• This forum is for posting news stories or links from rumor sites. When you start a thread, please include a link to the site you're referencing.

    THIS IS NOT A FORUM TO ASK "WHAT IF?" TYPE QUESTIONS.

    THIS IS NOT A FORUM FOR ASKING QUESTIONS ABOUT HOW TO USE YOUR MAC OR SOFTWARE.

    This is a NEWS and RUMORS forum as the name implies. If your thread is neither of those things, then please find the appropriate forum to ask your question.

    If you don't have a link to a news story, do not post the thread here.

    If you don't follow these rules, then your post may be deleted.

Latest 'MAC Defender' malware attacks Mac OS X without password

BrianLachoreVPI


Retired Staff
Joined
Feb 24, 2011
Messages
3,733
Reaction score
124
Points
63
Location
Maryland
Your Mac's Specs
March 2011 15" MBP 2.3GHz i7 Quad Core 8GB Ram | Mid 2011 27" iMac 3.4 GHz i7 16 GB RAM 2 TB HDD
Mac Guard - New Mac Defender malware variant drops admin password requirement

Figured I'd give this its own thread - just so folks who don't read the nerd sites that I do will see it. :)

New Mac Defender malware variant drops admin password requirement

When we spoke with Intego spokesperson Peter James last week, he pointed out that he initially saw a new Mac Defender variant every 12 to 24 hours, but eventually stopped seeing new versions. He warned that the creators could be revamping the malware to stay under the radar of legit antivirus software or to find new ways to poison users' machines. Now with the availability of Mac Guard, that indeed seems to be the case.

"Unlike the previous variants of this fake antivirus, no administrator’s password is required to install this program. Since any user can install software in the Applications folder, a password is not needed," Intego wrote on its blog. "This package installs an application—the downloader—named avRunner, which then launches automatically. At the same time, the installation package deletes itself from the user’s Mac, so no traces of the original installer are left behind."

Once again, the company advises users to turn off "Open 'safe' files after downloading" in their Safari preferences, since this malware (and others like it) are making their way onto users' computers via maliciously crafted URLs.
 
Joined
Oct 3, 2009
Messages
2,641
Reaction score
26
Points
48
Location
Albuquerque, New Mexico
*facepalm*

I'm hoping there's more in the upcoming security update than simply removing the old program...
 
Joined
Mar 30, 2005
Messages
9,571
Reaction score
25
Points
48
Latest 'MAC Defender' malware attacks Mac OS X without password

A new, more dangerous variant of "MAC Defender," dubbed "Mac Guard," has been discovered, and the new malware does not require an administrator password to install.


pixel
p-8bUhLiluj0fAw.gif
adscout.php

Read more
 

iWhat

,
Joined
Nov 11, 2004
Messages
5,736
Reaction score
164
Points
63
Location
Toledo, Ohio
Your Mac's Specs
Macbook, iMac G5, iPad, iPhone 4, iPod (MANY)!
Going to merge these real quick, posting to the Twitters soon.
 

bobtomay

,
Retired Staff
Joined
Dec 22, 2006
Messages
26,561
Reaction score
677
Points
113
Location
Texas, where else?
Your Mac's Specs
15" MBP '06 2.33 C2D 4GB 10.7; 13" MBA '14 1.8 i7 8GB 10.11; 21" iMac '13 2.9 i5 8GB 10.11; 6S
And if anyone finds a link for this new variant, PM me with it and I'll go grab it.
 
Joined
Jan 24, 2011
Messages
76
Reaction score
1
Points
8
Your Mac's Specs
13.3" macbook pro (2010) 2.4 Ghz Core 2 Duo, 4 Gb RAM, 500GB HD.
What are the people who claim this can't happen going to say now?
 
Joined
Nov 28, 2007
Messages
25,564
Reaction score
486
Points
83
Location
Blue Mountains NSW Australia
Your Mac's Specs
Silver M1 iMac 512/16/8/8 macOS 11.6
Who says what can't happen? Malware is always a threat this one is just a little more professional looking.
 

CrimsonRequiem


Retired Staff
Joined
Jul 24, 2008
Messages
6,003
Reaction score
125
Points
63
Your Mac's Specs
MBP 2.3 Ghz 4GB RAM 860 GB SSD, iMac 3.4 GHz Intel Core i7 32GB RAM, Fusion Drive 1TB
Who says what can't happen? Malware is always a threat this one is just a little more professional looking.

It's not just professional looking it's also pretty convincing as legit.
 
Joined
May 14, 2009
Messages
2,052
Reaction score
136
Points
63
Location
Near Whitehorse, Yukon
Your Mac's Specs
2012 MBP i7 2.7 GHz 15" Matte - 16 GB RAM - 120 GB Intel SSD - 500 GB DataDoubler Mac OS 10.9
I'm still waiting for this to install itself on my machine, so I can look at it's inner workings :D
 
Joined
Sep 30, 2007
Messages
9,962
Reaction score
1,235
Points
113
Location
The Republic of Neptune
Your Mac's Specs
2019 iMac 27"; 2020 M1 MacBook Air; macOS up-to-date... always.
I recall reading a few weeks ago that an AV vendor said there was evidence that malware writers had finished constructing a development kit for writing malware for OS X and a major assault was imminent. After all these years of crying wolf, it looks like they were actually right. This stuff is here, it's real, and it's here to stay.
 
Joined
Feb 1, 2011
Messages
4,424
Reaction score
2,130
Points
113
Location
Sacramento, California
Some feedback from someone within the Mac security industry:

"First let me say that the only information I have is based on the Intego analysis that was published. Neither I nor any of the Mac forensic analysts I know have been able to get our hands on this version.
...

"If you are not running as Admin then it won't install without a password. If you are an Admin then you must click on the installer's "Continue..." button once it launches and probably the "Install" button after that, but no password is required."

So, it may be that this version of Mac Defender isn't currently out in the wild.

It also appears that, even though it doesn't require a password to install, some volitional human involvement is still required for it to install.
 

robduckyworth


Retired Staff
Joined
Jan 4, 2011
Messages
2,971
Reaction score
109
Points
63
Location
Reading, UK
Your Mac's Specs
15" MBP, 2.5GHz i7, 750GB, 6770M 1GB, iPad 3, iPhone 4, custom PC
I'm still waiting for this to install itself on my machine, so I can look at it's inner workings :D

just do a google image search for "Osama bin Laden", im sure you will get it soon enough ;)
 

dtravis7


Retired Staff
Joined
Jan 4, 2005
Messages
30,133
Reaction score
703
Points
113
Location
Modesto, Ca.
Your Mac's Specs
MacMini M-1 MacOS Monterey, iMac 2010 27"Quad I7 , MBPLate2011, iPad Pro10.5", iPhoneSE
just do a google image search for "Osama bin Laden", im sure you will get it soon enough ;)

Is that for real? Search for that and you will find that new malware?
 

bobtomay

,
Retired Staff
Joined
Dec 22, 2006
Messages
26,561
Reaction score
677
Points
113
Location
Texas, where else?
Your Mac's Specs
15" MBP '06 2.33 C2D 4GB 10.7; 13" MBA '14 1.8 i7 8GB 10.11; 21" iMac '13 2.9 i5 8GB 10.11; 6S
Well, I just went through about 100 of them, clicking at random. Found nothing.

(I think it would be great if Intego was caught in a hoax. Not sayin' it is, but... I want to see what will install without user input myself.)
 

dtravis7


Retired Staff
Joined
Jan 4, 2005
Messages
30,133
Reaction score
703
Points
113
Location
Modesto, Ca.
Your Mac's Specs
MacMini M-1 MacOS Monterey, iMac 2010 27"Quad I7 , MBPLate2011, iPad Pro10.5", iPhoneSE
Well, I just went through about 100 of them, clicking at random. Found nothing.

(I think it would be great if Intego was caught in a hoax. Not sayin' it is, but... I want to see what will install without user input myself.)

That was why I asked Robert before I wasted time with it! :D

Not feeling well tonight. Inner Ear acting up for the first time in over 3 months.

kind of wanted to see what it does.
 

robduckyworth


Retired Staff
Joined
Jan 4, 2011
Messages
2,971
Reaction score
109
Points
63
Location
Reading, UK
Your Mac's Specs
15" MBP, 2.5GHz i7, 750GB, 6770M 1GB, iPad 3, iPhone 4, custom PC
Is that for real? Search for that and you will find that new malware?

well, the youtube video i watched where the guy was looking at mac defender (i think i linked it earlier in this post, or a similar one) and that was how he managed to get it anyway. maybe google has refined the search now.

http://www.youtube.com/watch?v=L6cvUY4CGp0
 
Joined
Oct 27, 2002
Messages
13,172
Reaction score
348
Points
83
Location
Cleveland, Ohio
Your Mac's Specs
MacBook Pro | LED Cinema Display | iPhone 4 | iPad 2
Cue the fanboys...3...2...1. :)
 
Joined
Mar 17, 2009
Messages
3,626
Reaction score
111
Points
63
Your Mac's Specs
2018 15" MBP, 2019 11" iPad Pro, iPhone 11 Pro
Ok, so it self-installs without your password.
Then what happens? It doesn't do anything malicious to your Mac, does it? I thought the purpose was to solicit your credit card info when it scares you into purchasing. Or did things change with this new version?
I was going to warn my wife (not the most tech-savvy person) if it pops up to just close the window with command+W or quit Safari with command+Q, then come tell me so I can delete it. I wonder if that strategy is still sufficient...
 
Joined
Oct 10, 2004
Messages
10,345
Reaction score
597
Points
113
Location
Margaritaville
Your Mac's Specs
3.4 Ghz i7 MacBook Pro (2015), iPad Pro (2014), iPhone Xs Max. Apple TV 4K
That's my question. If it installs it would likely have to show some sort of an installation dialoge as indicated in a previouse post in this thread. So if one cancels the install process, assuming one can, then it shouldn't install. Even if it does, what does it do once it's there?
 
Joined
Apr 26, 2008
Messages
2,963
Reaction score
120
Points
63
Location
Belgium
Your Mac's Specs
iPad Pro 12.9 latest iOS
It will launch an installer and wait for the user to click " Continue ".
The next step usually is to ask for your password .... that step will be skipped.
So if you quit the installer and not click " continue " on the first dialogue you are good.
Go into the download folder and delete the bloody thing.

After that, cancel your internet subscription :)

Cheers ... McBie
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top