Diaz, Senior Security Analyst, Global Research & Analysis Team, Kaspersky Lab

Kaspersky Security for Mac Launch Event, Moscow, 14-16, May 2012

Mac OS X Malware: From Myth to Mainstream

Page 2: Mac OS X Malware: From Myth to Mainstream

Mac OS X: security from a user´s perspective

Page 3: Mac OS X Malware: From Myth to Mainstream

Wait a minute…

Page 4: Mac OS X Malware: From Myth to Mainstream

Recipe for an infection:

1.Vulnerability

2.Exploit

3.Attack vector

Or

4.Fooling the user

The cybercriminals’ checklist

Page 5: Mac OS X Malware: From Myth to Mainstream

Mac OS X vulnerabilities in the past…

Page 6: Mac OS X Malware: From Myth to Mainstream

And even more vulnerabilities now

2008 2009 2010 2011 2012*0

50

100

150

200

250

300

350

400

450

Advisories

Vulnerabilities

Source: Apple Security Updates: http://support.apple.com/kb/HT1222

Page 7: Mac OS X Malware: From Myth to Mainstream

Apple’s management of Mac OS X vulnerabilities

32 days

20 days

48 days

Page 8: Mac OS X Malware: From Myth to Mainstream

The cybercriminals’ checklist

Recipe for an infection:

1. Vulnerability

2. Exploit

3. Attack vector

Or

4.Fooling the user

Page 9: Mac OS X Malware: From Myth to Mainstream

Mac OS X’s pre-installed protection measures

ASLR Stack protection XProtect

2005

OSX 10.4 Tiger

No No Only warnings

2007

OSX 10.5 Leopard

Buggy - useless

Optional Only warnings

2009

OSX 10.6 Snow Leopard

Buggy - useless

OS compiled with protection

Enhanced

2011

OSX 10.7 Lion

Fully implemented

OS compiled with protection

Enhanced

Page 10: Mac OS X Malware: From Myth to Mainstream

Introducing … Xprotect (aka File Quarantine)

Live Demo

Page 11: Mac OS X Malware: From Myth to Mainstream

The future of Mac OS X protection

Page 12: Mac OS X Malware: From Myth to Mainstream

The cybercriminals’ checklist

Recipe for an infection:

1. Vulnerability

2. Exploit

3. Attack vector

Or

4. Fooling the user

Page 13: Mac OS X Malware: From Myth to Mainstream

Attack vectors

Compromised websites

Black Hat SEO

Targeted attacks

Page 14: Mac OS X Malware: From Myth to Mainstream

The cybercriminals’ checklist

Recipe for an infection:

1. Vulnerability

2. Exploit

3. Attack Vector

Or

4. Fooling the user

Page 15: Mac OS X Malware: From Myth to Mainstream

If what you say is true…show me the malware

Page 16: Mac OS X Malware: From Myth to Mainstream

Mac OS X malware over time

2008 2010

20112009

Scareware

DNSChanger

Remote control

FakeAV

Page 17: Mac OS X Malware: From Myth to Mainstream

Mac OS X’s malware evolution

Source: Kaspersky Lab

2003

.08

2005

.08

2005

.10

2005

.12

2006

.03

2006

.11

2007

.01

2008

.01

2008

.06

2008

.11

2009

.05

2009

.10

2009

.12

2010

.02

2010

.04

2010

.10

2010

.12

2011

.05

2011

.08

2011

.10

2011

.12

2012

.02

2012

.04

0

50

100

150

200

250

300

Page 18: Mac OS X Malware: From Myth to Mainstream

Case Study 1: Flashback

Page 19: Mac OS X Malware: From Myth to Mainstream
Page 20: Mac OS X Malware: From Myth to Mainstream

Flashback attack method

Page 21: Mac OS X Malware: From Myth to Mainstream

Flashback attack vector

Main infection vector: Hacked WordPress sites

Late February to early March: between 30,000 and 100,000 sites were hacked

Depending on OS and browser, victims are redirected to an exploit

85% of hacked sites were based in the U.S.

Traffic hired from partner program associated with the rr.nu gang

Page 22: Mac OS X Malware: From Myth to Mainstream

Geographical distribution of infected Mac OS X computers

Page 23: Mac OS X Malware: From Myth to Mainstream

Case Study 2: SabPub

Page 24: Mac OS X Malware: From Myth to Mainstream

Advanced Persistent Threat targeting MAC OS X users

Doc files from 2010, rearmed with new exploits

CVE-2009-0563 – targets Office

CVE-2012-0507 – targets Java

The “10th March Stamnet”

Installs backdoor on victim´s machine

APT is currently ACTIVE

Page 25: Mac OS X Malware: From Myth to Mainstream

What has changed?

Page 26: Mac OS X Malware: From Myth to Mainstream

Mac OS X’s growth in market share

Page 27: Mac OS X Malware: From Myth to Mainstream

Call to action: Apple’s security update process

• Allow Oracle to patch Mac OS X vulnerabilities in Java directly, rather than issuing your own security updates.

• Implement automatic security updates for user systems

• Respond faster to new security vulnerabilities to minimize window of exploitation

Page 28: Mac OS X Malware: From Myth to Mainstream

Conclusions & predictions for users

• The myth of Mac OS X being invulnerable to malware has been shattered

• Use AV software and proper security practices to protect yourself

• Mac OS X mass-malware attacks will increase. This will include drive-by downloads and Mac OS X-based botnets

• Expect cross-platform exploit kits with Mac OS X-specific exploits

• Apple is pushing for a more controlled ecosystem (GateKeeper) but this will be a cat-and-mouse game.

Page 29: Mac OS X Malware: From Myth to Mainstream

Thank You

Vicente Diaz, Senior Security Analyst, Global Research & Analysis Team, Kaspersky Lab

@trompi

Kaspersky Security for Mac Launch Event, Moscow, 14-16, May 2012