A decade-old Windows malware trojan wormed its way into the macOS ecosystem, complete with a signed (likely stolen) Apple developer certificate. The exploit appears as an Adobe Flash Player installer. Once permission is granted, it hides itself deep inside macOS folders. Its certificate has already been revoked by Apple, but it's good to be aware of your enemies.
According to Fox-IT, Snake, a malware framework that has been infecting Windows software since 2008, and more recently Linux, is now targeting Mac.
The DMG for Flash will only 'show up' on your desktop if you download it. That can happen when you click on a link disguised as a video, or an image, but Adobe doesn't download them automatically. If your Flash Player is up to date, you can delete any DMG that does download. You don't need it.
Now, Fox-IT has identified a version of Snake targeting Mac OS X.As this version contains debug functionalities and was signed on February 21st, 2017 it is likely that the OS X version of Snake is not yet operational.Fox-IT expects that the attackers using Snake will soon use the Mac OS X variant on targets. How to download iphone apps on mac.
Snakes are dangerous and here's why
Similar to the Dok trojan that we heard about earlier this week, Snake popped up with an authenticated developer certificate, which means the Mac's built-in security system, Gatekeeper, would consider it legit and allow the installation process to complete.
It's important to note that Apple has already revoked this fake or stolen developer certificate, so Gatekeeper will block it. However, there is still a slight chance of someone downloading Snake by accident if they've found it through dubious channels. Malwarebytes explains:
Fortunately, Apple revoked the certificate very quickly, so this particular installer is no further danger unless the user is tricked into downloading it via a method that doesn't mark it with a quarantine flag (such as via most torrent apps).
How Snake slithers into your Mac
Just like most malware attacks, Snake doesn't just magically appear on your Mac one day. There isn't someone shooting corrupted files through your ethernet cable directly into your software. Snake has to be welcomed into your operating system by you.
Think of it is a vampire. If you don't invite it into your home, it can't attack you.
The file, named Install Adobe Flash Player.app.zip, will appear to be an Adobe Flash installer (Say what you will about Flash, but there are still a lot of people that have to use it for school or work). From Malwarebytes:
If the app is opened, it will immediately ask for an admin user password, which is typical behavior for a real Flash installer. If such a password is provided, the behavior continues to be consistent with the real thing.
Interestingly, once the installation is complete, Flash is actually installed on the Mac, making it even more difficult to tell that it's a trojan.
How you can protect yourself against SnakeAdobe Flash Player.dmg Virus
As noted above, the fake/stolen developer certificate that allowed Snake to get a pass from Gatekeeper has already been revoked, so it's likely that, even if you download the zip file and try to open the app, your built-in security program will say, 'Nope Dope!'
But to refresh best practices, if you receive an email with an attachment at all, do some due diligence to make sure it's from a legitimate source. Check the sender address to make sure it is from an address you recognize. Sims 3 demo mac download. Crypto key generate rsa command reference. Click on the sender's name to view the email address it was sent from to make sure it's not a spoofed email. If you're still unsure, confirm with the sender by texting, calling or sending a separate email asking if the attachment is legit.
Specific to the Snake trojan, avoid downloading any zip files with the name Install Adobe Flash Player.app.zip.
What to do if Snake already bit you
Do you like my snake puns? Mac and safari cleaner.
If you think you might have managed to accidentally install the Snake trojan onto your Mac, you can find and delete the following files:
Next, delete the stolen/fake signed Apple Developer certificate.
Lastly, change your administrator password to ensure that you're backdoor is rekeyed so the hackers can't get back in.
Flash Player.dmg Virus Removal MacRemember best practices for staying safe
It is unlikely, at this point, that Snake will slither through your Mac's backdoor. For one, Apple has revoked the certificate, which makes it nearly impossible to make it through the installation process without you knowing about it.
To reiterate, don't open attachments from unknown sources. Double check the sender email address to make sure it is not spoofed. Don't open suspicious-looking files or give administrator permission to unknown programs. You can protect yourself from attacks if you stay safe.
Flash Player Dmg Virus Mac
If you do end up with malware on your Mac, take a moment to relax and know that everything will be O.K. You can remove malware on your own, but if it seems too difficult for you to tackle, you can talk to Apple support. Someone will be able to help you.
MacBook ProMainApple ArcadeSTELA for Apple Arcade is a shallow, sadistic, totally fun gameAdobe Flash Player Dmg Virus Mac
Free movie downloads app for mac. Can you outrun killer dark shadows? Take leaps of faith into the unknown? Traverse a world where nothing is what it seems? STELA will test your mettle.
Adobe Flash Player Dmg Virus Mac
Adobe Flash Player for Mac is the standard for delivering high-impact, rich Web content. Designs, animation, and application user interfaces are deployed immediately across all web browsers and platforms, attracting and engaging users with rich Web experience.
Adobe Flash Player for Mac supports several data formats including AMF, SWF, XML and JSON. The multimedia formats which are supported by Flash Player include MP3, FLV, JPEG, GIF, PNG and RTMP. The other features which are supported include accelerated graphics rendering, multithread video decoding and webcam support for StageVideo. Adobe Flash Player for Mac also enables greater privacy controls, utilizing protected HTTP Dynamic Streaming (HDS). Installed on more than 1.3 billion systems, Flash Player is the standard for delivering high-impact, rich Web content. Features and Highlights Staying Secure Ensure your Flash Player for Mac installation is secure and up to date. Simply select 'Allow Adobe to install updates' during the installation process or choose this option anytime in the Flash Player control panel. Gaming Take your gaming to the next level with Flash Player's incredible Stage 3D graphics. Smooth, responsive, and incredibly detailed games are a click away. It even added support for game controllers so come get your game on! High Performance Experience hardware accelerated HD video with perfect playback using Flash Player for Mac. Recent improvements allow supported Flash content and games to continue to deliver responsive feedback even when your CPU is maxed. Note: Requires Intel Core Duo or faster processor. If you are using the Google Chrome browser, Adobe® Flash® Player is built-in but has been disabled. To enable Flash Player, follow the steps in this TechNote. Comments are closed.
|
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |