24 C
Jaipur
Wednesday, October 21, 2020

Beware of New Mac Malware Spreading via Poisoned Search Results

Must read

telia company: Telecom operator Telia core profit tops forecast – Latest News

STOCKHOLM: Nordic telecom operator Telia Company on Wednesday reported quarterly core earnings ahead of market expectations aided by cost savings and said it had...

DJI Pocket 2 with better camera, audio system launched

DJI has launched the second iteration of the Osmo Pocket called DJI Pocket 2. It’s a stabilised mini camera that can record in...

JioPages: Reliance Jio launches ‘made-in-India’ browser, JioPages: Features and how to download

Reliance Jio has launched a made-in-India browser, JioPages. The company claims that JioPages focusses on data-privacy and gives users full...

This is the only country where Apple has to provide free EarPods with iPhone 12 by law

Apple is no longer providing EarPods and the charging adapter with any of its iPhones. Citing environmental reasons, Apple has trimmed the...

Security researchers discovered a new Mac malware Shlayer spreading through Google poisoned search results. The malware distributed masqueraded as a fake Adobe Flash Player installer (.DMG disk image).

The malware installer and its payload had a 0/60 detection rate among all antivirus engines on VirusTotal.

Mac Malware Shlayer

Intego researchers observed this newly updated Shlayer malware delivered as a Trojan horse file (.DMG disk image) masqueraded as an Adobe Flash Player.

Once the user installs the malicious Flash Player on Mac machine the image will get the mount and display instructions on how to install it.

“The instructions tell users to first “right-click” on the flash installer and select Open, and then to click Open in the resulting dialog box,” reads Intego blog post.

When the user starts following the instruction to installing the malicious application, the icon looks like a Flash player, but in the background, the bash shell script executed the opening terminal.

The bash script extracts password-protected .zip archive file which has a malicious app bundle, it stores the malicious app into a hidden temporary folder.

The malicious app also downloads the legitimate, Adobe-signed Flash Player installer to trick the user, but the hidden Mac app downloads malicious apps.

“The developers’ decision to hide the Mac .app within a password-protected .zip file, and to hide that within a bash shell script, is a novel idea—and it is also extremely clear evidence that the developers are trying to evade detection by antivirus software.”

“This newly re-engineered malware purports to be a legitimate Flash Player installer, but it can surreptitiously download and install additional unwanted packages containing adware or spyware.”

Shlayer malware believed to be the most widespread macOS threat, earlier this February Carbon Black researchers spotted new Shlayer malware targeting 10.10.5 up to 10.14.3.

Adobe already announced that they will stop distributing and updating Flash Player after 31 December 2020 (“EOL Date”).

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

Blue Mockingbird Hacker Group Attack Windows Machines at Multiple Organizations to Deploy cryptocurrency-mining Malware

Does Your Mac Need Antivirus Protection? Here’s What You Need to Know

Source link

- Advertisement -

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article

telia company: Telecom operator Telia core profit tops forecast – Latest News

STOCKHOLM: Nordic telecom operator Telia Company on Wednesday reported quarterly core earnings ahead of market expectations aided by cost savings and said it had...

DJI Pocket 2 with better camera, audio system launched

DJI has launched the second iteration of the Osmo Pocket called DJI Pocket 2. It’s a stabilised mini camera that can record in...

JioPages: Reliance Jio launches ‘made-in-India’ browser, JioPages: Features and how to download

Reliance Jio has launched a made-in-India browser, JioPages. The company claims that JioPages focusses on data-privacy and gives users full...

This is the only country where Apple has to provide free EarPods with iPhone 12 by law

Apple is no longer providing EarPods and the charging adapter with any of its iPhones. Citing environmental reasons, Apple has trimmed the...

Vivo V20 Pro to launch in India in November, confirms India CEO

Vivo is soon going to launch its Vivo V20 Pro smartphone in India. The confirmation of the India launch of the handset...