Digita Security

Cybersecurity solutions for the

  • modern
  • mobile
  • independent
  • innovative
  • enterprising

macOS workforce

10.8.2013 ( Version 2043 )

PrxlA

Also Known As: Icefog

OSX/PrxlA is an OS X Remote Access Trojan (RAT)/Backdoor that is installed via injected legitimate applications (e.g. Img2icns, CleanMyMac, AppDelete). The applications function as expected while the malware silently installs and persists itself in the background. It was used in targeted espionage attacks in Asia and was found to be active since 2011 [1].

References:
  1. http://www.thesafemac.com/new-mac-malware-discovered-icefog/

Sample Hashes (VT links):
edff0cd0111ee1e3a85dbd0961485be1499bdb66
429ed6bced9bb18b95e7a5b5de9a7b023a2a7d2c
f1a32e53439d3adc967a3b47f9071de6c10fce4e