Search Results for:

XcodeSpy Mac Malware Targets Developers

XcodeSpy Mac Malware Targets Developers

XcodeSpy is macOS malware that can install a persistent backdoor on a Mac. In this article, we’ll explain what it is, how it works, and how you can detect it!

March 25, 2021 • 7 min read
Checklist 223: Visiting Clubhouse and Revisiting App Privacy Labels

Checklist 223: Visiting Clubhouse and Revisiting App Privacy Labels

If you spend any time on the socials, you’ve heard people talk about Clubhouse. It’s been around for close to a year, though it’s really taken off over the past few months. We’ll look at its safety, then look at Privacy Labels with Clubhouse as a sort of yardstick.

Trouble in the Clubhouse?

Clubhouse is a new social media platform that’s drawing all kinds of attention. At the moment, it’s still in beta testing, and is only available as an iOS app.

So what does Clubhouse do? It’s actually pretty simple. The app …

March 21, 2021 • 4 min read
Crisis

Crisis

also known as OSX/Morcut

Type:
Trojan Horse

Platform:
Mac OS X

Last updated:
02/09/16 9:14 pm

Threat Level:
High

Description

Crisis is a Trojan horse that creates a backdoor on infected systems. Also known as Morcut, Crisis was first discovered in 2012, with subsequent variants appearing in the years to follow.

Crisis comes in the form of an illegitimate Adobe Flash Player installer. If installed, Crisis takes steps to achieve persistence (the ability to survive reboots), and then performs several actions, the nature of which depends on whether or not the Trojan was launched with administrative permissions. On a system which …

March 6, 2021 • 2 min read
Conduit

Conduit

Type:
Adware

Platform:
Mac OS X

Last updated:
02/09/16 9:14 pm

Threat Level:
High

Description

Conduit is adware. Conduit was a platform that could be used to create custom toolbars — meant to be installed as browser extensions — that were ostensibly aimed helping web publishers market to their audiences more effectively. However, Conduit had a number of behaviors that are classified as malicious: It would make unauthorized changes to a user’s web browser, including changes to the home page, new tab page, and search engine.

Conduit’s illegitimate search engine, search.conduit.com, posed a clear privacy threat, since it collected highly …

March 6, 2021 • 2 min read
CoinThief

CoinThief

also known as OSX/StealBit

    • Type:
    • Trojan Horse
    • Platform:
    • Mac OS X
    • Last updated:
    • 01/18/23 6:40 pm
    • Threat Level:
    • High

Description

CoinThief is a trojan horse that steals Bitcoins.

CoinThief Threat Removal

MacScan can detect and remove CoinThief Trojan Horse from your system, as well as provide protection against other security and privacy threats. A 30-day trial is available to scan your system for this threat.

Download MacScan

March 6, 2021 • 1 min read
ClickAgent

ClickAgent

also known as OSX/ClickAgent.FLA

Type:
Adware

Platform:
Mac OS X

Last updated:
02/09/16 9:14 pm

Threat Level:
High

Description

ClickAgent is adware. It masquerades as a Flash Player installer and may be found on various websites, especially filesharing and adult websites.

When ClickAgent was discovered in August 2013, it had been signed with an actual Apple Developer ID. If a user installs it, it will be added as an extension to their web browser — Safari, Chrome, or Firefox — and begin injecting ads into any website that the user visits. Some of these ads may be inappropriate or pornographic in …

March 6, 2021 • 2 min read
ChatZum

ChatZum

Type:
Adware

Platform:
Mac OS X

Last updated:
02/09/16 9:14 pm

Threat Level:
High

Description

ChatZum is adware. It most often makes its way onto a Mac during the installation of another, legitimate program such as VLC or UnRarX. Although these applications in themselves are not malicious, and are not affiliated with the malware’s authors, the installer packages that bundle them together with the ChatZum adware are. Users are given the option to opt out of installing ChatZum by the installer program; however, ChatZum components are nevertheless installed on their computers even if they opt out.

Once installed on a …

March 6, 2021 • 1 min read
CallMe

CallMe

Type:
Trojan Horse

Platform:
Mac OS X

Last updated:
04/02/16 10:02 am

Threat Level:
High

Description

CallMe is a Trojan horse that targets Tibetan activist organizations. The Trojan infects its target through a malicious Microsoft Word (.doc) file, exploiting an older Word vulnerability cataloged as CVE-2009-0563.

Once active, CallMe is able to run commands on the infected system; however, it only takes a limited number of actions using these permissions. The Trojan attempts to connect to a command and control server; creates a copy of the user’s contact list for the malware authors to access remotely; and establishes a …

March 6, 2021 • 2 min read
Bundlore

Bundlore

also known as Buca, Not-a-virus:HEUR:AdWare.OSX.Bnodlero.x

    • Type:
    • Adware
    • Platform:
    • Mac OS X
    • Last updated:
    • 01/17/23 11:13 pm
    • Threat Level:
    • High

Description

Bundlore is adware.

Bundlore Threat Removal

MacScan can detect and remove Bundlore Adware from your system, as well as provide protection against other security and privacy threats. A 30-day trial is available to scan your system for this threat.

Download MacScan

March 6, 2021 • 1 min read
BlackHoleRAT

BlackHoleRAT

Type:
Trojan Horse

Platform:
Mac OS X

Last updated:
04/02/16 7:14 am

Threat Level:
High

Description

BlackHoleRAT is a Trojan horse that allows remote access by malicious third parties to an infected computer. Early versions of the Trojan were relatively unsophisticated and seemed to be intended as proof of concept, but subsequent, better-developed variants were soon discovered — and these were being offered for distribution.

BlackHoleRat is able to carry out a range of malicious actions on an infected machine, including the following: It can request an administrator password and store it to a file, execute shell scripts, turn the …

March 6, 2021 • 1 min read
BackTrack

BackTrack

Type:
Keylogger

Platform:
Mac OS X

Last updated:
02/09/16 9:14 pm

Threat Level:
High

Description

BackTrack is a keylogger. It is marketed as a data recovery tool designed to help users in the event of an application crash, but like all keystroke logging software, it can also be used to record the activity of any user working on the computer on which it is installed.

BackTrack captures all keystrokes — with the exception of passwords — and saves them in an SQLite database file along with relevant metadata. In addition to what was typed, the program also records the application …

March 6, 2021 • 2 min read
BPK

BPK

also known as BlazingToolsPerfectKeylogger, PerfectKeyloggerLite

    • Type:
    • Keylogger
    • Platform:
    • Mac OS X
    • Last updated:
    • 06/08/21 9:05 pm
    • Threat Level:
    • High

Description

BPK is a keylogger.

BPK Threat Removal

MacScan can detect and remove BPK Keylogger from your system, as well as provide protection against other security and privacy threats. A 30-day trial is available to scan your system for this threat.

Download MacScan

March 6, 2021 • 1 min read
Award

Award

Type:
Keylogger

Platform:
Mac OS X

Last updated:
02/09/16 9:14 pm

Threat Level:
High

Description

Award is a keylogger. Like all keyloggers, it can be used to monitor the activity of any system on which it is installed.

Award allows the administrator to monitor keystrokes, clipboard content, and app usage. The keylogger can also take screenshots, either at set intervals or whenever a specific event (like a mouse click) occurs. Data is collected into log files which are then delivered via email to whoever controls the software.

Unlike other, more fully-featured keyloggers and spyware, Award does not permit the monitoring of …

March 6, 2021 • 2 min read