Feeds

New Mac scareware variant installs without password

Welcome to the world, fanbois

Website security in corporate America

Scammers have developed a strain of Mac scareware that avoids the need to trick a mark into entering an administrative password.

Earlier rogue anti-virus strains, such as MacDefender, need permission to run, a hurdle MacGuard neatly sidesteps. MacGuard works on the premise that home users have administrator rights, meaning they don't need to enter the administrator password to install software in the Applications folder.

MacGuard downloads itself into this folder rather than the default download folder. This downloader connects to malicious IP addresses hidden in its own resources folder. The appearance of the malware means that advice to treat all unexpected requests for the administrator password with suspicion becomes moot. "This is not the sky falling, but it does change the game somewhat," writes anti-malware researcher David Harley.

Mac security specialist Intego reports that MacGuard, which it describes as a variant of MacDefender, is being distributed via various portals offering fake security scans. These portals are getting promoted through search engine manipulation. Intego has a write-up of the scam here.

After advising support staff not to help users who might be infected by MacDefender for at least a fortnight, Apple rethought its position and posted an advisory on dealing with the malware on Tuesday. Part of its advice – to cancel the installation process and not to enter admin passwords – has been rendered redundant by the arrival of MacGuard.

Sophos has charted the evolution of Mac-specific malware which it reckons is "advancing fast and taking many cues from the Windows malware scene" in a blog post here. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
'Windows 9' LEAK: Microsoft's playing catchup with Linux
Multiple desktops and live tiles in restored Start button star in new vids
Not appy with your Chromebook? Well now it can run Android apps
Google offers beta of tricky OS-inside-OS tech
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
NHS grows a NoSQL backbone and rips out its Oracle Spine
Open source? In the government? Ha ha! What, wait ...?
Google extends app refund window to two hours
You now have 120 minutes to finish that game instead of 15
Intel: Hey, enterprises, drop everything and DO HADOOP
Big Data analytics projected to run on more servers than any other app
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.