New 'DOK' Malware targeting MacOS

Raz0rEdge

Well-known member
Staff member
Moderator
Joined
Jul 17, 2009
Messages
15,762
Reaction score
2,100
Points
113
Location
MA
Your Mac's Specs
2022 Mac Studio M1 Max, 2023 M2 MBA
A new twist on the malware landscape that uses legitimate certificates to thwart the built-in protections of macOS. Once installed, the malware will monitor all network traffic and could steal any data it seems useful..

The whole thing, of course, starts with a phishing email relating to taxes (since all of us in the US just filed ours) that fools you into downloading a zip file..

This cannot be stressed enough. Government agencies (regardless of country) don't send you email with random ZIP files about whatever they are responsible for. So the IRS will not email you about taxes. If they want to contact you, they will use a very official letter sent through USPS and nothing else. So, do not click on any of these emails..

Read more: http://www.mactrast.com/2017/04/new-mac-malware-uses-apple-developer-certificate-infect-machines/
 
Joined
May 21, 2012
Messages
10,735
Reaction score
1,188
Points
113
Location
Rhode Island
Your Mac's Specs
M1 Mac Studio, 11" iPad Pro 3rd Gen, iPhone 13 Pro Max, Watch Series 7, AirPods Pro
Thanks for the heads up Ashwin.
 

chscag

Well-known member
Staff member
Admin
Joined
Jan 23, 2008
Messages
65,248
Reaction score
1,833
Points
113
Location
Keller, Texas
Your Mac's Specs
2017 27" iMac, 10.5" iPad Pro, iPhone 8, iPhone 11, iPhone 12 Mini, Numerous iPods, Monterey
I read that this morning in my daily "Macworld Review email letter". This one is a real nasty especially if it gets your permission as Ashwin pointed out. It's bad enough I had to pay the IRS this year, so I can't imagine getting "Phished" by malware pretending to be them. Double whammy!

Be careful out there! ;D
 
OP
Raz0rEdge

Raz0rEdge

Well-known member
Staff member
Moderator
Joined
Jul 17, 2009
Messages
15,762
Reaction score
2,100
Points
113
Location
MA
Your Mac's Specs
2022 Mac Studio M1 Max, 2023 M2 MBA
<Mr. Burns>Excelleeeeent!</Mr. Burns>
 
Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
Nice. Thank you
 

chscag

Well-known member
Staff member
Admin
Joined
Jan 23, 2008
Messages
65,248
Reaction score
1,833
Points
113
Location
Keller, Texas
Your Mac's Specs
2017 27" iMac, 10.5" iPad Pro, iPhone 8, iPhone 11, iPhone 12 Mini, Numerous iPods, Monterey
It's blocked already. You can test for it. In Terminal, enter this

Thanks Jake. Good stuff. :)
 
Joined
Jan 20, 2012
Messages
5,067
Reaction score
429
Points
83
Location
North Carolina
Your Mac's Specs
Air M2 ('22) OS 14.3; M3 iMac ('23) OS 14.3; iPad Pro; iPhone 14
M

MacInWin

Guest
Dave, the fact that the grep returned the string says that you are fine. If it had NOT returned the string name, then your Xprotect would have needed updating.
 
Joined
Feb 1, 2011
Messages
4,424
Reaction score
2,131
Points
113
Location
Sacramento, California
A new twist on the malware landscape that uses legitimate certificates to thwart the built-in protections of macOS. Once installed, the malware will monitor all network traffic and could steal any data it seems useful..

Apple patched the MacOS against this malware before any of us had even heard of it.

OSX.DOC is a Trojan, not a virus. It arrives attached to an e-mail message. It can be completely avoided by not opening any e-mail attachments called “Dokument.zip”. (Or simply not opening any attachments to any e-mails that you aren't expecting or which don't come from someone you know.)

More importantly:
“Apple has already revoked the certificate used to sign the app, so, at this point, anyone who encounters this malware will be unable to open the app and unable to be infected by it.”
https://blog.malwarebytes.com/threat-analysis/2017/04/new-osx-dok-malware-intercepts-web-traffic/
 
Joined
Jan 20, 2012
Messages
5,067
Reaction score
429
Points
83
Location
North Carolina
Your Mac's Specs
Air M2 ('22) OS 14.3; M3 iMac ('23) OS 14.3; iPad Pro; iPhone 14
Dave, the fact that the grep returned the string says that you are fine. If it had NOT returned the string name, then your Xprotect would have needed updating.

Apple patched the MacOS against this malware before any of us had even heard of it.

OSX.DOC is a Trojan, not a virus. It arrives attached to an e-mail message. It can be completely avoided by not opening any e-mail attachments called “Dokument.zip”. (Or simply not opening any attachments to any e-mails that you aren't expecting or which don't come from someone you know.)

More importantly:
“Apple has already revoked the certificate used to sign the app, so, at this point, anyone who encounters this malware will be unable to open the app and unable to be infected by it.”
https://blog.malwarebytes.com/threat-analysis/2017/04/new-osx-dok-malware-intercepts-web-traffic/

Thanks Jake - that was my assumption, especially after Randy's further clarification above. Dave :)
 

Rod


Joined
Jun 12, 2011
Messages
9,690
Reaction score
1,879
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.
Thanks everybody, nice to stay abreast of these things.
 
Joined
May 7, 2010
Messages
982
Reaction score
14
Points
18
Location
UK
Your Mac's Specs
2 iMacsOSX13.6.4;10.13.6;iPhone SE2 17.3.1;SE1 15.8;iPadMini15.8;iPadAir 2 15.8
Yes we have had similar e-mails in UK purporting to come from our equivalent HMRC although none of them has included any attachments. Instead they suggest that the recipient is entitled to a refund etc.
 

Rod


Joined
Jun 12, 2011
Messages
9,690
Reaction score
1,879
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top