Janicab (OS X)

First seen
2013-08-01 00:00:00
Malware type
spyware, trojan
Profile updated
2026-07-07 12:58:01

Targeted industries: media-and-entertainment technology-and-telecommunications

Context

According to Patrick Wardle, this malware persists a python script as a cron job. Steps: 1. Python installer first saves any existing cron jobs into a temporary file named '/tmp/dump'. 2. Appends its new job to this file. 3. Once the new cron job has been added 'python (~/.t/runner.pyc)' runs every minute.

Reports & references

  • Kaspersky — 98177 (report)
  • Kaspersky — 99204 (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Janicab (report)
  • archive.f-secure.com — 00002576 (report)
  • malwarology.com — Janicab Series First Steps In The Infection Chain (report)
  • malwarology.com — Janicab Series The Core Artifact (report)
  • blog.avast.com — Multisystem Trojan Janicab Attacks Windows And Macosx Via Scripts (report)
  • macmark.de — Osx Blog 2013 08 A (report)
  • malwarology.com — Janicab Series Attibution And Iocs (report)
  • malwarology.com — 5 Janicab Part 1 (report)
  • malwarology.com — Janicab Series Further Steps In The Infection Chain (report)
  • Kaspersky — 108131 (report)
  • sec0wn.blogspot.com — Powersing From Lnk Files To Janicab (report)

External references