
Photo: cyberwarfaremag.wordpress.com
Kaspersky Lab researcher Costin Raiu is reporting that a new APT (Advanced Persistent Threat) using a Mac OS X backdoor is targeting ‘certain Uyghur Mac users’ [1]. Once installed on the victim’s computer, the trojan ‘calls home’ to a Command and Control server, the IP of which is located in China.
Raiu also points to some English errors in file comments and debug information which indicate they were written by someone whose native language is not English.
These sorts of phishing attacks are not new to Uyghur and Tibetan minority groups, both increasingly under attack in recent years. When I spoke to a representative from Tibet House here in Japan back in 2009, I was told that they receive as many as 10 or 15 attacks per day, usually from Beijing and Shanghai, and are advised by security experts to change their passwords frequently.
This past weekend Chinese state media reported that six Uyghur men had been arrested in an alleged plane hijacking attempt in the western province of Xinjiang, although rights groups claim that it was just a brawl over a seat dispute. Two men have reportedly died in custody, says the BBC citing state media.
It should be noted that those arrests took place on Friday, July 1, and the APT attacks were intercepted on June 27, according to Raiu.
[Via TUAW]
-
Raiu begins his report with a preamble stating that “the Dalai Lama is a well-known Mac user,” citing a photo from last year showing him sitting at a Mac. But regarding that photo, the Office of the Dalai Lama informed me last July that “His Holiness does not own or use a computer” and that “our office arranged the computer for [a] webcast interview.” ↩
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.






