- Feb 4, 2016
- 2,520
...some quotes from the articlle above:
A new type of tech support scam tactic observed against Mac users relies on opening a large number of email drafts, an action which eventually causes the user's machine to become unresponsive.
Delivered from the domains listed below, this new tech support scam was discovered by Malwarebytes security researcher Jérôme Segura, who says that the sites only work if users are using Safari on Mac.
safari-get[.]com
safari-get[.]net
safari-serverhost[.]com
safari-serverhost[.]net
According to Segura, when users land on one of the URLs, the page will scan the visitor's user-agent string and determine the user's Mac OS X version.
Tech support page freezes Macs for Yosemite users
If the user is using OS X 10.10 (Yosemite), the tech support page will load the first of two exploit files.
This exploit will keep opening a new email message window using the Mac's default mail app until the workstation runs out of memory and freezes.
El Capitan users get DoSed via iTunes
On the other hand, if the user is using OS X 10.11 (El Capitan), then the tech support page delivers the second exploit, which starts iTunes with repeated automatic clicks on an iTunes link. This eventually causes a Denial of Service state and freezes the user's Mac.
OS X 10.12 (macOS Sierra) users are protected from the first exploit, since macOS blocks opening email drafts via a web page, but the second exploit still works, attempting to endlessly open iTunes multiple times in a row.