HandBrake mirror delivered Proton RAT
An official HandBrake download mirror, download.handbrake.fr, was compromised while hosting the macOS release.
Story
HandBrake's 2017 incident hit a mirror, not the source tree. Between May 2 and May 6, the download.handbrake.fr mirror served a trojanized HandBrake-1.0.7.dmg for macOS. The main site stayed legitimate, but the official mirror path was enough.
The replacement package carried OSX/Proton.B. The malware used activity_agent, decrypted strings from a .hash resource, asked the user for a password under the cover of installing codecs, and then used that password to obtain higher privileges.
Proton was built for control and theft. Public analysis described keylogging, password and keychain theft, browser credential theft, file exfiltration, screenshots, remote shell, and remote access capabilities. HandBrake told affected users to change passwords stored in macOS Keychain and browsers.
The project said users who downloaded during the window had about a fifty percent chance of infection because not every download came from the compromised mirror. Built-in updates from HandBrake 1.0 and later were reported safe because update verification would reject the malicious file.
Affected Artifacts
- Observed
- 2017-05-02 to 2017-05-06
- Compromised Versions
- Fixed
- Not listed
- Hashes
-
- sha256:0935a43ca90c6c419a49e4f8f1d75e68cd70cb90b79306ce0cc7af2716aaa377
- sha1:32176407013738cb03959d0945993c13373f9590
- sha256:013623e5e50449bbdf6943549d8224a122aa6c42bd3300a1bd2b743b01ae6793
- +1 more
Incident Context
- Motive
- Credential Theft
- Attribution
- Group
- Cause
- Compromised Infrastructure
- Transitive
- No
- Actor
- Cybercriminal Gang
External References
- HandBrake download server hacked to distribute Mac malwarearstechnica.com
- Proton Mac OS X RATsecurelist.com
- Check your HandBrake 1.0.7.dmgforum.handbrake.fr
- Proton.B: What this Mac malware actually doescybereason.com
Source record: oss/attacks/handbrake/meta.yaml