New OS X Malware Spotted in the Wild Hints at Hacking Team's Return

Advertisement
By Manish Singh | Updated: 1 March 2016 16:26 IST

More than six months after the infamous surveillance firm Hacking Team disappeared in the wake of a massive breach on its own network, it seems the Italian software company is prepping a return to the game.

Security researchers have found new OS X malware in the wild that they believe has been developed by Hacking Team. The malware, researchers note, installs a copy of the software firm's Remote Code Systems compromise platform, leading them to believe that the infamous, controversial Italian firm is back.

Advertisement

The malware in question installs different programs on a computer. "The dropper is using more or less the same techniques as older Hacking Team RCS samples, and its code is more or less the same," wrote security researcher Pedro Vilaca.

The Hacking Team suffered a massive breach on its network last July. The hack saw over 400GB of data including sensitive information such as firm's relationship with governments, emails, source code, and exploits published online. The group has been mysteriously quiet since. "Either this is an old sample or HackingTeam are still using the same code base as before the hack," Vilaca wrote.

Advertisement

The sample was uploaded on Google-owned VirusTotal last month, and at the time, no popular antivirus program was able to detect it. At the time of writing, 15 antivirus programs including AVG, Eset-Nod 32, F-Secure, BitDefender, and TrendMicro were able to detect it.

Patrick Wardle of Synack security firm believes that the installer was last updated in October or November last year. He added that the sample of malware utilises most of the same code as old Hacking Team malware.

Advertisement

"I just found some unique code in this dropper. This code checks for newer OS X versions and does not exist in the leaked source code," Vilaca wrote. "Either someone is maintaining and updating HackingTeam code (why the hell would someone do that!?!?!) or this is indeed a legit sample compiled by HackingTeam themselves. Reusage and repurpose of malware source code happens (Zeus for example) but my gut feeling and indicators seem to not point in that direction."

Many questions remain unanswered for now. It is not clear how this malware gets installed on a system. Wardle, however, has found out a way to check if your Mac is infected with it. He urges users to check for a file "Bs-V7qIU.cYL" in a folder called "~/Library/Preferences/8pHbqThW/ directory."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Best Phones for Video Recording in India: iPhone 17 Pro Max, Galaxy S26 Ultra, and More
  2. Best Compact Smartphones in India: iPhone 17, Google Pixel 11 and More
  3. Here are the Best Phones for Portrait Photography in India in 2026
  1. Japan Digital Agency Reports Potential Leak of 246,000 Records After Cyberattack
  2. Samsung Galaxy SmartTag 3 Design, Colourways and Price Leaked Online
  3. Denmark Central Bank Flags Risks as Stablecoin Market Expands
  4. Google Makes It Easier to Switch Password Managers on Android: How to Transfer Passwords and Passkeys
  5. Instagram Lets Users Add Tagged Posts to Their Main Profile Grid
  6. BGMI 4.6 Update Set to Arrive on September 16 With Supernatural Midnight Hunters Theme Mode
  7. India Adopts Digital Rupee for Bond Transaction Settlements
  8. iQOO 16 Design, Colourway Revealed as Firm Confirms Major Camera Upgrade
  9. AMD Ryzen 7500 and Ryzen 5 5500F Desktop Processors Launched: Specifications, Features
  10. Snapdragon 8 Elite Extreme Gen 6 Outperforms MediaTek’s Upcoming Flagship Smartphone Chipset
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.