TF-MAL-osx.mughthesec
📛 Threat Title
Malware family: Mughthesec
Description
ThreatFox malware family `osx.mughthesec`. Printable name: Mughthesec.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.mughthesec
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.mughthesec
IOC database
- Type
- domain
- Value
osx.mughthesec- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.mughthesec
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.mughthesec
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:github.com
The malware will create a LaunchAgent "~/Library/LaunchAgents/com. Mughthesec .plist" in order to persist on the infected system. Mughthesec pretends to be a FlashPlayer installer.
-
web:macos.checkpoint.com
The malware will create a LaunchAgent "~/Library/LaunchAgents/com. Mughthesec .plist" in order to persist on the infected system. Mughthesec pretends to be a FlashPlayer installer.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Mughthesec malware family including references, samples and yara signatures.
-
web:malwaretips.com
Removal Instructions for Mughthesec (PUA) This malware removal guide may appear overwhelming due to the number of steps and numerous programs that are being used.
-
web:securityaffairs.com
The Mac Malware has been improved across the months, new features were implemented such as an MAC-address-based anti-VM detection system and components of Mughthesec are signed with a legitimate Apple developer certificate allowing it to bypass the Gatekeeper protection that normally prevents the installation of unsigned applications.
-
web:thecloudconsultancy.co
The malware has been dubbed Mughthesec , after the name of the app and the launch agent it installs on the target machine. The sample analyzed by security researcher Patrick Wardle was not detected by a Mac AV solution, and it was lifted directly from an infected MacBook, after being spotted by a user.
-
web:threatpost.com
Mughthesec , a variant of the OperatorMac adware, has been turning hijacked Macs into revenue-generating machines for the authors.
-
web:www.bleepingcomputer.com
This new adware's name is Mughthesec , and according to Thomas Reed, an expert in Mac malware at Malwarebytes, it's a new and improved version of the older OperatorMac family that's been haunting ...
-
web:www.cyberdefensemagazine.com
The Mac Malware has been improved across the months, new features were implemented such as an MAC-address-based anti-VM detection system and components of Mughthesec are signed with a legitimate Apple developer certificate allowing it to bypass the Gatekeeper protection that normally prevents the installation of unsigned applications.
-
web:www.mdpi.com
Our symmetry investigation in artificial intelligence and cybersecurity analytics will enhance malware detection, analysis, and mitigation abilities to provide resilient cyber systems against cyber threats.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.