If you think Microsoft only focuses on its own Windows system, then you are looking down on it! The Microsoft 365 Defender Threat Intelligence team recently released a latest report, which conducts long-term tracking and observation of a macOS Trojan called “UpdateAgent” and records its entire variant development since September 2020.

Microsoft’s new report reveals that a Mac Trojan has grown in variants since September 2020
A new report from Microsoft details a sophisticated Trojan that has been developing variants since September 2020 to more effectively disrupt Mac users’ lives. The Trojan was named “UpdateAgent” by Microsoft, and the report outlines the Trojan’s capabilities, which include pretending to be safe and harmless software, and even worse, using the characteristics of the Mac itself for malicious purposes. If you thought your Mac was invincible at protecting you from only running trusted applications, UpdateAgent will shatter your illusion of invincibility. Even worse news is that once it compromises your device, it can completely wipe out its own footprints without being discovered.

Since its debut, UpdateAgent developers have regularly updated the Trojan over the past year to make it more sophisticated in functionality. The two latest variants have more refined behavior patterns than earlier versions, but they are signs that the malware is still in the development stage and that more variants with more functionality are likely. In the latest campaign, the malware installed Adload adware with both evasive and persistent features, but in theory UpdateAgent’s ability to access the device could be further exploited to obtain other, potentially more dangerous, malicious payloads, increasing the likelihood of multiple infections of the device.
▲UpdateAgent functional variant roadmap from discovery to October 2021
The Trojan may be distributed via drive-by downloads or advertising pop-ups that look very similar to legitimate software, such as video applications, support agents, etc. This bundling of Trojans with legitimate software increases the likelihood that users will be tricked into installing malicious software. Once installed, UpdateAgent begins collecting system information and then sends any stolen data to its command and control (C2) server.

▲UpdateAgent’s activities and attack chain
Interested readers can go to Microsoft’s security blog to get a more complete report. This is not the first time Microsoft has reminded Apple fans to pay attention to network security. Of course, it probably will not be the last time. Although it is still promoting its own Microsoft Defender, it is good to see Microsoft broadening its horizons.
Source: KOCPC Chinese