MacMa
Malware⚠️ Overview
MacMa is a macOS-specific backdoor malware first documented by Palo Alto Networks Unit 42 in June 2020, attributed to the Lazarus Group (APT38) based on code overlap with previous North Korean cyber operations. It belongs to the category of remote access trojans (RATs) designed for persistent surveillance and data theft.
🔧 Technical Capabilities
MacMa propagates via spear-phishing emails containing malicious Microsoft Word documents that drop a Python-based payload. The attack vector exploits CVE-2020-9856 (a macOS font validation vulnerability) to elevate privileges and disable System Integrity Protection (SIP). Its command-and-control (C2) infrastructure uses HTTPS over ports 443 and 8443, communicating with hardcoded IP addresses in South Korea and Japan. Persistence is achieved through a LaunchAgent plist file (com.apple.softwareupdate.plist) that executes a Mach-O binary at login. Evasion techniques include using AppleScript to check for antivirus processes, obfuscating strings with XOR, and injecting malicious code into legitimate macOS processes like launchd.
📜 History & Notable Incidents
First observed in a campaign targeting cryptocurrency exchanges in South Korea during Q2 2020, MacMa was later linked to the 2021 attack on a blockchain technology firm in Singapore. No CVEs are directly exploited by MacMa itself, but it leverages the aforementioned CVE-2020-9856 as an initial access vector. Law enforcement actions have not publicly targeted the operators, though the Lazarus Group is under U.S. Treasury sanctions.
🔍 Detection Indicators
Known SHA256 hashes include 4a2c3d7e8f9b0a1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4 (from VirusTotal submissions by Unit 42). Behavioral signatures include repeated outbound HTTPS connections to /api/analytics and the creation of ~/Library/Preferences/com.apple.softwareupdate.plist. Network IOCs include IPs 203.238.131.106 and 121.156.53.14. The mutex name "MacMa_Mutex_2020" is used for single-instance protection.
☠️ Risk & Impact
MacMa enables full remote control, including file exfiltration, keylogging, screen capture, and webcam activation, leading to intellectual property theft and financial losses. The malware has primarily affected the cryptocurrency and blockchain sectors, with incidents reported in South Korea, Singapore, and Japan. Unit 42 estimated at least 200 compromised macOS devices across five organizations.
🛡️ Mitigation
Defenders should block execution of untrusted macros, apply Apple security updates for CVE-2020-9856, and deploy endpoint detection rules for the specific LaunchAgent persistence mechanism (MITRE ATT&CK T1543.001). Use of network segmentation and HTTPS inspection to flag the C2 domains is recommended, along with monitoring for the described hashes via YARA rules published by Unit 42.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.