[HN Gopher] Mac Malware of 2022
       ___________________________________________________________________
        
       Mac Malware of 2022
        
       Author : stock_toaster
       Score  : 61 points
       Date   : 2023-01-24 20:09 UTC (2 hours ago)
        
 (HTM) web link (objective-see.org)
 (TXT) w3m dump (objective-see.org)
        
       | dandongus wrote:
       | Perhaps that's not the best place to list the sponsors.
        
         | [deleted]
        
       | brundolf wrote:
       | That's... a long list, too long for me to read it all I think.
       | Wish there were a summary of general trends/takeaways
        
         | waterhouse wrote:
         | ~> p | grep 'Infection Vector' | sort | uniq -c | sort -s
         | -rnk1,1          4 Infection Vector: Unknown          3
         | Infection Vector: TypoSquatting          1 Infection Vector:
         | (likely) Trojanized Disk Images          1 Infection Vector:
         | Malicious Ads / Fake Update Prompt          1 Infection Vector:
         | Safari Exploit          1 Infection Vector: Supply-chain attack
         | 1 Infection Vector: Trojanized Disk Images(?)          1
         | Infection Vector: Unknown, possible via infected npm packages
        
       | jsz0 wrote:
       | Has anyone seen Mac malware that involves hyjacking
       | accessibly/mouse input? I've come across several Macs in the last
       | year with mysterious self moving cursors. I don't know what
       | benefit there would be for malware to hyjack a mouse cursor so my
       | assumption is they simply have hardware problems with their
       | trackpads. Makes me paranoid tough.
        
         | 0xCMP wrote:
         | If it's a closed laptop sometimes when they get very warm the
         | touch pad starts getting activated. At least that is what the
         | problem was for me a few years ago with Intel MBPs.
         | 
         | There is an option to disable the track pad when using an
         | external keyboard which was the perfect solution.
        
         | duxup wrote:
         | Typically random mouse movements are Bluetooth mice people
         | forget are connected.
         | 
         | I suggest checking for that/ disable Bluetooth to see what
         | happens.
        
           | kitsunesoba wrote:
           | Yeah, I'd bet that this is what is happening. A few times in
           | the offices of my workplaces I've seen cases of BT keyboards
           | and mice randomly reconnecting to Macs they'd been paired
           | with at some point in the past (even years back) and causing
           | a short bout of chaos.
        
         | varenc wrote:
         | I'm doubtful. It's certainly possible for malware to hijack
         | mouse/keyboard control, with a local privilege escalation
         | exploit, but I'm not sure what the point would be. Escalating
         | to mouse/keyboard control is hard and any malware capable of
         | doing that likely wouldn't need to.
        
           | LeSaucy wrote:
           | Any app that allows accessibility persmissions has access.
           | For example, I run a program called "Jiggler" whos job it is
           | to jiggle my mouse during work hours as to prevent the teams
           | "Away" status.
        
         | btgeekboy wrote:
         | I once spent far, far too much time debugging my "broken"
         | laptop to realize a book was touching the corner of my external
         | trackpad that I wasn't actively using.
        
       | BudaDude wrote:
       | Is Clean My Mac X really malware?
        
         | [deleted]
        
         | askiiart wrote:
         | Clean My Mac X I could believe, based on its name, to be
         | malware.
         | 
         | Sophos, on the other hand...
        
           | sleepybrett wrote:
           | I've found CMMX to be fairly useful actually. A lot of
           | software in this category can be pretty pestery and
           | exploitative but I've been pretty happy with CMMX
        
           | nerdponx wrote:
           | > CleanMyMac X is all-in-one package to awesomize your Mac.
           | It cleans megatons of junk and makes your computer run
           | faster. Just like it did on day one.
           | 
           | Looks like it's badly infected with
           | PatronizingPandering.exe... you might need to nuke this one
           | from orbit and cut your losses.
        
         | bluetidepro wrote:
         | The apps at the top are their sponsors, not the malware.
         | However, as someone else pointed out, probably dumb on their
         | part to design it that way. haha
        
       ___________________________________________________________________
       (page generated 2023-01-24 23:01 UTC)