Is the Chinese Government exploiting a hole in Office for Mac?

Chinese authorities may be exploiting a security hole in Microsoft Office for Mac to target the Uyghur people

According to Kaspersky and AlienVault Labs, Chinese authorities may be exploiting a security hole in Microsoft Office for Mac to target the Uyghur people, an ethnic group of people who live in parts of Asia and are seeking independence from Chinese rule.

The targeted attacks exploit an old Office for Mac vulnerability (CVE-2009-0563) that was actually fixed over three years ago.

Kaspersky says it has noticed a "significant spike in the number of attacks during Jan 2013 and Feb 2013, indicating the attackers are extremely active at the moment."

Phishing emails have been sent to the Uyghur community that include Microsoft Word documents, which once open, activate a Mac OS X backdoor that "would initiate a connection with the server, and its "tshd_put_file" function was configured to drop stolen data in the "/downloads/" directory located there", writes Kaspersky.

The hackers are able to remotely control the computer and spy on its user's activities.

One of the corrupt files details the "Concerns over Uyghur People's Fundamental Rights Under the New Chinese Leadership". The documents can be identified by the author name: "Captain".

Similar attacks have been reported against other ethnic groups, including the Tibetan people and Uighur activists.

Follow Karen Haslam on Twitter / Follow MacworldUK on Twitter

Related:

Mac backdoor used in attacks against Uighur activists

The worst security exploits, fails and blunders: 2012 in review

Security expert claims Apple will lose out to 'open, sexy, flexible' competitors

Kaspersky Security for Mac review

Mountain Lion and Gatekeeper: What you need to know

Flashback the wake up call Apple needed: Kaspersky

2015 State of The IT Channel Survey : IT'S TIME!!! Fill in this year's State of the IT Channel Survey and be in the running to win great prizes. CLICK HERE

Join the ARN newsletter!

Error: Please check your email address.

Tags MacapplicationsMicrosoftsecuritysoftwareOffice suitesExploits / vulnerabilities

More about AppleKasperskyMicrosoft

ARN Directory | Distributors relevant to this article

ARN Directory | Vendors relevant to this article

Show Comments
 

Latest News

May 22
Raiders change strip to support cancer research
May 22
Chromebook sales up 27 per cent to 7.3 million units: Gartner
May 22
Federal Government foreshadows changes to spectrum pricing and allocation
May 22
Seventy per cent of Australian small businesses predict growth in year ahead
More News
26 May
IM Experience, Brisbane
26 May
SplunkLive! Brisbane
26 May
Entrepreneurial Marketing - Innovative Thinking to Create or Re-Invigorate your ...
26 May
D-Link IP Surveillance Training and Certification
View all events