Security News Tech Support Scam Causes Macs to Freeze

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
...some quotes from the articlle above:

A new type of tech support scam tactic observed against Mac users relies on opening a large number of email drafts, an action which eventually causes the user's machine to become unresponsive.

Delivered from the domains listed below, this new tech support scam was discovered by Malwarebytes security researcher Jérôme Segura, who says that the sites only work if users are using Safari on Mac.

safari-get[.]com
safari-get[.]net
safari-serverhost[.]com
safari-serverhost[.]net
According to Segura, when users land on one of the URLs, the page will scan the visitor's user-agent string and determine the user's Mac OS X version.

Tech support page freezes Macs for Yosemite users

If the user is using OS X 10.10 (Yosemite), the tech support page will load the first of two exploit files.
This exploit will keep opening a new email message window using the Mac's default mail app until the workstation runs out of memory and freezes.

El Capitan users get DoSed via iTunes

On the other hand, if the user is using OS X 10.11 (El Capitan), then the tech support page delivers the second exploit, which starts iTunes with repeated automatic clicks on an iTunes link. This eventually causes a Denial of Service state and freezes the user's Mac.

OS X 10.12 (macOS Sierra) users are protected from the first exploit, since macOS blocks opening email drafts via a web page, but the second exploit still works, attempting to endlessly open iTunes multiple times in a row.
 
  • Like
Reactions: Der.Reisende

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top