New 'MACDefender' Malware Threat for Mac OS X

Status
Not open for further replies.

savit

Level 1
Thread author
Apr 9, 2011
120
094840-macdefender.jpg


Antivirus firm Intego today noted the discovery of new malware known as "MACDefender" targeting Mac OS X users via Safari. According to the report, the malware appears to be being deployed via JavaScript as a compressed ZIP file reached through Google searches.

When a user clicks on a link after performing a search on a search engine such as Google, this takes them to a web site whose page contains JavaScript that automatically downloads a file. In this case, the file downloaded is a compressed ZIP archive, which, if a specific option in a web browser is checked (Open "safe" files after downloading in Safari, for example), will open.
More information is available in Apple's support communities (1, 2), where users report that the malware is popping up directly in Google image searches.

Users running administrator accounts and with the Safari option to open "safe" files automatically checked appear to be most at risk, with some claiming that no notification of installation was seen or password required. Only when a screen popped up asking for a credit card number to sign up for virus protection did they realize that malware had been installed on their systems.

For those infected with the MACDefender malware, the following steps are recommended:

1. Open Applications > Utilities > Activity Monitor and quit any processes linked to MACDefender.

2. Delete MACDefender from the Applications folder.

3. Check System Preferences > Accounts > Login Items for suspicious entries

4. Run a Spotlight search for "MACDefender" to check for any associated files that might still be lingering.

Full details on the malware and the simplest steps needed for its complete removal are still being investigated.

Users are of course reminded that day-to-day system usage with standard accounts rather than administrator ones, as well as unchecking the Safari option for automatically opening "safe" files, are two of the simplest ways users can enhance their online security, adding extra layers of confirmation and passwords in the way of anything being installed on their systems.

Link
 

Jack

Administrator
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Another proof that no operating system immune to malware threats.
Using a standard account is a "must" on every system...not only on Mac OS X.....also having some common sense is not bad ;P
 

Ibrad

New Member
Apr 29, 2011
107
I hope this will slow/stop the false information that Mac machines are immune to malware.
 

Tweak

New Member
Jan 8, 2011
274
Hard to believe but only a few hours after I saw this posted here I got a phone call from a client that stated his wife had an infection on her mac and this is it...guess it is spreading rapidly.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
Have you seen the negative ratings the article received, the Mac users just don't want to believe this kind of stuff exists.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top