Google TAG watering hole drops OSX.CDDS implant
Google TAG uncovered a watering-hole campaign chaining a WebKit n-day and an XNU 0-day to deploy the OSX.CDDS macOS backdoor, now analyzed by Objective-See.
Google's Threat Analysis Group published research on a highly targeted watering hole campaign that used both iOS and macOS exploit chains to infect Apple users. The macOS chain combined a patched WebKit RCE (CVE-2021-1789) with an XNU local privilege escalation zero-day (CVE-2021-30869), the latter reportedly first demonstrated publicly by Pangu Lab at zer0con21 and MOSEC conferences. Objective-See obtained sample hashes provided by Google and performed independent analysis of the payload, dubbed OSX.CDDS, which remained fully undetected by all AV engines on VirusTotal at time of analysis.
The implant exists in at least two variants: a 2019 sample distributed via a trojanized 'Flash Player' installer (social engineering, apparently targeting Chinese-speaking users based on embedded Chinese-language strings) and a 2021 sample delivered directly via the exploit chain. Both versions drop a persistent Launch Agent (com.UserAgent.va.plist) and install a toolkit into ~/Library/Preferences/Tools, including screen-capture and system-survey utilities, and — notably in the 2021 sample — a keylogger (kAgent) built on Core Graphics Event Taps. The implant communicates with its C2 using a Data Distribution Service (DDS) publish-subscribe framework and supports numerous tasking commands, indicating a fairly full-featured backdoor capability set.
Objective-See demonstrated that its free tools (BlockBlock, LuLu, KnockKnock) were able to detect the implant's persistence and C2 beaconing behavior without prior signatures. The overall architecture — separating exploit delivery from implant deployment — is consistent with more resourced threat actor tradecraft, though the article does not attribute the campaign to a specific named group.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x69.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free