Signed Mac Malware Using Right-to-Left Override Trick

Right-to-left override (RLO) is a special character used in bi-directional text encoding system to mark the start of text that are to be displayed from right to left. It is commonly used by Windows malware such as Bredolab and the high-profile Mahdi trojan from last year to hide the real extension of executable files.

F-Secure Lab have spotted a malware for Mac using the RLO trick. It was submitted to VirusTotal last Friday.
http://www.f-secure.com/weblog/archives/00002576.html
Malware for Mac using the RLO trick

No comments:

Post a Comment