Digita Security

Cybersecurity solutions for the

  • modern
  • mobile
  • independent
  • innovative
  • enterprising

macOS workforce

7.31.2017 ( Version 2093 )

XProtect_OSX_Leverage_A

Also Known As: OSX/FlashyComposer

OSX/Leverage is a malware macOS backdoor with command and control capabilities. It poses as a legitimate software installer (e.g. Adobe Flash) [1]. It was originally discovered in 2013 and has resurfaced in 2017 with ties to the Syrian Electronic Army [2].

References:
  1. https://www.intego.com/mac-security-blog/apple-updates-xprotect-to-block-new-leverage-malware-variant/
  2. http://www.thesafemac.com/tag/leverage/

Sample Hashes (VT links):
58509ec67ce9a271bf4a1ec3cad3a37bb666c1df4cc90f16db7038982b57dcf1