Shlayer Mac Malware Returns with Extra Sneakiness

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,132
A fresh variant of the Shlayer Mac OSX malware with advanced stealth capabilities has been spotted in the wild, actively using poisoned Google search results in order to find its victims.

According to researchers at Intego, the malware, like many malware samples before it, is purporting to be an Adobe Flash Player installer. However, it has its own unique characteristics: It takes a crafty road to infection once it’s downloaded, all in the name of evading detection. To start with, the masquerading “installer” is downloaded as a .DMG disk image, according to Intego’s analysis.

“After the deceptive Flash Player installer is downloaded and opened on a victim’s Mac, the disk image will mount and display instructions on how to install it,” explained Joshua Long, chief security analyst at Intego, in a posting on Monday.

Oddly, the instructions tell users to first right-click on the Flash Installer and select “Open,” and then to click Open in the resulting dialog box. But this “may be a bit puzzling to many casual Mac users,” Long pointed out. “Unlike typical Windows PCs, there is no obvious right-side button on Apple mice and trackpads. Therefore, novice Mac users may not know how to do the Mac equivalent of a right-click, and therefore may not understand how to run the malware installer script.”
 

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
779
Wonderful, I expect some calls from my parents.....
They don’t believe in Trojan horses. Not even joking! They once downloaded some free movie plugin scam that ended up using 100% CPU and all of their network bandwidth doing who knows what.... and they were like “well it played the movie just fine so it must have been legitimate, are you sure it wasn’t something else?”
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top