TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

New macOS malware steals info, including a user's entire Keychain database

188 点作者 WallyFunk大约 2 年前

10 条评论

Someone大约 2 年前
This malware gets onto systems 100% through social engineering. It lures users to download the software, run it, ignore the OS warning that the code isn’t signed, and then enter their password.<p>So, what should Apple do in response to such malware? Make it impossible for user code to read the entire keychain, even when running as admin? Containerize macOS more, making it impossible for user programs to access files written by other programs, in the way things work on iOS? Ignore it because, at some point, security becomes the user’s responsibility?<p>If tools like these get popular, I can see them getting blamed whatever they do or don’t do.
评论 #35583230 未加载
评论 #35582031 未加载
评论 #35582224 未加载
评论 #35582045 未加载
评论 #35584962 未加载
评论 #35583390 未加载
评论 #35583309 未加载
评论 #35584920 未加载
评论 #35584303 未加载
评论 #35583376 未加载
评论 #35581997 未加载
hjuutilainen大约 2 年前
&gt; MacStealer being an unsigned DMG file is also a barrier for anyone, especially beginners, attempting to run the program on a modern mac, said Malwarebytes&#x27; Reed. &quot;Its attempt at phishing for login passwords is not very convincing and would probably only fool a novice user. But such a user is exactly the type who would have trouble opening it.&quot;<p>Given the above and the default macOS security configuration, you really have to work your way to get this malware running.
评论 #35582597 未加载
评论 #35582614 未加载
sunshinerag大约 2 年前
Looks like an ad for malwarebytes. Genuine question: how do we know they are NOT in the business of writing the malware themselves
评论 #35584257 未加载
mk89大约 2 年前
I am surprised that this is NEW. I mean, like nobody ever created a stupid program asking the user for the system password and tried to collect sensitive data based on it?<p>OSX Ventura has several guards already against it:<p>- prevent execution of software not downloaded from app store and not from an identified developer (not digitally signed basically). You as a user have to explicitly go to your security settings and enable the app, and then reopen it.<p>- ask explicitly for permissions to give to an app (e.g., X is asking to access the Downloads folder, ...). Maybe in case of Keychain this is not done, which could be something to improve... but even then if the user wants, there will be a &quot;click&quot;.
provenance大约 2 年前
Is the Keychain DB (SQLite) stolen in encrypted form? As I understand, the Keychain DB is stored on the file system, but the DB&#x27;s key is held in the Secure Enclave.
pindab0ter大约 2 年前
Why is it specified (twice!) that the keychain is extracted in it’s base64 encoded form?<p>That seems like an insignificant technical detail to mention, or am I missing something?
can16358p大约 2 年前
So I need to double click an unsigned DMG downloaded most likely from an unreputable source, bypass any security warnings, and then I&#x27;m vulnerable.<p>I wonder how many people got infected in the wild. Also, it&#x27;s any moment that Telegram removes the channel that is used for C&amp;C, making the malware virtually ineffective.
评论 #35584281 未加载
snehk大约 2 年前
This might be a good place to ask: I have Malwarebytes installed but aside from that nothing really. What&#x27;s the recommended software stack to stay as protected as possible?
评论 #35582099 未加载
评论 #35582498 未加载
评论 #35582392 未加载
评论 #35587350 未加载
评论 #35583384 未加载
评论 #35582265 未加载
评论 #35582477 未加载
评论 #35582510 未加载
112233大约 2 年前
Does VirusTotal flag these DMGs?<p>I cannot be the only one basing my decision to run random blob from internet on virustotal output?
phendrenad2大约 2 年前
Crypto is incentivizing a lot of new malware. We&#x27;re getting to see how MacOS fares when faced with real targeted attacks. I feel that in the end, everyone will have to copy the Windows security model, which has had to deal with these attacks for decades.
评论 #35583599 未加载