[Issue] Multi APT attacks for both Mac and Windows

1. Information

INCA Internet response team detected multi APT attack for both Mac OS of Apple and Windows OS of Microsoft. Most of reported APT attacks were for Windows so far, however; we got APT attacks for Mac. It means that attackers reflect the rapid growth of Mac user and try to generate malicious file for Mac user. Therefore, Mac users need to be careful from malicious files.
Especially, we need to careful on attachment of e-mail.

2. Malicious file attacking procedure and technique

It attacked with malicious email which contains Uyghur People related contents on Jun, 2012.

Recipient used yahoo Canada's mail service, but he uses Uyghur language on universal web site and uses his name as Uyghurmen.

E-mails are written on 2 types, their attachment name was "matiriyal.zip" but one for Mac and another for Windows malicious file.

Following figure is malicious file for Mac OS.

Following figure is malicious file for Windows.

Each attachment contains same JPG file which is as following.

She is Rebiya Kadeer,a Uyghur human rights activist with origins in Xinjiang, China. Kadeer is the symbolic leader of Uighur self-determination movement in her capacity as President of the World Uyghur Congress, a group that advocates for greater autonomy for Uyghurs in China and fights against what they consider to be oppressive policies of the Chinese government.

Malicious file for Mac is located on "\matiriyal.app\Contents\MacOS\iCnat" and works as Backdoor. Besides it contains some typos including "Recieve", "os verison", "memery".

This malicious file tries to access certain C&C server on China and can perform various additional attacks.

"matiriyal.exe", malicious file for Windows is disguised its icon as MS Word file and compressed by RAR SFX. It contains "1.exe".

"1.exe" creates "kbdmgr.exe" on Temp folder and makes start program folder as hidden. It creates "kbdmgr.lnk" and makes malicious file run on boot.

Both malicious files are coded for similar works and malicious file for Windows contains certain string "DDoS".

3. Summary

We have to notice that malicious files for Mac are spreading in these days. To use PC safely from security threats of these malicious attachments, we recommend you download latest security updates and obey following "Security management tips" for general users.

Security management tips

1. Maintain the latest security update on OS and applications
2. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function
3. Do not see and download attached file from suspicious e-mail.
4. Keep caution to link from instant messenger and SNS.

INCA Internet (Security Response Center / Emergency Response Team) runs responding system against various security threats.
nProtect Anti-Virus/Spyware v3.0 diagnoses and treats various variant files.

Free installation link of nProtect AVS : http://avs.nprotect.com/


  1. Analytical essay writing is not an easy task, especially for unexperienced students. Here's a good guide on how to write an analytical essay just for you, my friends.

  2. How to prevent these malicious files?

  3. افضل شركة شراء اثاث مستعمل بالرياض  http://tiny.cc/klph5y حيث نقدم خدماتنا لأركان المدينة بالكامل ونغطيها بدون اي مشاكل كما اننا نقدم جميع خدمات التنظيف والتي نتميز فيها عن منافسينا من الشركات الاخري المتعددة في نفس المجال حيث نعتمد علي ارخص الاسعار التي نقدمها إلي العملاء في شركتنا لضمان الحصول علي ثقتكم الغالية والتي اهم ما يشغلنا… اقرأ المزيد

    المصدر: شركة شراء اثاث مستعمل بالرياض

    افضل شركة تنظيف مسابح بالرياض  http://tiny.cc/8rph5y من الطبيعي أن تجد المنازل قد اتسخت أو مُلئت بالغبار و الأتربة مع مرور الوقت خاصة مع تغيرات الفصول .. مما يزيد نسبة الإصابة بالأمراض لذا فإن عملية التنظيف بالنسبة للمنزل بما في ذلك الجدران و السلالم و المفروشات.
    لاشك أن الأطفال يفضلون كثيرا اللعب في المسابح خاصة في الأوقات شديدة الحرارة في فصل الصيف.
    لكن ذلك يعقبه اتساخ في أرضية المسبح أو في مياهه وتزداد هذه المشكلة تعقيدا حينما يكون حجم المسبح كبيرا الأمر الذي يجعل المنزل أو الفيلا تبدوا بمظهر خارجي أقل جمالا ورونقا .
    تضمن الشركة تقديم خدمات التنظيف الشاملة للمسبح وبمعدات و أدوات صيانة على أعلى مستوى من الجودة والنقاوة
    إن جميع أشكال المسابح تفتقر إلى عزل وهذا لقيام مؤسسة عزل المسابح والحمامات بالرياض بحفظ المسابح وإطالة عمرها كما أنها تمنع التسربات التى قد تتم بأحجام هائلة أو يتم إهدارها , كما أنه مع القيام بعملية مؤسسة عزل المسابح والحمامات بالرياض يحاول أن المحافظة على المواد التى تستخدم لتنظيف وتعقيم المسابح والتى يتم وضعها لتنقية المسابح من مختلَف الجراثيم أو البكتيريا والتى قد كان سببا الضرر القوي للإنسان والذى يكون له إحتكاك مباشر مع المسابح وغيره .
    الأمر الذي يسبب له الأمراض التى تتغاير شدتها وخطورتها ولذا الداعِي يلزم الإهتمام بقيام بعملية شركة عزل مسابح بالرياض وجعلها وجوب قسوة , والحرص على القيام بها قبل إستعمال المسبح , وهذا لتجنب إنتشار الميكروبات والجراثيم و البكتيريا والتى قد كان سببا الأمراض والحساسية لأشخاص الشخص والمجتمع والعائلة خاصة الأطفال وكبار العمر .

    بما في ذلك من شفط وتنظيف و تعقيم و أيضا علاج حالات التسرب التي قد تحدث أحيانا بعد تصميم المسبح
    تعد عملية ضرورية و يجب أن تتم من حين إلى آخر و بصفة دورية.
    تختص شركتنا بكافة أعمال التنظيف المنزلية ,والتي قد تتطلب مجهودا بدنيا شاقا قد يعجز أفراد الأسرة عن إنجازه وبشكل احترافي بما في ذلك تنظيف الجدران و الرخام و المفروشات و المسابح و حتى الحديقة مع إزالة الروائح الكريهة و رش المبيدات الحشرية .… اقرأ المزيد

    المصدر: شركة تنظيف مسابح بالرياض

  4. Thanks for the info. I don't have any issues. Good job.

  5. Resumeyard service offers a good deal to anyone who seeks help in preparing for an interview. They will create your resume; they also have an option to coach you for your interview. And you also have an option if you want to talk to them over the phone or you want it in-person. This company will help you put more of yourself in your resume.

  6. This is really an interesting blog,keep sharing more.
    While using any application if there is any issue that occurs like hacking and the application is processing slow then contact Mcafee activate to get the instant solution.

  7. Our Pay for non plagiarized research papers services makes your college life bearable and also receive the pay for term papers fulfilling by enabling you to pass your exams and also in other research and essay writing tasks.

  8. This is a great article, with lots of information in it, These types of articles interest users in your site. Please continue to share more interesting articles!
    Quickbooks support helps you with everything regarding QuickBooks software. If you are stuck in some general issues related to QuickBooks like installation error or payroll issues then we are here to help you anytime you want.

  9. These issues are not new but yes we can solve it no. Through writing platforms we can rephrase a thesis easily and in simple words too so what we have to do is focus.

  10. All scattered objects:
    Put in the lounge room a box for the collection of scattered objects, put on the shelves small boxes for keys, coins or pens, and another box for sheets or pillows that may be needed by a family member at the time of this box is possible to do workmanship in your home and put the colors on it and help achieve something Decoration Because the cleaning company councils in Riyadh Basma Riyadh knows very well that the councils of the most important places that exist in the house.

    شركة تسليك مجاري

    شركة جلي بلاط

    شركة تنظيف بيارات

    شركة عزل خزانات

    شركة كشف تسربات المياه

    شركة مكافحة حشرات

    شركة رش مبيدات

    شركة نقل عفش بالرياض

    شركة تخزين عفش بالرياض

  11. Research Papers Writing Services should strive to ensure that all essays meets the pukka standards of the examining bodies. Consider hiring quality but also Qualified Research Paper Writers which are advantageous in terms of ensuring you get only top-quality grades on your Online Research Paper Writing Service.

  12. yes these kind of attack happened nowadays. either you use mac or os.
    Microsoft launches sone new updates for windows 10. windows spotlight quiz is one of them.


  13. I like your article very much, thanks for sharing the good information we have read.
    hotmail login email
    gmail sign up

  14. Keep good security programs and software on your system to avoid these malicious activities to take place.professional assignment help online

  15. free robux generator is a one solution of all kinds of problems as it can easily get the free robux currency generated and is very much capable to unlock various gaming accessories and characters.
    To get the access to the website you will found it easy to generate the currency generated and as a result you will unlock various gaming characters and accessories and made the game a new one.

  16. you can generate Free vbucks by using vbucks generator tool. these vbucks are using to unlock your favorite characters. vbucks are not transfer from one account to another.


  17. الرائد افضل شركة تنظيف و غسيل خزانات بالمدينة المنورة تنظيف خزانات بالمدينة المنورة وتقوم اياب تقيمها بالاشعه الفوق البنفسجية

    تنظيف خزانات

  18. To get access to my ex's Instagram account, I used mspy.com app - it's simple to work with and it really let me see all the photos.

  19. Nice sharing, Thanks for sharing this type of posts, How many peoples like this post? Please tell me, also Good News for you, SALES ARE BEGIN! get ready for abaya collection in karachi

  20. Wales publications are well-known publishing solution providers in various disciplines in the UK, Wales Publications serving to scientific organizations worldwide. Contact us for further information and know our best services and deals to achieve your goal.The fast submission process includes rapid publication research in UK that includes unique rapid process, inhouse peer review and 100% acceptance guarantee.