	{"id":5034,"date":"2012-07-10T17:18:36","date_gmt":"2012-07-11T00:18:36","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=5034"},"modified":"2016-02-12T10:28:30","modified_gmt":"2016-02-12T18:28:30","slug":"new-multi-platform-backdoor-discovered","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/","title":{"rendered":"New Multi-Platform Backdoor Discovered"},"content":{"rendered":"<p>Recently a compromised Columbian website was found that is being used to deliver a multi-platform backdoor. The infection is a multi-stage process, which is what allows it to deliver different files depending on what operating system a machine is running.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/java_select\/\" rel=\"attachment wp-att-5035\"><img loading=\"lazy\" class=\"size-full wp-image-5035 aligncenter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png\" alt=\"\" width=\"533\" height=\"500\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png 533w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select-150x140.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select-300x281.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select-100x93.png 100w\" sizes=\"(max-width: 533px) 100vw, 533px\" \/><\/a><\/p>\n<p>The initial piece of the puzzle is a signed Java applet on the compromised website, which does an operating system check. It then downloads additional components depending on whether the machine is running Windows, Linux or OS X. Once those components are downloaded, it will attempt to install a backdoor Trojan. The functionality of the backdoor Trojan is the same, regardless of which OS it\u2019s running on.<\/p>\n<p>There is one part of the OS X version that is particularly notable: It is a PPC binary only, so it will require Rosetta in order to run on an Intel machine. This is likely to severely limit prevalence of the OS X version.<\/p>\n<p>It\u2019s also interesting to note that the components of this threat are created with readily available hack-tools, namely <a href=\"https:\/\/www.trustedsec.com\/downloads\/social-engineer-toolkit\/\">TrustedSec Social Engineering Toolkit<\/a> and <a href=\"http:\/\/www.metasploit.com\/\">MetaSploit<\/a>. This is not something that was cleverly handcrafted, but something that was generated with tools made by other people. And given that the OS X component is not intended for current hardware, it\u2019s likely that the person who planted this threat was not especially technically savvy.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/virusbarrier\">Intego VirusBarrier X6<\/a> detects the initial Java applet in this infection chain since July 5th as OSX\/SET.gen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently a compromised Columbian website was found that is being used to deliver a multi-platform backdoor. The infection is a multi-stage process, which is what allows it to deliver different files depending on what operating system a machine is running.<\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[190,5],"tags":[30,86,167],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Recently a compromised Columbian website was found that is being used to deliver a multi-platform backdoor. The infection is a multi-stage process, which is what allows it to deliver different files depending on what operating system a machine is running.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Multi-Platform Backdoor Discovered - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Recently a compromised Columbian website was found that is being used to deliver a multi-platform backdoor. The infection is a multi-stage process, which is what allows it to deliver different files depending on what operating system a machine is running.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2012-07-11T00:18:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-02-12T18:28:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lysa Myers\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png\",\"width\":\"533\",\"height\":\"500\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/\",\"name\":\"New Multi-Platform Backdoor Discovered - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#primaryimage\"},\"datePublished\":\"2012-07-11T00:18:36+00:00\",\"dateModified\":\"2016-02-12T18:28:30+00:00\",\"description\":\"Recently a compromised Columbian website was found that is being used to deliver a multi-platform backdoor. The infection is a multi-stage process, which is what allows it to deliver different files depending on what operating system a machine is running.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Multi-Platform Backdoor Discovered\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\"},\"headline\":\"New Multi-Platform Backdoor Discovered\",\"datePublished\":\"2012-07-11T00:18:36+00:00\",\"dateModified\":\"2016-02-12T18:28:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#webpage\"},\"wordCount\":247,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png\",\"keywords\":[\"Backdoor\",\"Malware\",\"PPC\"],\"articleSection\":[\"Malware\",\"Security News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"caption\":\"Lysa Myers\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Recently a compromised Columbian website was found that is being used to deliver a multi-platform backdoor. The infection is a multi-stage process, which is what allows it to deliver different files depending on what operating system a machine is running.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/","og_locale":"en_US","og_type":"article","og_title":"New Multi-Platform Backdoor Discovered - The Mac Security Blog","og_description":"Recently a compromised Columbian website was found that is being used to deliver a multi-platform backdoor. The infection is a multi-stage process, which is what allows it to deliver different files depending on what operating system a machine is running.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/","og_site_name":"The Mac Security Blog","article_published_time":"2012-07-11T00:18:36+00:00","article_modified_time":"2016-02-12T18:28:30+00:00","og_image":[{"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lysa Myers","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png","width":"533","height":"500"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/","name":"New Multi-Platform Backdoor Discovered - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#primaryimage"},"datePublished":"2012-07-11T00:18:36+00:00","dateModified":"2016-02-12T18:28:30+00:00","description":"Recently a compromised Columbian website was found that is being used to deliver a multi-platform backdoor. The infection is a multi-stage process, which is what allows it to deliver different files depending on what operating system a machine is running.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"New Multi-Platform Backdoor Discovered"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a"},"headline":"New Multi-Platform Backdoor Discovered","datePublished":"2012-07-11T00:18:36+00:00","dateModified":"2016-02-12T18:28:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#webpage"},"wordCount":247,"commentCount":2,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/07\/Java_Select.png","keywords":["Backdoor","Malware","PPC"],"articleSection":["Malware","Security News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/new-multi-platform-backdoor-discovered\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","caption":"Lysa Myers"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/"}]}},"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-1jc","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/5034"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=5034"}],"version-history":[{"count":8,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/5034\/revisions"}],"predecessor-version":[{"id":50212,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/5034\/revisions\/50212"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=5034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=5034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=5034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}