Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Nasty Mac malware bypasses Gatekeeper, undetectable by most antivirus apps
9 to 5 Mac ^ | April 28, 2017 | By Ben Lovejoy

Posted on 04/28/2017 10:21:46 AM PDT by Swordmaker

We learned recently that macOS malware grew by 744% last year, though most of it fell into the less-worrying category of adware.


However, a newly-discovered piece of malware (via Reddit) falls into the ‘seriously nasty’ category – able to spy on all your Internet usage, including use of secure websites.

Security researchers at CheckPoint found something they’ve labelled OSX/Dok, which manages to go undetected by Gatekeeper and stops users doing anything on their Mac until they accept a fake OS X update …

OSX/Dok does rely on a phishing attack as its initial way in. Victims are sent an email claiming to be from a tax office regarding their income tax return, asking them to open an attached zip file for details. This should, of course, immediately ring alarm-bells: no-one should ever open a zip file they aren’t expecting, even if it seems to be from a known contact.

But after that, the approach taken by the malware is extremely clever. It installs itself as a Login Item called AppStore, which means it automatically runs each time the machine is booted. It then waits for a while before presenting a fake macOS update window.

The victim is barred from accessing any windows or using their machine in any way until they relent, enter the password and allow the malware to finish installing. Once they do, the malware gains administrator privileges on the victim’s machine […]

The malware then changes the victim system’s network settings such that all outgoing connections will pass through a proxy, which is dynamically obtained from a Proxy AutoConfiguration (PAC) file sitting in a malicious server.

This means that literally everything you do on the Internet, even accessing secure servers using https connections, will pass through the attacker’s proxy. A bogus security certificate is also installed, allowing the attacker to impersonate any website without being flagged.

As a result of all of the above actions, when attempting to surf the web, the user’s web browser will first ask the attacker web page on TOR for proxy settings. The user traffic is then redirected through a proxy controlled by the attacker, who carries out a Man-In-the-Middle attack and impersonates the various sites the user attempts to surf. The attacker is free to read the victim’s traffic and tamper with it in any way they please.

The reason Gatekeeper doesn’t block the malware in the first place is that it has a valid developer’s certificate. This should make it easy for Apple to address, by revoking the certificate, but it of course set in motion again if the attackers can gain access to another certificate.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: apple; applepinglist; mac; macbook; macmalware; phishing
Navigation: use the links below to view more comments.
first 1-2021-25 next last
That window above looks nothing like Apple's alert for updates for OS X or macOS. If you see it, force quit the app that is running it and delete the email you were in. It would be a good idea to cold restart your Mac.
1 posted on 04/28/2017 10:21:46 AM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: Swordmaker

[[Nasty Mac malware bypasses Gatekeeper, undetectable by most antivirus apps]]

PHEW! Thank goodness I have a windows computer then


2 posted on 04/28/2017 10:24:56 AM PDT by Bob434
[ Post Reply | Private Reply | To 1 | View Replies]

To: ~Kim4VRWC's~; 1234; 5thGenTexan; AbolishCSEU; Abundy; Action-America; acoulterfan; AFreeBird; ...
If you get an email purporting to be from the IRS containing a ZIP file, it's a PHISHING attack containing a malicious TROJAN that can damage your Mac. DO NOT OPEN IT. It will install a file that will require you to install a bogus OS X or MacOS update that installs malware on your Mac. BEWARE! As always, this attack requires you to be industrially strength stupid by opening something you shouldn't. But this time the Mac's built in protections will not help. Apple will block it soon, but watch out in the meantime. IRS does not contact people via email! — PING!


Apple Mac Security and Malware Warning!
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

3 posted on 04/28/2017 10:27:18 AM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bob434
PHEW! Thank goodness I have a windows computer then

Except many windows viruses cause users to bypass windows altogether by buying Macs. Problem of thousands of windows viruses then no longer a problem.

4 posted on 04/28/2017 10:30:09 AM PDT by roadcat
[ Post Reply | Private Reply | To 2 | View Replies]

To: Bob434


In all fairness I have both PC and Mac.
5 posted on 04/28/2017 10:31:17 AM PDT by rollo tomasi (Working hard to pay for deadbeats and corrupt politicians.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: roadcat

yeah i was just kiddin- I actually run linux- and only use windows in an offline environment in a dual boot configuration- my linux install is my online os-


6 posted on 04/28/2017 10:31:55 AM PDT by Bob434
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker
Nasty Mac!


7 posted on 04/28/2017 10:38:20 AM PDT by Buckeye McFrog
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bob434

Apple has under invested in their OS for years. Considering they have a locked in hardware base it should be pretty simple to keep ahead of the threats. Those massive profits come at a price.


8 posted on 04/28/2017 10:42:40 AM PDT by ImJustAnotherOkie
[ Post Reply | Private Reply | To 2 | View Replies]

To: Bob434

I’ve been running Linux in some form since 1994. Seldom ever boot a Window machine, almost never a MAC machine.

I’ve never had malware on a Linux computer.

Now there is a risk of root kit, but that can happen with the other OS’s too.


9 posted on 04/28/2017 10:51:22 AM PDT by Texas Fossil ((Texas is not where you were born, but a Free State of Heart, Mind & Attitude!))
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker

Bookmark


10 posted on 04/28/2017 10:54:08 AM PDT by Irish Eyes
[ Post Reply | Private Reply | To 1 | View Replies]

To: Texas Fossil

the rootkits in linux though are very very scarce- unlike windows viruses which are everywhere- I’m far less concerned about getting viruses in linux than i was running windows (although i had an awesome program called RollBackRX that was like system restore on steroids- as it could be accessed at boot- and revert to before any virus hit- complete restore- no trace of virus afterwards)- but i got sick of doing searches- going to sites you thought would be fine- like a PC oriented site- only to get redirected to another site full of viruses and auto downloads- and constantly having to guard against viruses- and worrying about emails etc- The peace of mind with linux has been a Godsend really-

I only dual boot to windows to use photoshop and soem processing apps within photoshop for photography purposes, and to run windows only games-


11 posted on 04/28/2017 10:58:30 AM PDT by Bob434
[ Post Reply | Private Reply | To 9 | View Replies]

To: ImJustAnotherOkie

I never looked into macs- thought about it a few times because of all the heavy processing i do in photoshop- but was just always comfortable with what i knew- too old to learn new stuff lol


12 posted on 04/28/2017 11:00:36 AM PDT by Bob434
[ Post Reply | Private Reply | To 8 | View Replies]

To: Bob434

I ran a catalog/advertising department for 5-1/2 years for a wholesale distributor. I lived in a spread sheet and in graphic software.

Quit using Adobe, had several version of Adobe Suite. I found I could do the same job I needed to do with GIMP and use only 1 app. No bridge thingie. (bridge = BLOAT)

Used ImageMagic for mass image processing. Did it daily as I made changes and added images. (47,000 items in warehouse)

Now, seldom need anything I don’t have in Linux. I have knobs screwed down pretty tight for web use.


13 posted on 04/28/2017 11:28:16 AM PDT by Texas Fossil ((Texas is not where you were born, but a Free State of Heart, Mind & Attitude!))
[ Post Reply | Private Reply | To 11 | View Replies]

To: All

I have been told repeatedly on this forum by very loud and rude posters that Mac’s don’t have security issues.

So this, and other recent stories, are false..... :-O


14 posted on 04/28/2017 11:40:43 AM PDT by TheTimeOfMan (A time for peace and a time for war)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Bob434

The time of the Mac being the best at anything is long past. It’s a platform now for the old dogs not wanting to learn new tricks.


15 posted on 04/28/2017 11:43:48 AM PDT by ImJustAnotherOkie
[ Post Reply | Private Reply | To 12 | View Replies]

To: Swordmaker
Open a .zip file attached to an email?


16 posted on 04/28/2017 12:15:14 PM PDT by al_c (Obama's standing in the world has fallen so much that Kenya now claims he was born in America.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bob434; ImJustAnotherOkie
I never looked into Macs- thought about it a few times because of all the heavy processing I do in photoshop- but was just always comfortable with what I knew- too old to learn new stuff lol

Okie hasn't a clue what he's blathering about in Apple threads. He's here to spread dis-information.

17 posted on 04/28/2017 9:21:15 PM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 12 | View Replies]

To: TheTimeOfMan
I have been told repeatedly on this forum by very loud and rude posters that Mac’s don’t have security issues.

So this, and other recent stories, are false..... :-O

It is. To install something in the booting Startup Items which is a protected Library in OS X and macOS still requires an Administrator Password. It won't happen without the user's stupid complicity. It takes industrial strength stupidity to give a ZIP FILE an administrator's name and password when it unZips. It will be as obvious as all hell that something that should NOT BE ALLOWED is going on.

About the only people I can think of that might be susceptible to this are those who are running as an Administrator and they would STILL have to provide their administrator password, not just click "Yes" when prompted as on the other popular system.

In addition, that screen that comes up looks absolutely NOTHING like a normal Apple update screen. That alone is enough to alert any normally alert Mac user. . . especially since it gives the user no choice in the matter. Apple always gives the user a choice. Pull the plug and then reboot. Find out what's wrong. It's easy to get rid of, simply delete the bogus "AppStore" file from the Startup folder in the Library. Done.

So:


18 posted on 04/28/2017 9:48:16 PM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Swordmaker

Thank you! Always good to be reminded of safety basics such as not opening a zipfile.


19 posted on 04/28/2017 10:23:05 PM PDT by The Westerner (Protect the most vulnerable: get the government out of medicine and education!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bob434
yeah i was just kiddin- I actually run linux- and only use windows in an offline environment in a dual boot configuration- my linux install is my online os-

I was thinking about diving into modern linux with some of my older PCs. I haven't worked with Linux since the late 1990s, abandoned it because of problems with hardware and trying to get around it. Since it's more mature now maybe I'll dive in and put it on some PCs that I have (up through 2008 PCs). Mac environment is my main daily thing now; I used to administer Windows/NT and Unix machines.

20 posted on 04/30/2017 12:39:49 PM PDT by roadcat
[ Post Reply | Private Reply | To 6 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-25 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson