Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Nearly 30,000 Macs reportedly infected with mysterious malware
#11
I’m having deja vu :hamsterdance:
Reply
#12
More... https://www.macrumors.com/2021/02/20/m1-...w-malware/

- Look for a process that appears to be PlistBuddy executing in conjunction with a command line containing the following: LaunchAgents and RunAtLoad and true. This analytic helps us find multiple macOS malware families establishing LaunchAgent persistence.
- Look for a process that appears to be sqlite3 executing in conjunction with a
command line that contains: LSQuarantine. This analytic helps us find multiple macOS malware families manipulating or searching metadata for downloaded files.
- Look for a process that appears to be curl executing in conjunction with a command line that contains: s3.amazonaws.com. This analytic helps us find multiple macOS malware families using S3 buckets for distribution.
Reply
#13
In 2020, Apple shipped 23,000,000 Macs.
Reply
#14
C(-)ris wrote:
And this is why I don't give any users Admin privileges on their Macs. Even the IT support staff have to use a different admin account to make changes, their normal user is just a standard user.

Amen...
Wish I could explain this to the new boss!
Reply
#15
Paul F. wrote:
[quote=C(-)ris]
And this is why I don't give any users Admin privileges on their Macs. Even the IT support staff have to use a different admin account to make changes, their normal user is just a standard user.

Amen...
Wish I could explain this to the new boss!
I am fortunate to work under people who think rationally and understand valid concerns and risk mitigation techniques. I cannot even fathom giving anyone admin rights in an environment with vast amounts of PII, especially PII of a minor.
Reply
#16
Ammo wrote:
No discussion about removing this threat. Can we assume nothing can be done about at this point?

Malwarebytes will find and I think they quarantine it. They were instrumental in identifying it.

Not a lot of info from them on the subject, but this thread seems to indicate that they've got a handle on it.

https://forums.malwarebytes.com/topic/27...nt-1440442
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)