Silver Sparrow (malware)

From HandWiki
Short description: MacOS computer virus
Silver Sparrow
Common nameSilver Sparrow
Technical nameVersion 1: updater.pkg; Version 2: update.pkg
Typecomputer virus
Operating system(s) affectedMacOS
FilesizeVersion 1: 53.13 KB; Version 2: 72.08 KB

The Silver Sparrow computer virus is malware that runs on x86- and Apple M1-based Macintosh computers.[1][2] Engineers at the cyber security firm Red Canary have detected two versions of the malware in January and February 2021.[3]

Description

Two versions of the malware were reported. The first version (described as the "non-M1" version) is compiled for Intel x86-64. It was first detected in January 2021.[3] The second version contains code that runs natively on Apple's proprietary M1 processor, and was probably released in December 2020 and discovered in February 2021.[4][3] The virus connects to a server hosted on Amazon Web Services.[5] The software includes a self-destruct mechanism.[1]

As of 23 February 2021, information about how the malware is spread and what system may be compromised is sparse. It is uncertain whether Silver Sparrow is embedded inside malicious advertisements, pirated software, or bogus Adobe Flash Player updaters. Red Canary has theorized that systems could have been infected through malicious search engine results that might have directed them to download the code.[3] The ultimate object of the malware's release is also still unknown.[3]

Silver Sparrow is the second malware virus observed to include M1-native code.[6]

Impact

As of 23 February 2021, Internet security company Malwarebytes has discovered over 29,000 Macs worldwide running their anti-malware software to be infected with Silver Sparrow.[7] Silver Sparrow infected Macs have been found in 153 countries as of February 17, with higher concentrations reported in the US, UK, Canada, France, and Germany, according to data from Malwarebytes.[1] Over 39,000 Macs were affected in the beginning of March 2021.[8]

On 23 February 2021, a spokesperson of Apple Inc. stated that "there is no evidence to suggest the malware they identified has delivered a malicious payload to infected users." Apple also revoked the certificates of the developer accounts used to sign the packages, thereby preventing any additional Macs from becoming infected.[9]

References

  1. 1.0 1.1 1.2 Alexis Benveniste (21 February 2021). "Nearly 30,000 Macs reportedly infected with mysterious malware". https://www.cnn.com/2021/02/21/tech/mac-mysterious-malware/index.html. 
  2. Hollister, Sean (2021-02-21). "Sophisticated hackers snuck sleeper malware into nearly 30,000 Macs" (in en). https://www.theverge.com/2021/2/21/22294377/silver-sparrow-malware-macs-m1-intel-red-canary-wardle. 
  3. 3.0 3.1 3.2 3.3 3.4 "Silver Sparrow macOS malware with M1 compatibility". 2021-02-18. https://redcanary.com/blog/clipping-silver-sparrows-wings/. 
  4. "Mysterious malware found on 30,000 Macs" (in en). 2021-02-22. https://www.consumeraffairs.com/news/mysterious-malware-found-on-30000-macs-022221.html. 
  5. "Thousands infected with 'mystery' virus" (in en). 2021-02-22. https://www.news.com.au/technology/home-entertainment/computers/red-canary-warn-silver-sparrow-malware-infected-30000-m1-apple-mac-computers/news-story/0f7b8ee5e97f5a8ed71354e0daaa3473. 
  6. Goodin, Dan (2021-02-20). "New malware found on 30,000 Macs has security pros stumped" (in en-us). https://arstechnica.com/information-technology/2021/02/new-malware-found-on-30000-macs-has-security-pros-stumped/. 
  7. "Mysterious malware discovered on 30,000 new Macs" (in en). 2021-02-22. https://www.independent.co.uk/life-style/gadgets-and-tech/malware-new-macs-m1-b1805582.html. 
  8. "macOS Malware Silver Sparrow Affects About 40,000 Macs Running Both Intel and ARM Chips" (in en-US). 2021-03-04. https://www.cpomagazine.com/cyber-security/macos-malware-silver-sparrow-affects-about-40000-macs-running-both-intel-and-arm-chips/. 
  9. "Apple Takes Action Against Silver Sparrow Malware Discovered on 30K Infected Macs" (in en). https://www.pcmag.com/news/silver-sparrow-malware-discovered-on-30k-infected-macs.