There’s a dangerous new tool worming its way through the dark web that can completely take control of your Mac computer without your knowledge, allowing hackers to pilfer personal financial information or other sensitive data.
In a blog post this week, Guardz — the cybersecurity firm behind the discovery — found that the malicious dark web tool has been available to buyers since April of this year, with a pretty hefty price tag of $60,000 for a lifetime subscription.
Based on that price — with a $20,000 add-on “to deliver more malicious capabilities to the arsenal,” according to Guardz — it’s likely being sold to those seeking to attack small to medium-sized businesses.
Getting a little help from AI in the discovery, Guardz first asked OpenAI’s chatbot ChatGPT about macOS threats to small and medium-sized businesses on the dark web. Though the AI bot didn’t offer up any specifics, it provided inspiration nevertheless and led to the discovery of this new HVNC malware tool.
“Motivated by the response, our researchers delved back into the depths of the cybercrime underground to authenticate this lead,” Guardz said.
What is an HVNC Tool? How Does It Work?
The tool is a malicious version of legitimate VNC (Virtual Network Computer) tools. An IT support technician might use VNC to access your device remotely to help with a technical issue.
As Guardz explains: “In this case, the user is clearly able to see on his/her screen that somebody else controls the workstation and is fully aware of which actions are performed by a third party.”
A malicious HVNC tool (Hidden Virtual Network Computer), however, operates without user knowledge and sneaks its way onto the device. This could be downloaded via malicious email attachments, links in phishing emails, or through business email compromise (BEC).
The likely aim is for a cybercriminal to go through a Mac computer and steal login credentials, financial information, intellectual property, or other sensitive data. Since the tool runs in stealth mode, a user never knows someone has complete control of their device — and simply restarting a Mac will not deter the persistent infection.
Dark Web Threats Found on Underground Russian Forum
According to a deep dive by Guardz into the prominent Russian cybercrime forum “Exploit,” a threat actor — dubbed “RastaFarEye” — is providing this malicious tool.
As proof of the tool’s effectiveness, the hackers have even deposited $100,000 (equivalent to about 3.33 Bitcoin) into an escrow account. This deposit serves as a type of underground insurance should the product not work effectively and reflects the seller’s high-profile status.
“For a lifetime price of $60,000, the threat actor will provide you with a malicious tool that supports persistence, runs without requesting any permission from the user, has a reverse shell plus remote file manager, and was tested on a wide array of macOS versions from 10 up to 13.2,” Guardz said.
Security Measures for Mac Owners Against Stealthy HVNC Threat
Businesses and personal Mac owners alike must remain vigilant. To prevent potential compromise, keeping your Mac updated to the latest macOS version is key, cybersecurity experts say, as the malware only functions up to macOS Ventura 13.2.
At this time, users can update their Macs to the latest version, 13.5, via the Finder tool > Software Update. You should also ensure that “Automatically keep my Mac up to date” is ticked there.
A simple update to Mac’s current 13.5 operating system, alongside leading Mac antivirus software, should keep users safe — for the time being.
Standard cybersecurity practices are also always vital. We recommend installing apps only from the official Apple App Store and not clicking on email links or attachments unless you’re absolutely certain of their origin.
Check email addresses carefully, and look out for messages or requests that seem odd or strange. Social engineering and business email compromise (BEC) are major ways savvy crooks can find their way onto your Mac. Furthermore, we always urge Mac users to follow our cyber hygiene fundamentals top list.
The unveiling of this threat follows Guardz’s discovery of another macOS threat, ShadowVault, just last month. The dark web is a known breeding ground for illicit activities, extending far beyond tools like HVNC and other macOS threats.
For instance, here, cybercriminals trade malicious software like DarkBERT, a malicious artificial intelligence chatbot, and entire stolen identity kits, which include everything from Social Security numbers to bank details.
Follow us on Twitter, Threads, and Mastodon for the latest on dark web threats and much more!
