{"id":92380,"date":"2020-10-22T15:32:30","date_gmt":"2020-10-22T22:32:30","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=92380"},"modified":"2020-10-22T15:32:30","modified_gmt":"2020-10-22T22:32:30","slug":"gravityrat-and-ipstorm-mac-malware-ported-from-windows","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/","title":{"rendered":"GravityRAT and IPStorm: Mac Malware, Ported from Windows"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-92382\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-600x350-1.png\" alt=\"GravityRAT malware logo art\" width=\"600\" height=\"350\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-600x350-1.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-600x350-1-300x175.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-600x350-1-150x88.png 150w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>Two malware threats that began on Windows\u2014GravityRAT and IPStorm\u2014are now available for Mac, Android, and Linux, too.<\/p>\n<p>So what does each malware family do? And what does this mean for the future of Mac malware? Read on for details.<\/p>\n<h3>GravityRAT remote access Trojan<\/h3>\n<p><img loading=\"lazy\" class=\"alignright wp-image-76096 size-full\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/03\/RAT.jpg\" alt=\"\" width=\"150\" height=\"150\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/03\/RAT.jpg 250w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/03\/RAT-150x150.jpg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/03\/RAT-32x32.jpg 32w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/03\/RAT-50x50.jpg 50w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/03\/RAT-64x64.jpg 64w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/03\/RAT-96x96.jpg 96w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/03\/RAT-128x128.jpg 128w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/>As the name implies, GravityRAT is a RAT: a remote access Trojan. A Windows version of GravityRAT was first discovered in 2017, but the campaign may have been active since 2015 or earlier. It targeted the armed forces of India.<\/p>\n<p>In 2018, GravityRAT was ported to Android. The malware maker used the source code of a legitimate Android mobile app called Travel Mate, and added malicious code and distributed it as &#8220;Travel Mate Pro.&#8221; The real Travel Mate is an app designed for people who travel in India.<\/p>\n<p>As reported by Securelist, GravityRAT malware has more recently been discovered masquerading as &#8220;Enigma,&#8221; a supposed secure file sharing app that claims to somehow protect against ransomware. First seen on Windows in September 2019, Enigma has also been ported to macOS.<\/p>\n<p>Other Windows and Mac variants of this Trojan have been distributed under the pretend product names &#8220;OrangeVault,&#8221; &#8220;StrongBox,&#8221; and\u00a0&#8220;TeraSpace.&#8221;<\/p>\n<h3>InterPlanetary Storm (IPStorm) botnet<\/h3>\n<p><img loading=\"lazy\" class=\"alignright size-thumbnail wp-image-72748\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/zombie-95x150.png\" alt=\"\" width=\"95\" height=\"150\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/zombie-95x150.png 95w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/zombie-190x300.png 190w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/zombie.png 320w\" sizes=\"(max-width: 95px) 100vw, 95px\" \/>The original Windows version of the InterPlanetary Storm (or IPStorm) malware was discovered in May 2019, and the first Linux version was found in June 2020.<\/p>\n<p>The latest variant targets devices running UNIX-like operating systems, including Linux, Android-based TV boxes, and Darwin\u2014the core of macOS.<\/p>\n<p>IPStorm spreads itself by conducting dictionary-based, brute-force password guessing attacks against SSH servers, and also by accessing open Android Debug Bridge (ADB) ports.<\/p>\n<p>While the ultimate intentions of the malware maker and botnet master is unknown, an estimated 13,500 devices are believed to be infected worldwide, across at least 84 different countries. Fifty-nine percent of infected devices are located in Hong Kong, South Korea, or Taiwan.<\/p>\n<h3>Why is more Windows malware coming to Mac?<\/h3>\n<p><img loading=\"lazy\" class=\"alignright wp-image-65395 size-thumbnail\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/04\/ApplesAndOranges-150x83.png\" alt=\"\" width=\"150\" height=\"83\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/04\/ApplesAndOranges-150x83.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/04\/ApplesAndOranges-300x167.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/04\/ApplesAndOranges.png 414w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/>This is not the first time Windows malware has been ported to Mac. A couple of memorable examples include the <a href=\"https:\/\/www.intego.com\/mac-security-blog\/snake-malware-ported-from-windows-to-mac\/\">Snake (aka Turla, Uroburos) malware, ported to Mac in 2017<\/a>, and the <a href=\"https:\/\/www.intego.com\/mac-security-blog\/spyware-xslcmd-malware-os-x\/\">XSLCmd malware, ported to Mac in 2014<\/a>.<\/p>\n<p>Nevertheless, it&#8217;s very interesting to see IPStorm and GravityRAT, two unrelated Windows malware families, making their way to Mac in such a short span of time.<\/p>\n<p>Is this a sign of things to come? Probably.<\/p>\n<p>The Mac operating system&#8217;s market share has more than doubled over the past seven years, according to <a href=\"https:\/\/www.statista.com\/statistics\/218089\/global-market-share-of-windows-7\/\" target=\"_blank\" rel=\"noopener noreferrer\">data from Statista<\/a>. Moreover, we&#8217;ve seen a <a href=\"https:\/\/www.intego.com\/mac-security-blog\/do-macs-need-antivirus-software\/#macmalwarehasincreased\">continuous increase in Mac malware<\/a> in recent years.<\/p>\n<p>We&#8217;ve even seen state-sponsored attackers that historically made Windows malware beginning to target macOS, as was the case with <a href=\"https:\/\/www.intego.com\/mac-security-blog\/operation-applejeus-and-osxlazarus-rise-of-a-mac-apt\/\">Lazarus malware as part of Operation AppleJeus in 2018<\/a>.<\/p>\n<p>Windows malware developers are likely noticing these trends, and for these and other reasons, Macs are becoming an ever more interesting target for cybercriminals.<\/p>\n<h3>How can one stay safe from IPStorm and GravityRAT?<\/h3>\n<p><img loading=\"lazy\" class=\"alignright size-medium wp-image-54214\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png\" alt=\"Intego X9 software boxes\" width=\"300\" height=\"150\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch.png 600w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>Intego VirusBarrier X9, included with <strong><a href=\"https:\/\/www.intego.com\/mac-protection-bundle\">Intego&#8217;s Mac Premium Bundle X9<\/a><\/strong>, can protect against, detect, and eliminate this malware.<\/p>\n<p><span style=\"font-size: small;\">Note: Customers running VirusBarrier X8, X7, or X6 on older versions of Mac OS X are also protected. It is best to upgrade to the latest version of VirusBarrier and macOS if possible to ensure your Mac gets all the latest security updates from Apple.<\/span><a name=\"iocs\"><\/a><\/p>\n<h3>Indicators of compromise (IoCs)<\/h3>\n<p>The following are some known SHA-256 hashes of malicious Mac files from these malware families.<\/p>\n<pre>GravityRAT:\r\n65EEF61BA8FC477771BCF37A1C6DF5EA636EF61AC29187D49EB13BA93C228E9A\r\n84D6372141166F87DE9C557E030B866AFFAEB726D66DA204B0A711B1167C83BE\r\nC29BEEDDFF66D825E9A813B5BBFECA513AEC5E4BA3CF1A45284EED9E2A9DFE0E\r\n\r\nIPStorm:\r\n4cd7c5ee322e55b1c1ae49f152629bfbdc2f395e9d8c57ce65dbb5d901f61ac1<\/pre>\n<h3>How can I learn more?<\/h3>\n<p>For more technical details about this malware, you can refer to <a href=\"https:\/\/securelist.com\/gravityrat-the-spy-returns\/99097\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Securelist&#8217;s write-up of GravityRAT<\/a> and <a href=\"https:\/\/blog.barracuda.com\/2020\/10\/01\/threat-spotlight-new-interplanetary-storm-variant-iot\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Barracuda&#8217;s write-up of IPStorm<\/a>.<\/p>\n<p><a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" class=\"alignright size-thumbnail wp-image-71818\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-150x150.png\" sizes=\"(max-width: 50px) 100vw, 50px\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-150x150.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-32x32.png 32w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-50x50.png 50w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-64x64.png 64w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-96x96.png 96w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-128x128.png 128w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png 300w\" alt=\"\" width=\"50\" height=\"50\" data-pagespeed-url-hash=\"2337344131\" \/><\/a>We discussed these and other new Mac malware (including <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-notarizes-new-mac-malware-again\/\">the latest notarized Mac malware<\/a>) on <a href=\"https:\/\/podcast.intego.com\/158\">episode 158<\/a> of the <a href=\"https:\/\/podcast.intego.com\/\"><strong>Intego Mac Podcast<\/strong><\/a>. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" rel=\"noopener\">subscribe<\/a> to make sure you don\u2019t miss any episodes. You\u2019ll also want to subscribe to our <strong>e-mail newsletter<\/strong> and keep an eye here on <strong>The Mac Security Blog<\/strong> for the latest Apple security and privacy news.<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/player.fireside.fm\/v2\/GegHgcrH+eQF1_uQc?base_slug=intego&amp;theme=dark\" width=\"740\" height=\"200\" frameborder=\"0\" scrolling=\"no\" data-mce-fragment=\"1\"><\/iframe><\/p>\n<p>You can also follow Intego on your favorite social and media channels: <a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>, <a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener noreferrer\">Instagram<\/a>, <a href=\"https:\/\/twitter.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>, and <a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener noreferrer\">YouTube<\/a> (click the \ud83d\udd14 to get notified about new videos).<\/p>\n<p><span style=\"font-size: x-small;\">GravityRAT logo header image based on: &#8220;<a href=\"https:\/\/commons.wikimedia.org\/wiki\/File:Newton%27s-apple.jpg\" target=\"_blank\" rel=\"noopener noreferrer\">Newton&#8217;s apple<\/a>&#8221; by Alexander Borek (<a href=\"https:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/deed.en\" target=\"_blank\" rel=\"noopener noreferrer\">CC BY-SA 4.0<\/a>) and &#8220;<a href=\"https:\/\/www.wannapik.com\/vectors\/333\" target=\"_blank\" rel=\"noopener noreferrer\">Vector Illustration of Long-Tailed Rodent Rats Sniff the Air<\/a>,&#8221; Designed by Wannapik (CC BY); both images modified.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two malware threats that began on Windows\u2014GravityRAT and IPStorm\u2014are now available for Mac, Android, and Linux, too.<\/p>\n","protected":false},"author":14,"featured_media":92383,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[190],"tags":[86,149],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Two malware threats that began on Windows\u2014GravityRAT and IPStorm\u2014are now available for Mac, Android, and Linux, too.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GravityRAT and IPStorm: Mac Malware, Ported from Windows - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Two malware threats that began on Windows\u2014GravityRAT and IPStorm\u2014are now available for Mac, Android, and Linux, too.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/JoshLong\" \/>\n<meta property=\"article:published_time\" content=\"2020-10-22T22:32:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@theJoshMeister\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joshua Long\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png\",\"width\":400,\"height\":260,\"caption\":\"GravityRAT malware logo art\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/\",\"name\":\"GravityRAT and IPStorm: Mac Malware, Ported from Windows - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#primaryimage\"},\"datePublished\":\"2020-10-22T22:32:30+00:00\",\"dateModified\":\"2020-10-22T22:32:30+00:00\",\"description\":\"Two malware threats that began on Windows\\u2014GravityRAT and IPStorm\\u2014are now available for Mac, Android, and Linux, too.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GravityRAT and IPStorm: Mac Malware, Ported from Windows\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\"},\"headline\":\"GravityRAT and IPStorm: Mac Malware, Ported from Windows\",\"datePublished\":\"2020-10-22T22:32:30+00:00\",\"dateModified\":\"2020-10-22T22:32:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#webpage\"},\"wordCount\":707,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png\",\"keywords\":[\"Malware\",\"Windows\"],\"articleSection\":[\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"caption\":\"Joshua Long\"},\"description\":\"Joshua Long (@theJoshMeister), formerly Intego\\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \\u2014\",\"sameAs\":[\"https:\/\/security.thejoshmeister.com\",\"https:\/\/www.facebook.com\/JoshLong\",\"https:\/\/www.instagram.com\/thejoshmeister\/\",\"https:\/\/www.linkedin.com\/in\/thejoshmeister\",\"https:\/\/www.pinterest.com\/thejoshmeister\/\",\"https:\/\/twitter.com\/theJoshMeister\",\"https:\/\/www.youtube.com\/@theJoshMeister\"],\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Two malware threats that began on Windows\u2014GravityRAT and IPStorm\u2014are now available for Mac, Android, and Linux, too.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/","og_locale":"en_US","og_type":"article","og_title":"GravityRAT and IPStorm: Mac Malware, Ported from Windows - The Mac Security Blog","og_description":"Two malware threats that began on Windows\u2014GravityRAT and IPStorm\u2014are now available for Mac, Android, and Linux, too.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/","og_site_name":"The Mac Security Blog","article_author":"https:\/\/www.facebook.com\/JoshLong","article_published_time":"2020-10-22T22:32:30+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_creator":"@theJoshMeister","twitter_misc":{"Written by":"Joshua Long","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png","width":400,"height":260,"caption":"GravityRAT malware logo art"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/","name":"GravityRAT and IPStorm: Mac Malware, Ported from Windows - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#primaryimage"},"datePublished":"2020-10-22T22:32:30+00:00","dateModified":"2020-10-22T22:32:30+00:00","description":"Two malware threats that began on Windows\u2014GravityRAT and IPStorm\u2014are now available for Mac, Android, and Linux, too.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"GravityRAT and IPStorm: Mac Malware, Ported from Windows"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1"},"headline":"GravityRAT and IPStorm: Mac Malware, Ported from Windows","datePublished":"2020-10-22T22:32:30+00:00","dateModified":"2020-10-22T22:32:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#webpage"},"wordCount":707,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png","keywords":["Malware","Windows"],"articleSection":["Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/gravityrat-and-ipstorm-mac-malware-ported-from-windows\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","caption":"Joshua Long"},"description":"Joshua Long (@theJoshMeister), formerly Intego\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \u2014","sameAs":["https:\/\/security.thejoshmeister.com","https:\/\/www.facebook.com\/JoshLong","https:\/\/www.instagram.com\/thejoshmeister\/","https:\/\/www.linkedin.com\/in\/thejoshmeister","https:\/\/www.pinterest.com\/thejoshmeister\/","https:\/\/twitter.com\/theJoshMeister","https:\/\/www.youtube.com\/@theJoshMeister"],"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2020\/10\/GravityRAT-malware-logo-art-400x260-1.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-o20","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/92380"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=92380"}],"version-history":[{"count":5,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/92380\/revisions"}],"predecessor-version":[{"id":92389,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/92380\/revisions\/92389"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/92383"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=92380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=92380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=92380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}