• This forum is for posting news stories or links from rumor sites. When you start a thread, please include a link to the site you're referencing.

    THIS IS NOT A FORUM TO ASK "WHAT IF?" TYPE QUESTIONS.

    THIS IS NOT A FORUM FOR ASKING QUESTIONS ABOUT HOW TO USE YOUR MAC OR SOFTWARE.

    This is a NEWS and RUMORS forum as the name implies. If your thread is neither of those things, then please find the appropriate forum to ask your question.

    If you don't have a link to a news story, do not post the thread here.

    If you don't follow these rules, then your post may be deleted.

Warning: New Mac OS X Spyware - OSX/OpinionSpy

cwa107


Retired Staff
Joined
Dec 20, 2006
Messages
27,042
Reaction score
812
Points
113
Location
Lake Mary, Florida
Your Mac's Specs
14" MacBook Pro M1 Pro, 16GB RAM, 1TB SSD
Sad news today:

Intego Security Memo - OSX/OpinionSpy Spyware Installed by Freely Distributed Mac Applications

Looks like this is actually being bundled in with legit OS X software as downloaded from several resources like MacUpdate, Softpedia and VersionTracker. No specific products are named, but apparently the payload is downloaded and installed during the program installation process.

Now, it does request administrator credentials to be installed, so experienced users should be undeterred, but we need to get the word out on this one.
 
Joined
Apr 9, 2009
Messages
2,073
Reaction score
68
Points
48
Location
Ithaca NY
Your Mac's Specs
13 inch alMacBook 2GHz C2D 4G DDR3, 1.25GHz G4 eMac
I read that earlier, and then I was like, "wait... it's just another malware piece posing as a codec. Doh."

lol. So yes, continue to use common sense and all will be well.
 
OP
cwa107

cwa107


Retired Staff
Joined
Dec 20, 2006
Messages
27,042
Reaction score
812
Points
113
Location
Lake Mary, Florida
Your Mac's Specs
14" MacBook Pro M1 Pro, 16GB RAM, 1TB SSD
This is a bit more significant as it's being distributed through a number of different popular download sites. It's also bundled in with completely legal (i.e. non-pirated) screensavers and a functional video converter. I would consider it a non-issue, but it's no longer safe to point people to Apple's third party download site, MacUpdate, Softpedia, and VersionTracker, which are normally pretty good sources. This software is distributed by all of them.

There is no warning for the user, other than giving them a misleading statement about joining a market research survey (which should tip most seasoned users off), but nonetheless, it represents a much greater threat than those that were bundled with pirated Apple software and porn sites.
 

chscag

Well-known member
Staff member
Admin
Joined
Jan 23, 2008
Messages
65,248
Reaction score
1,833
Points
113
Location
Keller, Texas
Your Mac's Specs
2017 27" iMac, 10.5" iPad Pro, iPhone 8, iPhone 11, iPhone 12 Mini, Numerous iPods, Monterey
It does more than pose itself as a codec. According to the writeup by Intego, you can actually download this malware along with legitimate software from sites such as Mac Update and SoftPedia plus you don't know you've downloaded it. That's what makes this type of malware dangerous.

Having said that, we have to remember the folks who put out the security warning are also one of the largest sellers of AV and anti-spyware protection for the Mac. I noticed their basic package for the Mac is $49.95 for one year of definitions and protection.

Regards.
 
Joined
Apr 9, 2009
Messages
2,073
Reaction score
68
Points
48
Location
Ithaca NY
Your Mac's Specs
13 inch alMacBook 2GHz C2D 4G DDR3, 1.25GHz G4 eMac
Yea, I figured most users could display some semblance of common sense, but I guess that is too much to ask these days. It's not the 90s anymore, people on computers aren't all the geeky scientific type anymore.
 
Joined
Nov 28, 2007
Messages
25,564
Reaction score
486
Points
83
Location
Blue Mountains NSW Australia
Your Mac's Specs
Silver M1 iMac 512/16/8/8 macOS 11.6
It requires installation as an application 'PremierOpinion' and reasonable precautions will prevent its installation. One wonders how much innocent information is purveyed by AV software dealers in their $49.95 p.a.?

The Mac Security Blog Preliminary List of Applications that Install OSX/OpinionSpy Spyware

Thanks cwa107 for the heads-up on this. No doubt the trumpets will start blaring about a Mac OS X virus. One question ~ does anyone actually use the list of applications referred to in the above link?
 
Joined
Apr 26, 2008
Messages
2,963
Reaction score
120
Points
63
Location
Belgium
Your Mac's Specs
iPad Pro 12.9 latest iOS
Hmmmm. so far only Intego is touting about it, but vigilance is the key word.

As a suggestion, I believe it is time to consider changing the name of the sticky on " The official Mac Antivirus and Firewall FAQ " to something that is suitable for the new era.

I consider this malware nothing more than a feeler to sense the water, and to be honest, the concept is nothing spectacular ... it is all plain simple stuff.
The fact how it goes about installing itself is the interesting part ... and believe me, it works. ( for the lack of a better word -_- )

Cheers ... McBie
 
Joined
Jan 27, 2007
Messages
5,658
Reaction score
159
Points
63
Location
*Brisvegas*
Your Mac's Specs
17 inch 2 GHz C2D imac (5,1) with 3GB DDR2 RAM, X1600 (128MB memory) GPU - OSX 10.6.3
Having said that, we have to remember the folks who put out the security warning are also one of the largest sellers of AV and anti-spyware protection for the Mac. I noticed their basic package for the Mac is $49.95 for one year of definitions and protection.

Seems someone's trying to get more sales.
 
Joined
Jan 17, 2010
Messages
1,466
Reaction score
47
Points
48
Your Mac's Specs
2.8 GHz 15" MacBook Pro OS X 10.7.x & some old Macs
It doesn't matter whether a person is using Mac or Windows. The biggest problem is some people are not aware of what they are doing. Even if you have an anti-virus program, it doesn't mean that you can safely do whatever you want because it's better to not get infected in the first place and not all viruses have known cures as of yet.

Part of the reason why viruses are so widespread on Windows is because people don't practice safe habits. Before I switched to Mac I've only had about 1-2 Windows viruses found on my Windows computer over a span of about 20 years. I didn't install them but was able to find them beforehand.

Since many people don't practice good safe computer habits, I still recommend anti-virus for Windows users. Although that sometimes creates the problem because people falsely think they are immune to all viruses and other problems because they have an anti-virus software installed. I think if more people feared viruses they wouldn't be installing so much random junk from the internet or from their friends. Just because your friend has installed it doesn't me that he/she isn't infected with something without knowing it.
 
Joined
Mar 30, 2004
Messages
4,744
Reaction score
381
Points
83
Location
USA
Your Mac's Specs
12" Apple PowerBook G4 (1.5GHz)
Several developments:

1. Intego briefly released a list of products that include this malware. It consisted of
  • Screensavers from some no-name Chinese company
  • A no-name flash-to-mp3 converter

That's it.

2. MacUpdate and Versiontracker pulled the listings for these apps as soon as the list was made public.

3. Intego promptly removed said list from its site this morning, while updating the warning

So, yeah. Better run out and buy a copy of whatever Intego's selling right friggin' now! It's the only way to be safe!
 
Joined
Oct 10, 2004
Messages
10,345
Reaction score
597
Points
113
Location
Margaritaville
Your Mac's Specs
3.4 Ghz i7 MacBook Pro (2015), iPad Pro (2014), iPhone Xs Max. Apple TV 4K
I thought the exact same thing. Small number of Apps with the issue so leys hype it and sell some software!
 

bobtomay

,
Retired Staff
Joined
Dec 22, 2006
Messages
26,561
Reaction score
677
Points
113
Location
Texas, where else?
Your Mac's Specs
15" MBP '06 2.33 C2D 4GB 10.7; 13" MBA '14 1.8 i7 8GB 10.11; 21" iMac '13 2.9 i5 8GB 10.11; 6S
Thanks tech - I was looking all over for some list of the supposed software this thing infects.

Reading their little paper makes you wanna run to the hills and pull evey machine you have off the net. At this point, sorry, but I have to wonder if Intego didn't hire the chinese company that put the thing in their own software.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top