MACDefender Poses Malware Threat

Earlier this morning, antivirus software company Intego posted an article detailing a new malware threat for OS X users. This malicious software—masquerading as “MACDefender”—targets users through Safari via SEO poisoning attacks. Essentially when a rigged link is clicked after performing a search, users are redirected to a page containing JavaScript that automatically downloads a compressed file.

This malware presents the greatest threat to users who have enabled the option for their browser to automatically open “safe” files. Upon downloading, the malware will automatically open and infect the machines of any users with this browser configuration. It is worth noting, however, that by default Mac OS X prompts users whenever a downloaded application attempts to open itself or install. If you ever see an application you haven’t explicitly elected to download, deny it permission to open, and under no circumstance provide it your administrator password.

If you have enabled the option for Safari to automatically open downloaded applications, there is a chance—though slim—that your machine has been infected. MACDefender installs silently and with nothing more than a click on a deceitful link. If you believe the malware has been installed on your machine, Mac Rumors recommends taking the following precautions:

  • Open Applications > Utilities > Activity Monitor and quit any processes linked to MACDefender.
  • Delete MACDefender from the Applications folder.
  • Check System Preferences > Accounts > Login Items for suspicious entries.
  • Run a Spotlight search for “MACDefender” to check for any associated files that might still be lingering.

Although these steps will effectively disable and remove MACDefender in the interim, Intego is further investigating the most efficient and complete means of removal. The company will post its findings on its blog shortly. As the number of Mac users who have consciously visited Safari preferences and enabled the “auto open” option are on the lower side, Intego has associated a low threat level with the malware. However, it may behoove you to run—at the very least—a quick Spotlight search for any traces of MACDefender. To be as savvy as possible against attacks such as these in the future, refrain from ever offering a suspicious application your admin password, and keep a regular Time Machine backup.

Similar Posts

  • Appreciating AAPL, again.

    Last week, AAPL was the hot stock after the announcement of Boot Camp. AAPL peaked at $71.94, is now down below $68.00, and…

  • PDF Exploit Patched in iOS 4.0.2

    This time last week, Apple released the second revision to its iOS4 mobile operating system. This incremental update is focused entirely on patching…

  • Back to School with Apple!

    We’re barely past the fourth of July, and parents, teachers, and students are already planning their back-to-school tech purchases. I was glad to…

  • iPad or iDud? Part Two

    When iPad was announced, I was surprised by the extreme negative options of iPad online. “This is Jobs’ biggest miss.” Why is this?…

  • New Colors for the iPod Shuffle!

    Apple has updated the iPod shuffle line with four new colors – pink, green, blue, and orangeish. The original silver color is still…

  • Apple to Stream Today's Keynote Live

    Apple is slated to hold their annual media event this afternoon at the Yerba Buena Center for the Arts in San Francisco. The…