Menu
Browse

Cyber Incident Victim: HandBrake

Date:

May 2017

Location:

United States of America

Summary

A mirror server hosting the HandBrake video transcoder was compromised, distributing malware to Mac users who downloaded the software during a specific window. The malicious version installed a remote access Trojan, OSX.Proton, granting attackers root privileges to steal credentials, capture keystrokes, hijack webcams, and exfiltrate files. Infected systems could be identified by checking for an "Activity_agent" process. The primary download sources remained unaffected, and the compromised mirror was taken offline. Security experts noted the incident highlighted risks for Mac users, who historically had lower antivirus adoption rates compared to Windows counterparts.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Between May 2 and May 6, 2017, attackers compromised a mirror server hosting downloads for HandBrake, a widely used video transcoding application. The intrusion resulted in the replacement of legitimate HandBrake software for macOS with malware. HandBrake developers publicly disclosed the breach on May 6 via their application forum, alerting users who downloaded the macOS version during the affected period. Forensic analysis revealed a 50% probability of infection for downloads originating from the compromised mirror during this timeframe. The malicious payload was identified as a new variant of OSX.Proton, a remote access trojan first observed in February 2017 that grants root-level system access.

Cyber Incident Image

Infected systems exhibited a process named "Activity_agent" visible in macOS Activity Monitor. The trojan enabled unauthorized remote control of compromised devices, permitting attackers to capture keystrokes, harvest credentials from password managers and browsers, steal files, activate webcams, and take screenshots. HandBrake instructed potentially affected users to terminate malicious processes via Terminal commands, uninstall the application, and reset all stored credentials. Concurrently, Apple initiated distribution of updated XProtect antivirus definitions to automatically detect the malware. The compromised mirror server was taken offline for forensic investigation, while primary distribution channels remained operational. Security analysts noted the incident highlighted risks associated with lower adoption rates of antivirus solutions among macOS users compared to Windows environments, potentially increasing susceptibility to such attacks. No attribution or technical details regarding the server compromise method were disclosed by HandBrake.

Sources
Sources available to members
1 source