JokerSpy | Unknown Adversary Targeting Organizations with Multi-Stage macOS Malware

2023-06-28 Sentinel One

https://www.sentinelone.com/blog/jokerspy-unknown-adversary-targeting-organizations-with-multi-stage-macos-malware/

Thumbnail for JokerSpy | Unknown Adversary Targeting Organizations with Multi-Stage macOS Malware

SentinelOne reviewed JokerSpy activity involving macOS-focused spyware, cross-platform Python backdoors, and a suspected Java-based QRLog infection vector tied to a trojanized QR code generator. QRLog wrote and executed payloads after contacting hxxps://www.git-hub.me/view.php, while shared.dat used matching GITHUB_REQ and GITHUB_RES strings and could stage AppleAccount payloads on macOS. The sh.py backdoor used ~/Public/Safari/sar.dat for configuration, could beacon as often as every five seconds, and supported surveillance, command execution, data exfiltration, and file deletion; Elastic observed app.influmarket[.]org as C2 in a Japanese cryptocurrency exchange intrusion. The macOS xcc component imitated XProtect naming, checked user activity and privacy permissions, and was observed alongside SwiftBelt deployment, indicating multi-language tooling across Java, Python, and Swift for financially relevant targets.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.git-hub.me/view.php 2023-06-16 2023-11-14
HASH 89706d1258b6f1c165ff8d1d6d13346… 2023-06-28 2023-06-28
HASH 2234c9fc3c3d340f0367c49c6599379… 2023-06-28 2023-06-28
HASH 9860c28299d58e71540c64e56c709aa… 2023-06-28 2023-06-28
HASH 89706d1258b6f1c165ff8d1d6d13346… 2023-06-28 2023-06-28
HASH 1f99081affd7bef83d44e0072eb860d… 2023-06-28 2023-06-28
HASH c304aef96a783a39aedf1af30de5d5f… 2023-06-28 2023-06-28
HASH 21ffda8a6a05a007ef92088f99ab544… 2023-06-28 2023-06-28
HASH 55554944f74096a836b73310bd55d97… 2023-06-21 2023-06-28
DOMAIN app.influmarket.org 2023-06-21 2023-06-28
IPv4 45.76.238.53 2023-06-21 2023-06-28
HASH c7d6ede0f6ac9f060ae53bb1db40a4f… 2023-06-16 2023-06-28
HASH 937a9811b3e5482eb8f96832454723d… 2023-06-16 2023-06-28
HASH bd8626420ecfd1ab5f4576d83be35ed… 2023-06-16 2023-06-28
HASH 1ed2c5ee95ab77f8e1c1f5e2bd24658… 2023-06-16 2023-06-28
HASH 370a0bb4177eeebb2a75651a8addb04… 2023-06-16 2023-06-28
HASH 76b790eb3bed4a625250b961a5dda86… 2023-06-16 2023-06-28

Related Reports

« Back