Hackers manage botnet with 17,000 Macs via Reddit

Spread the love

With a backdoor, hackers would be in control of approximately 17,000 Macs. According to the security company that discovered the botnet, the devices will receive instructions from the administrators via comments on the popular site Reddit.

The backdoor is called Mac.BackDoor.iWorm and was discovered by the Russian antivirus company Dr. Web that published about it on his blog. According to the company, more than 17,000 Macs worldwide have been infected with the malware. It is not yet clear how the worm spreads. Most infected computers are located in the United States.

Interestingly enough, the botnet administrators seem to communicate via Reddit. The /minecraftserverlists subchannel contains ip addresses of botnet servers, Macs infected with Mac.BackDoor.iWorm use Reddit’s search function to find the list. The required search query to find the list consists of eight digit hexadecimal values. These are obtained from the first eight digits of the md5 hash of the current date. As a result, the posts are not easy to find for ordinary users.

Infected devices attempt to connect to any server. Once connected, the botnet administrators can issue commands to the infected Mac, although it doesn’t appear that the botnet is actually being used at the moment. The administrators are probably trying to grow their network first.

You might also like