MacSpy is advertised as the 'most sophisticated Mac spyware ever”, with the low starting price of free. While the idea of malware-as-a-service (MaaS) isn’t a new one with players such as Tox and Shark the game, it can be said that MacSpy is one of the first seen for the OS X platform.
In Need for Speed Underground 2, you'll challenge the rest of drivers as long as you go further in the competition through the streets. But that's not the only important point of NFS Underground 2, because NFS Underground 2 offers that tuning side to custom parts and the car itself. Welcome to the “Need for Speed Underground 2” for Mac game page. This page contains information + tools how to port this game so you can play it on your Mac just like a normal application. This game is already available in the Porting Kit. Porting Kit is the new application which “ports” the game to your Mac. Need for speed underground 2 free download - U.S. Robotics High-speed Modem Script, and many more programs.
Need for Speed Hot Pursuit launches you into a new open-world landscape behind the wheel of the world's fastest and most beautiful cars. From Criterion, the award-winning studio behind the Burnout series, Hot Pursuit will redefine racing games for a whole new generation.
The authors state that they created this malware due to Apple products gaining popularity in the recent years. They also state that during their tenure in the field that they have noticed a lack of 'sophisticated malware for Mac users' and they believe that 'people were in need of such programs on MacOS'. So they created MacSpy. The MacSpy authors claim to have the following features in the free version of their RAT:
If you are willing to pay an unknown amount of bitcoins for the advanced version, the malware authors advertise the following features:
MacSpy is not as polished as some of the malware-as-a-service providers out there, as there doesn’t seem to be any customer facing automated service of signing up for their service. In order to receive a copy of MacSpy we had to email the author our preferred username and password, in order for them to make us an account. After confirming our details they created an account for us, and delivered a zipped file and the following instructions:
Initial Analysis
After unzipping the archive we observed it contained the following files:
The archive contains four files:
![Need Need](/uploads/1/1/7/5/117506457/145332781.jpg)
- Mach-O 64-bit executable called 'updated'
- Mach-O 64-bit executable called 'webkitproxy'
- Mach-O 64-bit dynamically linked shared library called 'libevent-2.0.5.dylib'
- Config file
After examining webkitproxy and libevent-2.0.5.dylib, we noted they are signed by Tor, and thus we concluded that they are related to the function of Tor Onion routing. The contents of the config file further convince us of our suspicions are correct:
![Speed Speed](https://macgamesland.com/uploads/posts/2020-04/1587063416_screenshot-4-need-for-speed-porsche-unleashed.jpg)
Config Contents
The 'updated' file, on the other hand is not digitally signed, and it is currently completely undetected by various AV companies on VirusTotal.
Anti-Analysis
MacSpy has several countermeasures that hamper analysis efforts. To prevent debugging, it calls ptrace() with the PT_DENY_ATTACH option. This is a common anti-debugger check and will prevent debuggers from attaching to the process.
If you bypass the ptrace countermeasure, MacSpy has additional code that checks if it is running in a debugger.
The code above is very similar to the debugger checking code from this Stack Overflow post.
In addition to the anti-debugging countermeasures, MacSpy contains checks against the execution environment that can make it difficult to run in a virtual machine. In the code below, you can see that MacSpy checks that the number of physical CPUs is greater than 1, the number of logical cores is greater than 3, and the number of logical cores is twice the number of physical cores. MacSpy also checks that there is at least 4 GB of memory on the host. Since malware sandboxes often run with minimal resources, these checks can prevent proper execution in virtual environments.
Similar to MacRansom, MacSpy also compares the machine model to 'Mac' using the 'sysctl' command. MacSpy will kill all Terminal windows which can be annoying to analysts using command line tools to analyze the malware (OSX/Dok exhibits similar behavior by killing Terminal windows).
Persistence
In order to persist on the system the malware creates a launch entry in ~/Library/LaunchAgents/com.apple.webkit.plist. This ensures that the malware will run at start up to continue collecting information.
Behavior Analysis:
Upon execution, successfully passing the anti-analysis checks and setting persistence, the malware then copies itself and associated files from the original point of execution to '~/Library/.DS_Stores/' and deletes the original files in an attempt to stay hidden from the user. The malware then checks the functionality of its tor proxy by utilizing the curl command to contact the command and control server. After connecting to the CnC, the malware sends the data it had collected earlier, such as system information, by sending POST requests through the TOR proxy. This process repeats again for the various data the malware has collected. After exfiltration of the data, the malware deletes the temporary files containing the data it sent.
The following curl command used to exfiltrate data:
Contents of ~/Library/.DS_Stores/data/tmp/SystemInfo
User Web Portal
Need For Speed Underground 2 Mac Os X
In our initial email to the malware authors we sent a set of credentials that we wanted to use in their web portal. After logging into the MacSpy web portal you are greeted with a very bare bones directory listing containing a folder labeled the most recent date of the malware executing on a system in the YYYYMM format, followed by a folder in the DD format. Diving into that folder you're treated with a series of directories similar to that of the directory naming on the victim system. Inside these folders is the data that was collected from the victim the malware was executed on.
Detection
NIDS
The best way to detect MacSpy running on a Mac is to use a combination of Network IDS (NIDS) rules as it communicates. As it turns out, AlienVault provides this rule in its threat intelligence, which has already been updated with a rule called 'System Compromise, Malware RAT, MacSpy'. This feeds into the USM correlation engine to generate an alarm that will notify AlienVault customers that one of their systems is compromised.
Osquery
Yara
You can use the rule below in any system that supports Yara to detect this Mac-based malware.
Conclusion
People generally assume when they are using Macs they are relatively safe from malware. This has been a generally true statement, but this belief is becoming less and less true by the day, as evidenced by the increasing diversity in mac malware along with this name family. While this piece of Mac malware may not be the most stealthy program, it is feature rich and it goes to show that as OS X continues to grow in market share and we can expect malware authors to invest greater amounts of time in producing malware for this platform. Family tree maker for mac.
Mac Os X 10.13
If you want to find out more about this malware, here is a pulse we have in the AlienVault Open Threat Exchange (OTX):
Mac Os X Download
Appendix:
6c03e4a9bcb9afaedb7451a33c214ae4
c72de549a1e72cfff928e8d2591d7e97
cc07ab42070922b760b6bf9f894d0290
27056cabd185e939195d1aaa2aa1030f
f38977a34b1f6d8592fa17fafdb76c59
c72de549a1e72cfff928e8d2591d7e97
cc07ab42070922b760b6bf9f894d0290
27056cabd185e939195d1aaa2aa1030f
f38977a34b1f6d8592fa17fafdb76c59
Welcome to the “Need for Speed World” for Mac game page. This page contains information + tools how to port this game so you can play it on your Mac just like a normal application.
News update!!
Since almost 6 month EA games, discontinued the service of the game. Good mail program for mac. So the game won’t work anymore. Don’t be disappointed yet, because we still have a whole list of race games where you can choose of to play.
Since almost 6 month EA games, discontinued the service of the game. Good mail program for mac. So the game won’t work anymore. Don’t be disappointed yet, because we still have a whole list of race games where you can choose of to play.
Important things to know:
With latest wrapper its mountain Lion compatible and speed is great! However some issues remain:
1.Don’t touch the in-game Chat window, so don’t confirm language (see also video), or game will freeze after a race or exiting garage.
2. because of the chat/freeze thingy, confirm the language only when doing stuff in the garage (repair/boost/pimp/whatever) and restart the game because it will freeze anyway.
With latest wrapper its mountain Lion compatible and speed is great! However some issues remain:
1.Don’t touch the in-game Chat window, so don’t confirm language (see also video), or game will freeze after a race or exiting garage.
2. because of the chat/freeze thingy, confirm the language only when doing stuff in the garage (repair/boost/pimp/whatever) and restart the game because it will freeze anyway.
Game description:
World takes on the gameplay style of Most Wanted and Carbon, focusing on illegal street racing, tuning and police chases, and adds classic MMO elements to the mix such as special abilities. World also features the cities of Rockport and Palmont, the cities of Most Wanted and Carbon into its map design. The game currently features 94 licensed cars consisting of tuners, muscle cars and exotics.
World takes on the gameplay style of Most Wanted and Carbon, focusing on illegal street racing, tuning and police chases, and adds classic MMO elements to the mix such as special abilities. World also features the cities of Rockport and Palmont, the cities of Most Wanted and Carbon into its map design. The game currently features 94 licensed cars consisting of tuners, muscle cars and exotics.
Need For Speed Underground For Mac Os X 10.7
Additional Port Information:
Graphical Cards Tested: NVIDIA 9400M graphics card, NVIDIA GeForce 320M, AMD Radeon 6770M, INTEL 3000HD
Whats tested: Playing dozens of multiplayer games.
Does Multiplayer work?: Yes of course
OSX 10.7.5 and 10.8.2+ compatible?: yes
Known Issues: Don’t touch the in-game chat window or the game will freeze after races or when going to the garage
Whats not tested: Other Intel graphical cards
Wrapper version: 1.4
Icon: Paulthetall
Graphical Cards Tested: NVIDIA 9400M graphics card, NVIDIA GeForce 320M, AMD Radeon 6770M, INTEL 3000HD
Whats tested: Playing dozens of multiplayer games.
Does Multiplayer work?: Yes of course
OSX 10.7.5 and 10.8.2+ compatible?: yes
Known Issues: Don’t touch the in-game chat window or the game will freeze after races or when going to the garage
Whats not tested: Other Intel graphical cards
Wrapper version: 1.4
Icon: Paulthetall