{"id":17298,"date":"2019-12-27T20:57:39","date_gmt":"2019-12-28T04:57:39","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/12\/27\/news-11034\/"},"modified":"2019-12-27T20:57:39","modified_gmt":"2019-12-28T04:57:39","slug":"news-11034","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/12\/27\/news-11034\/","title":{"rendered":"VB2019 paper: Never before had Stierlitz been so close to failure (or: what is a Soviet super-spy doing in a popular bundleware for Mac?)"},"content":{"rendered":"<p>Over the years, many \u2018potentially unwanted applications\u2019 have plagued <em>macOS<\/em> in the same way they have plagued other platforms. Though anti-virus isn\u2019t ubiquitous on Macs, detecting such PUAs usually isn\u2019t a difficult problem.<\/p>\n<p>However, there are exceptions. One such exception is a popular yet unnamed piece of \u2018bundleware\u2019 that was analysed by <em>Sophos<\/em> researcher Sergei Shevchenko in a paper presented at VB2019 in London. The bundleware performs many obfuscation and anti-analysis techniques that are typical of malware and is used to download other software on systems on which it is installed.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" style=\"display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/www.virusbulletin.com\/files\/cache\/4bae642b9afbdafeb6fdd051e89beb2e_f4216.png\" alt=\"schema_engine.png\" width=\"600\" height=\"236\" \/><br \/>Today we publish Sergei&#8217;s paper in both <a title=\"VB2019 paper: Never before had Stierlitz been so close to failure (or: what is a Soviet super-spy doing in a popular bundleware for Mac?)\" href=\"https:\/\/www.virusbulletin.com\/virusbulletin\/2019\/12\/vb2019-paper-never-had-stierlitz-been-so-close-failure-or-what-soviet-super-spy-doing-popular-bundleware-mac\/\">HTML<\/a> and <a href=\"https:\/\/www.virusbulletin.com\/uploads\/pdf\/magazine\/2019\/VB2019-Shevchenko.pdf\" target=\"_blank\">PDF <\/a>format. We have also uploaded the recording of his presentation at VB2019 in London to our <em>YouTube<\/em> channel.<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: center;\" width=\"100%\" height=\"420\"><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/lmOeu6CI8EQ\" frameborder=\"0\" width=\"100%\" height=\"420\" style=\"\"> <\/iframe><\/p>\n<p>\u00a0<\/p>\n<p>outertext<br \/><a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/12\/vb2019-paper-never-had-stierlitz-been-so-close-failure-or-what-soviet-super-spy-doing-popular-bundleware-mac\/\" target=\"bwo\" >https:\/\/www.virusbulletin.com\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.virusbulletin.com\/files\/cache\/4bae642b9afbdafeb6fdd051e89beb2e_f4216.png\"\/><br \/>                                 Today, we publish the VB2019 paper and video by Sophos researcher Sergei Shevchenko in which he analyses a popular yet unnamed piece of macOS \u2018bundleware\u2019.                <\/p>\n<p>                 <a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/12\/vb2019-paper-never-had-stierlitz-been-so-close-failure-or-what-soviet-super-spy-doing-popular-bundleware-mac\/\">Read more<\/a>                                <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[23177,10378,23176],"tags":[],"class_list":["post-17298","post","type-post","status-publish","format-standard","hentry","category-magazine","category-security","category-virusbulletin"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17298","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17298"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17298\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17298"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17298"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}