Security experts create worm that infects Mac firmware and is nearly impossible to get rid of

Status
Not open for further replies.

Kardo Kristal

From Crystal Security
Thread author
Verified
Top Poster
Developer
Well-known
Jul 12, 2014
1,143
Apple’s Macs and OS X have traditionally been viewed as a safer, more secure alternative to Windows, but researchers have proven that’s not the case. Security experts created a worm that attaches itself to a Mac’s firmware and remains there no matter what.

Ahead of a presentation on this type of attack, researchers created a proof-of-concept worm that can stealthily burrow itself into a Mac’s firmware. It’s then impossible to remove without re-flashing the device’s firmware, which can be difficult and is only for those who really know what they’re doing.



The real threat is that previous attacks of this nature required physical access to the machine, but this attack can be delivered remotely by tricking the user to click on a malicious link. A silent, almost undetectable attack that’s nearly impossible to get rid of could spell disaster for many users.

Luckily Apple is already on the case and has patched one of the vulnerabilities that’s being exploited, while the second one is being worked on as we speak. The latest version of OS X (10.10.4) seems to no longer be vulnerable to these types of attacks, so make sure to upgrade quickly.
 

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,712
People should be careful. Their apple might have a worm inside it. :p

But joking aside, this is another reason why people shouldn't be so overconfident just because the number of malware is less than Windows.
 
  • Like
Reactions: Kardo Kristal
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top