Skip to main content

Apple to directly combat MacDefender scareware

Mac-OS-X-10.6-Snow-Leopard
Image used with permission by copyright holder

In an unusual move, Apple has announced that it will be releasing an update to its Mac OS X operating system that will directly detect and remove the MacDefender malware/phishing scam that has been targeting Mac OS X. Apple says the update will be available “in the coming days,” and in the meantime has posted instructions for users to manually remove MacDefender and its variants.

Although MacDefender popped up earlier this month, it’s only in the last few weeks that the scareware seems to have gained any real momentum in the Macintosh world. The MacDefender malware isn’t a worm or virus that spreads on its own between computers; instead, the scam directs Mac users to Web sites that tell them their computer is infected, and the problem can be solved by downloading specialized software—usually dubbed MacDefender, MacSecurity, or MacProtector—to solve the non-existent problem. Once users download the software, it attempts to extort users for credit card information to “fix” their computers. This sort of scareware scam is all-to-familiar to Windows users, but essentially unheard-of in the Macintosh community.

Although Apple has some rudimentary malware protection in Mac OS X—and has added new signatures from time to time—Apple’s announcement that it will be issuing an update to combat MacDefender is a significant step for the company. Although Apple routinely updates Mac OS X to include security fixes, this is the first time in recent memory Apple has updated Mac OS X to combat a specific threat “in the wild.” Apple has not announced what versions of Mac OS X it plans to update: certainly the current Mac OS X “Snow Leopard” will receive an update, but there’s no word on whether Apple will extend protection back to Mac OS X 10.5 “Leopard” or earlier.

Apple’s manual instructions for removing the malware essentially amount to using Mac OS X’s built-in Activity Monitor application to shut down processes associated with MacDefender, then deleting its files.

Macintosh users have long enjoyed the near-total absence of malware, as creators of worms, trojans, viruses, and other malware have traditionally focused on Windows due to its dominant share of the PC market. However, as Apple’s market share and profile have risen, the company and its products are now apparently beginning to attract the attention of malware writers—and years (make that decades) of relative safety may have instilled a sense of complacency amongst Macintosh users that could leave many unprepared to deal with significant malware. At least, when significant malware arrives, and MacDefender doesn’t qualify. The scareware isn’t exploiting any technical flaw in Mac OS X: it’s simply tricking users and preying upon their fears, and there isn’t platform or security program in the world that can protect solve that problem.

Editors' Recommendations

Topics
Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
This Mac malware can steal your credit card data in seconds
Apple's Craig Federighi speaking about macOS security at WWDC 2022.

Despite their reputation for security, Macs can still get viruses, and that’s just been proven by a malicious new Mac malware that can steal your credit card info and send it back to the attacker, ready to be exploited. It’s a reminder to be careful when opening apps from unknown sources.

The malware, dubbed MacStealer, was discovered by Uptycs, a threat research firm. It hoovers up a wide array of your personal data, including the iCloud Keychain password database, credit card data, cryptocurrency wallet credentials, browser cookies, documents, and more. That means there’s a lot that could be at risk if it gains a foothold on your Mac.

Read more
This devious scam app proves that Macs aren’t bulletproof
A close-up of a MacBook illuminated under neon lights.

Pirated software can cause all kinds of headaches, but Mac users might have thought themselves largely immune thanks to Apple’s reputation for solid security. Yet, that complacency could prove quite problematic, as a new strain of nearly undetectable malware has shown.

According to research from security firm Jamf Threat Labs, pirated versions of Apple’s Final Cut Pro moviemaking app have been modified to contain cryptojacking payloads. When installed, the app starts using your Mac to mine the Monero cryptocurrency behind your back, potentially slowing down your machine as system resources are illegitimately gobbled up.

Read more
This major Apple bug could let hackers steal your photos and wipe your device
A physical lock placed on a keyboard to represent a locked keyboard.

Apple’s macOS and iOS are often considered to be more secure than their rivals, but that doesn’t make them invulnerable. One security team recently proved that by showing how hackers could exploit Apple’s systems to access your messages, location data, and photos -- and even wipe your device entirely.

The discoveries were published on the blog of security research firm Trellix, and will be of major concern to iOS and macOS users alike, since the vulnerabilities can be exploited on both operating systems. Trellix explains that Apple patched the exploits in macOS 13.2 and iOS 16.3, which were released in January 2023, so you should update your devices as soon as you can.

Read more