New macOS Malware Targets Crypto-Currency Users

SecurityWeek | July 03, 2018

New macOS Malware Targets Crypto-Currency Users
A new piece of macOS malware has been observed being distributed via crypto-currency related Slack or Discord chat groups, security researchers warn. First detailed late last month, the malware is being distributed by malicious actors who impersonate admins or key people. The actors share small snippets of code with the members of said chat groups, and attempt to convince them into running the code in a terminal. Upon execution of the code, a malicious binary is downloaded and executed onto the victim’s machine. Although the social engineering trick isn’t as sophisticated, some users apparently fall for it. The downloaded payload is rather large, at 34MB. As of Friday, the malware wasn’t being detected by any of the 60 anti-virus engines in VirusTotal, Remco Verhoef, ISC Handler and Founder of DutchSec, explains. The malicious binary is not signed and Gatekeeper would normally flag and block it, but it appears that Apple’s protection measure does not work for files that are executed directly via terminal commands. The reason the binary is so large is that the author apparently packed in it libraries such as OpenSSL and V8, Objective-See’s Patrick Wardle, who named the malware OSX.Dummy, points out. When executed on the target machine, the malware first sets the script to be owned as root. When the threat executes sudo to change the file’s permissions, the user is prompted to enter their password in the terminal, and the malware steals it and saves it to /tmp/dumpdummy. Next, OSX.Dummy sets the script to be executable via chmod +x, moves the script to a new directory, dumps a plist file to /tmp/com.startup.plist and then moves it to the LaunchDaemons directory, sets the owner of the file to root, and then launches the plist launch daemon, for persistency.

Spotlight

Artificial intelligence gives your business the ability to sift through mass amounts of customer data, easily and quickly. So you’ll be able to focus on what counts — creating tailored content that boosts customer interactions. See why Adobe Sensei can make a difference to your bottom line. Check out our interactive experience M

Spotlight

Artificial intelligence gives your business the ability to sift through mass amounts of customer data, easily and quickly. So you’ll be able to focus on what counts — creating tailored content that boosts customer interactions. See why Adobe Sensei can make a difference to your bottom line. Check out our interactive experience M

Related News
AI APPLICATIONS

Infor Coleman AI Digital Assistant App Now Available for Microsoft Teams

Infor, the industry cloud company, today announced the general availability (GA) of its Infor Coleman AI Digital Assistant app for Microsoft Teams. The Infor Coleman Digital Assistant was previously available via a web browser, the Infor Go mobile app, and Amazon Alexa for Business. Now, Infor customers can interact with Infor Coleman using Microsoft Teams. This can help reduce adoption friction when rolling out the digital assistant to organizations that already use Teams in their day-to-day work. New Infor customers interested in the Microsoft Teams app can activate it straight from the Teams store. Existing customers will first need to activate the service via Infor Support. Infor Coleman AI Digital Assistant The Infor Coleman AI Digital Assistant provides a conversational interface to the Infor OS platform, the underlying foundation of Infor CloudSuites. It offers custom skills, a chat UX, and natural language processing (NLP) capabilities. As a digital assistant, Coleman uses a conversational UX and natural language processing – with deep domain and industry knowledge – to chat, hear, talk and, in the future, it is expected to analyze images to help people work more efficiently. The Infor Coleman Digital Assistant can help maximize human work potential by: Advising. It can provide intelligent insights designed to help users make decisions. Augmenting. It can serve as a partner to help amplify one's work and provide key information at critical decision points. Automating. It can complete low-value, repetitive tasks to enable users to focus on more valuable work. Conversing. It can offer a better user experience with more efficient interactions. "In the post-pandemic world, remote working and the use of collaboration platforms such as Microsoft Teams are ever more relevant. Enabling Coleman Digital Assistant within that ecosystem is a testimony to Infor's commitment to be on the leading edge of technology trends. We are excited to offer our customers the opportunity to use the same chat platform to collaborate among colleagues and to access their business information via a secured app such as the Infor Coleman Teams App." Vignesh Subramanian, Infor Coleman product director Infor Coleman makes its AI capabilities easily accessible, as it is built on the foundation of the Infor OS enterprise application platform (EAP). Constellation Research, in its April 23, 2021, Offering Overview report, "Infor OS Powers Next-Gen ERP with a Rich Platform," stated that "Infor has one of the most functionally rich and mature EAPs in the market." Infor Coleman is directly integrated with the rest of the platform's security, integration, mobile, low-code development, and user experience services. About Infor Infor is a global leader in business cloud software specialized by industry. Providing mission-critical enterprise applications to 65,000 customers in more than 175 countries, Infor software is designed to deliver more value and less risk, with more sustainable operational advantages. We empower our 17,000 employees to leverage their deep industry expertise and use data-driven insights to create, learn and adapt quickly to solve emerging business and industry challenges. Infor is committed to providing our customers with modern tools to transform their business and accelerate their own path to innovation.

Read More

AI TECH

Datatron Introduces New Features to MLOps and AI Governance Solution

Datatron announced today enhancements to its MLOps and AI governance solution, making it even easier for enterprises to catalog, operationalize, monitor and govern AI/ML models. With Datatron, customers experience 15 to 20 times more effectiveness in model deployment, bringing substantial business gains and productivity improvements. Datatron also eliminates the complexity and expense associated with constant iteration and management of many AI models at one time. Key enhancements to the Datatron Reliable AI™ platform include: ML Gateways: ML Gateways provide centralization and orchestration of models and data in complex, multi-tenant environments. It's designed to support a growing number of use cases, helping enterprises overcome challenges, including compliance, differing model technologies, and AI ownership across subsidiaries, partners, and internal data science teams Customer-defined KPIs: This enables enterprises to define their own formulas for continuous analysis of statistics and measures, set thresholds for warning and alert conditions, and include KPIs in the central governance dashboard Explainability with confidence: This unique innovation is a departure from many theoretical exercises by others. Datatron builds in a confidence score that is used against explainability, helping customers understand what data was relevant in the results and the level of trust one can place in those results Native Jupyter support: Supports direct import of Jupyter notebooks by data scientists to silently run alongside current models to get faster validation of fit, making all the governance metrics available before the model goes live Rapid setup and deployment: A new five-step guided process allows customers to run a selected model in production as APIs for real-time inferencing or scheduled batches in less than 10 minutes "At Domino's, we understood very early on that for our AI initiatives to be successful, it was important to bridge the skill sets gap between the different data scientist teams and IT organizations. Not only does Datatron's platform make this possible, but it also enables us to implement strong MLOps to rapidly operationalize our machine learning models." Zack Fragoso, manager, data science and AI, Domino's "Despite all the readily available open source MLOps frameworks, building your own MLOps infrastructure from scratch is no trivial task. Constant iteration and management of many AI models can be incredibly complex and expensive. That's why we're dedicated to making it even easier than ever for enterprises to operationalize, monitor and govern a large number of AI models." Harish Doddi, CEO, Datatron About Datatron Founded in 2016, Datatron's centralized AI ModelOps and Model Governance platform helps organizations unlock the value of their machine learning and artificial intelligence investments. With Datatron's Reliable™ AI platform, customers harness the power of AI and ML by automating and standardizing the deployment, monitoring, governance, and validation of all AI models developed in any environment. Industry leaders in financial services, insurance, pharmaceutical, and food and drinks rely on Datatron to operationalize and govern AI solutions at scale, producing predictable, rapid and reliable business outcomes. Datatron is a privately held, venture-backed company headquartered in San Francisco, California.

Read More

AI APPLICATIONS

Roostify Launches AI-Enabled Mortgage Document Intelligence Service

Roostify, a leading digital technology provider in home lending, has launched the Roostify Document Intelligence (RDI) Service for lenders, the first available service on its API platform, to instantly process and contextualize mortgage-related documents utilizing machine learning. Buying a home requires a borrower to submit substantial and detailed paperwork to support the loan application, making the current manual process cumbersome, error-prone, expensive, and difficult to scale. The lending industry spends millions of dollars each year processing these documents which include W-2s, pay stubs, and borrower asset statements. The RDI Service uses machine learning, developed in partnership with Google Cloud, to instantly process documents required for mortgage underwriting and deliver relevant data as needed to streamline the rest of the lending process. The service has three main capabilities: document classification, data extraction, and data validation. Through document classification, the service processes a document to identify the document type and confirm whether the document satisfies an associated condition generated by a loan origination system, automated underwriting system, or rules engine. With its data extraction capabilities, the RDI Service extracts the data contained in the document and returns it as human-readable, usable data via API. The data validation service matches extracted document data against loan application data to identify any potential inaccuracies, errors, or inconsistencies. The Roostify Document Intelligence Service is readily available to all lenders as well as mortgage service providers and technology providers. It can support an infinite number of use cases benefitting from automated identification and extraction of data contained within the mortgage document set. “Providing new services that utilize artificial intelligence is a big step towards improving the way borrowers experience the home buying journey, and the way lenders can simplify a process that despite rapid digitization is still cumbersome and complex.” Rajesh Bhat, co-founder and CEO at Roostify RDI is currently able to process more than 25 of the most common borrower-provided documents (e.g., paystubs, asset statements, tax forms), and by the end of the year, will have upwards of 50 mortgage document types covered. Across the entire document set, the average confidence level is greater than 90%, with 35+ document types having a confidence level of over 95%, without manual review. Thanks to machine learning capabilities, this confidence level only improves over time. “With mortgage lending becoming increasingly competitive, every minute and dollar counts for both lenders and homebuyers,” says Bhat. “As we look into the next decade, innovations in AI, machine learning, and other technologies will lead to a home lending industry that is virtually unrecognizable from today’s, and the foundations that we lay now are just the start of that process. The operational efficiencies the Roostify Document Intelligence Service enables serve as a foundation, and an absolutely fundamental one, for future innovations.” The Roostify Document Intelligence Service lays the groundwork and offers real advancement for a mortgage process that isn’t simply a digitized version of the old way, but a meaningfully improved, streamlined system that will ultimately benefit both lenders, and borrowers in the future. The service is now available to all mortgage providers on Roostify's new API platform and any lender, mortgage service provider or technology provider can use the technology regardless of their existing digital infrastructure, even if Roostify isn’t their mortgage technology partner. About Roostify Roostify was founded in 2012 to modernize and simplify the manual, inefficient mortgage process and create a more enjoyable experience for the customer and lender. Today, Roostify is helping lenders process more than $50 billion in loans each month, from large enterprise banks to thriving independent brokerages. We empower lenders to accelerate and simplify the lending process to help lenders and customers alike unlock more of life’s big moments.

Read More