{"id":14427,"date":"2013-05-17T07:43:46","date_gmt":"2013-05-17T14:43:46","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=14427"},"modified":"2026-07-02T01:30:49","modified_gmt":"2026-07-02T08:30:49","slug":"two-new-variants-of-backdoor-trojan-found-targeting-activists","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/","title":{"rendered":"Two New Variants of Backdoor Trojan Found Targeting Activists"},"content":{"rendered":"<p>Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass <a href=\"https:\/\/www.intego.com\/mac-security-blog\/do-os-xs-built-in-security-features-offer-good-enough-protection\/\">certain levels of Gatekeeper protection<\/a>. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and as such the threat has been effectively neutralized. As new variants could continue to be created, it is best to continue to exercise caution, particularly if you&#8217;re in a targeted group.<\/p>\n<p>The backdoor itself is, like previous variants, very basic in functionality. It copies itself to the User&#8217;s home folder (whereas the original variant copied itself to the \/Applications folder) and adds itself to the user&#8217;s login item to be launched on every startup. It does this using the same Applescript as used by the original OSX\/FileSteal.A variant. The backdoor silently takes screenshots of the affected user&#8217;s machine, which are put it in the ~\/MacApp folder. The threat then sends collected screenshots in PNG format to one remote website, and it sends other collected user info to another, separate site. The various sites used by the backdoor are not responding at this time.<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/LoginItems.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-14429\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/LoginItems.png\" alt=\"OSX\/FileSteal Mac malware\" width=\"479\" height=\"247\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/LoginItems.png 479w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/LoginItems-150x77.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/LoginItems-300x154.png 300w\" sizes=\"auto, (max-width: 479px) 100vw, 479px\" \/><\/a><\/p>\n<p>In the case of at least one variant, the application is purported to be a picture within a ZIP archive:<\/p>\n<ul>\n<li>DSC001254_160413.zip<\/li>\n<\/ul>\n<p>When unzipped, the application name is the same:<\/p>\n<ul>\n<li>DSC001254_160413.app<\/li>\n<\/ul>\n<p>The remote sites used by the different variants of this threat are as follows:<\/p>\n<ul>\n<li>torqspot.org\/App\/MacADV\/up.php<\/li>\n<li>securitytable.org\/app-ang\/upload.php<\/li>\n<li>securitytable.org\/lang.php<\/li>\n<li>docsforum.info\/lang.php<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.intego.com\/features\/virus-scanner\">Intego VirusBarrier<\/a> users with up-to-date virus definitions will detect this trojan as OSX\/FileSteal.B.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[190,5],"tags":[30,86,399,132],"class_list":["post-14427","post","type-post","status-publish","format-standard","has-post-thumbnail","category-malware","category-security-news","tag-backdoor","tag-mac-malware","tag-osxfilesteal","tag-trojan-horse"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Lysa Myers\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Two New Variants of Backdoor Trojan Found Targeting Activists\" \/>\n\t\t<meta property=\"og:description\" content=\"Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2013-05-17T14:43:46+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-02T08:30:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Two New Variants of Backdoor Trojan Found Targeting Activists\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#blogposting\",\"name\":\"Two New Variants of Backdoor Trojan Found Targeting Activists\",\"headline\":\"Two New Variants of Backdoor Trojan Found Targeting Activists\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert.png\",\"width\":400,\"height\":260},\"datePublished\":\"2013-05-17T07:43:46-07:00\",\"dateModified\":\"2026-07-02T01:30:49-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#webpage\"},\"articleSection\":\"Malware, Security News, Backdoor, Malware, OSX\\\/FileSteal, Trojan Horse, lysam\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"position\":2,\"name\":\"Security News\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#listItem\",\"name\":\"Two New Variants of Backdoor Trojan Found Targeting Activists\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#listItem\",\"position\":3,\"name\":\"Two New Variants of Backdoor Trojan Found Targeting Activists\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a244278f35cc41c7ec676b36673dee0464ed8c7ceafb1ff484fdf13a916d126c?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Lysa Myers\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/\",\"name\":\"Two New Variants of Backdoor Trojan Found Targeting Activists\",\"description\":\"Two new variants of a backdoor trojan named OSX\\\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#mainImage\",\"width\":400,\"height\":260},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/two-new-variants-of-backdoor-trojan-found-targeting-activists\\\/#mainImage\"},\"datePublished\":\"2013-05-17T07:43:46-07:00\",\"dateModified\":\"2026-07-02T01:30:49-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Two New Variants of Backdoor Trojan Found Targeting Activists<\/title>\n\n","aioseo_head_json":{"title":"Two New Variants of Backdoor Trojan Found Targeting Activists","description":"Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#blogposting","name":"Two New Variants of Backdoor Trojan Found Targeting Activists","headline":"Two New Variants of Backdoor Trojan Found Targeting Activists","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","width":400,"height":260},"datePublished":"2013-05-17T07:43:46-07:00","dateModified":"2026-07-02T01:30:49-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#webpage"},"articleSection":"Malware, Security News, Backdoor, Malware, OSX\/FileSteal, Trojan Horse, lysam"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","position":2,"name":"Security News","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#listItem","name":"Two New Variants of Backdoor Trojan Found Targeting Activists"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#listItem","position":3,"name":"Two New Variants of Backdoor Trojan Found Targeting Activists","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/a244278f35cc41c7ec676b36673dee0464ed8c7ceafb1ff484fdf13a916d126c?s=96&d=mm&r=g","width":96,"height":96,"caption":"Lysa Myers"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/","name":"Two New Variants of Backdoor Trojan Found Targeting Activists","description":"Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#mainImage","width":400,"height":260},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/#mainImage"},"datePublished":"2013-05-17T07:43:46-07:00","dateModified":"2026-07-02T01:30:49-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"Two New Variants of Backdoor Trojan Found Targeting Activists","og:description":"Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and","og:url":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/","article:published_time":"2013-05-17T14:43:46+00:00","article:modified_time":"2026-07-02T08:30:49+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"Two New Variants of Backdoor Trojan Found Targeting Activists","twitter:description":"Two new variants of a backdoor trojan named OSX\/FileSteal have been found to be targeting activists via targeted email. The trojan is signed using a developer certificate to bypass certain levels of Gatekeeper protection. At the time of writing, the certificate has been revoked and the servers used by the threat have been sinkholed and","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":[],"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/\" title=\"Security News\">Security News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tTwo New Variants of Backdoor Trojan Found Targeting Activists\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Security News","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/"},{"label":"Two New Variants of Backdoor Trojan Found Targeting Activists","link":"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/14427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=14427"}],"version-history":[{"count":14,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/14427\/revisions"}],"predecessor-version":[{"id":105380,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/14427\/revisions\/105380"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8755"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=14427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=14427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=14427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}