January 27, 2022  —  Eric Swotinsky
Incident reports

New DazzleSpy backdoor used in watering hole attack

Recent research shows that a previously undocumented form of cyber-espionage malware, named DazzleSpy, exploited the Safari web browser in a watering hole attack. The intended targets appear to be Hong Kong-based pro-democracy political activists, including the D100 radio station, which reaches over 10,000 listeners every day.

This attack made use of fake or compromised websites that contained exploits targeting versions of macOS 10.15.2 or newer, ultimately creating an attack chain that resulted in establishment of a backdoor on the victims' systems.

The full-featured backdoor DazzleSpy is detected and stopped by Acronis Cyber Protect's advanced behavioral detection capabilities, which protect you against even never-before-seen threats based on the malicious behaviors that they exhibit.