[HN Gopher] Mac Malware of 2022
___________________________________________________________________
Mac Malware of 2022
Author : stock_toaster
Score : 61 points
Date : 2023-01-24 20:09 UTC (2 hours ago)
(HTM) web link (objective-see.org)
(TXT) w3m dump (objective-see.org)
| dandongus wrote:
| Perhaps that's not the best place to list the sponsors.
| [deleted]
| brundolf wrote:
| That's... a long list, too long for me to read it all I think.
| Wish there were a summary of general trends/takeaways
| waterhouse wrote:
| ~> p | grep 'Infection Vector' | sort | uniq -c | sort -s
| -rnk1,1 4 Infection Vector: Unknown 3
| Infection Vector: TypoSquatting 1 Infection Vector:
| (likely) Trojanized Disk Images 1 Infection Vector:
| Malicious Ads / Fake Update Prompt 1 Infection Vector:
| Safari Exploit 1 Infection Vector: Supply-chain attack
| 1 Infection Vector: Trojanized Disk Images(?) 1
| Infection Vector: Unknown, possible via infected npm packages
| jsz0 wrote:
| Has anyone seen Mac malware that involves hyjacking
| accessibly/mouse input? I've come across several Macs in the last
| year with mysterious self moving cursors. I don't know what
| benefit there would be for malware to hyjack a mouse cursor so my
| assumption is they simply have hardware problems with their
| trackpads. Makes me paranoid tough.
| 0xCMP wrote:
| If it's a closed laptop sometimes when they get very warm the
| touch pad starts getting activated. At least that is what the
| problem was for me a few years ago with Intel MBPs.
|
| There is an option to disable the track pad when using an
| external keyboard which was the perfect solution.
| duxup wrote:
| Typically random mouse movements are Bluetooth mice people
| forget are connected.
|
| I suggest checking for that/ disable Bluetooth to see what
| happens.
| kitsunesoba wrote:
| Yeah, I'd bet that this is what is happening. A few times in
| the offices of my workplaces I've seen cases of BT keyboards
| and mice randomly reconnecting to Macs they'd been paired
| with at some point in the past (even years back) and causing
| a short bout of chaos.
| varenc wrote:
| I'm doubtful. It's certainly possible for malware to hijack
| mouse/keyboard control, with a local privilege escalation
| exploit, but I'm not sure what the point would be. Escalating
| to mouse/keyboard control is hard and any malware capable of
| doing that likely wouldn't need to.
| LeSaucy wrote:
| Any app that allows accessibility persmissions has access.
| For example, I run a program called "Jiggler" whos job it is
| to jiggle my mouse during work hours as to prevent the teams
| "Away" status.
| btgeekboy wrote:
| I once spent far, far too much time debugging my "broken"
| laptop to realize a book was touching the corner of my external
| trackpad that I wasn't actively using.
| BudaDude wrote:
| Is Clean My Mac X really malware?
| [deleted]
| askiiart wrote:
| Clean My Mac X I could believe, based on its name, to be
| malware.
|
| Sophos, on the other hand...
| sleepybrett wrote:
| I've found CMMX to be fairly useful actually. A lot of
| software in this category can be pretty pestery and
| exploitative but I've been pretty happy with CMMX
| nerdponx wrote:
| > CleanMyMac X is all-in-one package to awesomize your Mac.
| It cleans megatons of junk and makes your computer run
| faster. Just like it did on day one.
|
| Looks like it's badly infected with
| PatronizingPandering.exe... you might need to nuke this one
| from orbit and cut your losses.
| bluetidepro wrote:
| The apps at the top are their sponsors, not the malware.
| However, as someone else pointed out, probably dumb on their
| part to design it that way. haha
___________________________________________________________________
(page generated 2023-01-24 23:01 UTC)