Jump to content

New macOS malware exploits old Windows tricks to get into your system

captain_to_fire

Source: The Next Web

 

Quote

While Mac malware tends to be a rather rare occurrence, Ars Technica reports security researchers have discovered two separate, new macOS viruses that rely on old Windows tricks to get into your laptop and steal your data.

One of the attacks, documented by software firm Objective-See, exploits an established Windows technique which hides and executes malicious code using Word document macros.

IMG_5152.PNG

The hack tricks unsuspecting users into opening infected Word documents which subsequently run malicious macros once the file has been loaded. The good thing is that it’s fairly easy to identify infected files prior to opening them.

Anytime you open a Word file containing macros, your device will ask you for permission. Denying permission on its own is enough to prevent the malware from spreading.

But if you click ‘run’, all sorts of bad things could happen: A hacker could spy on you or pull your browsing history, or they could initiate a secondary infection by downloading additional malware.

Before the entire PC Master Race jumps into Apple hate bandwagon again, let's clear things up. This specific malware infection isn't the one usually found in Windows PCs where the infecting agent doesn't need user interaction to compromise the system, this one exploits social engineering in Microsoft Word macros. Just like ActiveX plugins and Browser Helper Objects that took Microsoft years before they ditched it in Microsoft Edge, they can't get away with Macros in Office either. Too bad that macOS's built in Gatekeeper only blocks executable files without Apple's digital signatures, it can't prevent infections via macros. 

 

Malware infections in OS X/macOS isn't something new. Remember the Mac Defender trojan in 2011 that infected a lot of Macs which caused false alerts of malware infection and requires users to pay but laters steals the browser history? I used to believe that the reason why malware infections on a Mac is scarce unlike Windows is because of the market share. Now, I'm doubting that. I hope someone can correct me about this but it seems that crafring a malware us harder on a UNIX kernel used by macOS unlike the plethora of viruses, trojans, and worms built to attack the NT kernel used by Windows. 

 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

My GF got this on a brand new file she made.. trusted or not? .. 

| Intel i5 4670k @ 4.3GHz | XFX RX 480 8 GB | Asus Z87i-Pro | 8.0 GB Kinston DDR3 | Samsung Evo 120GB SSD |

Link to comment
Share on other sites

Link to post
Share on other sites

Will this only be relative if its a downloaded Word document? 

| Intel i5 4670k @ 4.3GHz | XFX RX 480 8 GB | Asus Z87i-Pro | 8.0 GB Kinston DDR3 | Samsung Evo 120GB SSD |

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, OLS said:

Will this only be relative if its a downloaded Word document? 

I don't think so. I think Excel and Power Point files with macros embedded are vulnerable too. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

16 minutes ago, DrMikeNZ said:

Who actually allows and runs macros from unknown sources without reading the code first?

It could come even from people you trust. Let's say a friend with hidden grudge on you sends you an Excel file with a nasty malware embedded as a macro under the pretense that it's a group file for a project. Little did you know as soon as you open the file and said yes to executing macros, it can turn your computer into a zombie. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, hey_yo_ said:

It could come even from people you trust.

If I didn't write the code, then it is unknown to me.

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, DrMikeNZ said:

If I didn't write the code, then it is unknown to me.

I guess if you said no in opening the macro, then you're good. Microsoft Office since version 2010 featured protected view which is like their implementation of User Account Control for office files. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

good thing i don't use ms stuff anymore, such a bad company with awful products and services overall 

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, hey_yo_ said:

It could come even from people you trust. Let's say a friend with hidden grudge on you sends you an Excel file with a nasty malware embedded as a macro under the pretense that it's a group file for a project. Little did you know as soon as you open the file and said yes to executing macros, it can turn your computer into a zombie. 

Yeah... sure.... "friend".

 

I don't know about you, man, but none of my friends would do that. And if they did, they'd never be my friend again. Hell I'd be tempted to report them to the Police, because yeah that's a crime lol.

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

It is true, as far as market share Windows having larger one than Mac by a lot. Reason being that Windows will be way more targeted platform for such.

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

I use linux, libreoffice. I do not think this affects me like 1209353266 other windows viruses LOL

Computer users fall into two groups:
those that do backups
those that have never had a hard drive fail.

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, DrMikeNZ said:

If I didn't write the code, then it is unknown to me.

You are 0.00001% of the userbase. I'm probably not far from not exagerating.

1 hour ago, mate_mate91 said:

I use linux, libreoffice. I do not think this affects me like 1209353266 other windows viruses LOL

 

There's nothing worst then someone who assumes they're safe because they're using X software rather then Y.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, RagnarokDel said:

You are 0.00001% of the userbase. I'm probably not far from not exagerating.

Overexagerating a little. Closer to 0.00000003%

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, dalekphalm said:

Yeah... sure.... "friend".

 

I don't know about you, man, but none of my friends would do that. And if they did, they'd never be my friend again. Hell I'd be tempted to report them to the Police, because yeah that's a crime lol.

I have to deal with deplorable people all the time especially at work. It seems that killing them with kindness isn't working anymore. Who knows? Maybe in the future Microsoft office macros can be used to deliver a nasty crypto-ransomware? 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Dumb question... Can malwarebytes detect this??? 

Also I don't use microsoft suite, should I be worried???? 

If it is not broken, let's fix till it is. 

Link to comment
Share on other sites

Link to post
Share on other sites

56 minutes ago, mrchow19910319 said:

Dumb question... Can malwarebytes detect this??? 

Also I don't use microsoft suite, should I be worried???? 

Probably any AV with heuristics can detect malicious macros so I think malware bytes can remove it. If you no longer use Office, you're good to go. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, mrchow19910319 said:

Dumb question... Can malwarebytes detect this??? 

Also I don't use microsoft suite, should I be worried???? 

You should always be on guard (not worried) about malware when using any piece of software.

Desktop: KiRaShi-Intel-2022 (i5-12600K, RTX2060) Mobile: OnePlus 5T | Koodo - 75GB Data + Data Rollover for $45/month
Laptop: Dell XPS 15 9560 (the real 15" MacBook Pro that Apple didn't make) Tablet: iPad Mini 5 | Lenovo IdeaPad Duet 10.1
Camera: Canon M6 Mark II | Canon Rebel T1i (500D) | Canon SX280 | Panasonic TS20D Music: Spotify Premium (CIRCA '08)

Link to comment
Share on other sites

Link to post
Share on other sites

I know, I know, this could potentially be exploited on another program on macOS.

On the flip side, I wouldn't really blame Apple for this for once. Sure, as I said, you could potentially exploit it some way else, but considering that you basically have to use Microsoft Office for this, I don't know.

Check out my guide on how to scan cover art here!

Local asshole and 6th generation console enthusiast.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Dan Castellaneta said:

but considering that you basically have to use Microsoft Office for this, I don't know.

I'm thankful that Google Docs and iWork doesn't have antiquated macros. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

11 hours ago, RagnarokDel said:

There's nothing worst then someone who assumes they're safe because they're using X software rather then Y.

I did not say that i am safe, i said this must not affect me like other windows oriented viruses. And that's true actually.

I know that linux has it's vulnerabilities and viruses too.

Computer users fall into two groups:
those that do backups
those that have never had a hard drive fail.

Link to comment
Share on other sites

Link to post
Share on other sites

well i hope people aren't stupid enough to run the macros

wait..... this is people who don't know the meaning of value, good cheap devices and anything else outside of the apple ecosystem.......

hmm.....

oh well, macs aren't allowed on our network at my work, mainly because they don't play nicely with our servers, routers, extenders and anything else really!

****SORRY FOR MY ENGLISH IT'S REALLY TERRIBLE*****

Been married to my wife for 3 years now! Yay!

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, samiscool51 said:

well i hope people aren't stupid enough to run the macros

wait..... this is people who don't know the meaning of value, good cheap devices and anything else outside of the apple ecosystem.......

hmm.....

oh well, macs aren't allowed on our network at my work, mainly because they don't play nicely with our servers, routers, extenders and anything else really!

This isn't really Apple's fault. It's a vulnerability in Microsoft Office for Mac. Really? How come macs aren't allowed? macOS has SMB protocol for years and has Microsoft Exchange built in.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

All I can do is laugh, seriously its not because I have no love its just because its funny for some reason. *shrugs*

COMMUNITY STANDARDS   |   TECH NEWS POSTING GUIDELINES   |   FORUM STAFF

LTT Folding Users Tips, Tricks and FAQ   |   F@H & BOINC Badge Request   |   F@H Contribution    My Rig   |   Project Steamroller

I am a Moderator, but I am fallible. Discuss or debate with me as you will but please do not argue with me as that will get us nowhere.

 

Spoiler

  

 

Character is like a Tree and Reputation like its Shadow. The Shadow is what we think of it; The Tree is the Real thing.  ~ Abraham Lincoln

Reputation is a Lifetime to create but seconds to destroy.

You have enemies? Good. That means you've stood up for something, sometime in your life.  ~ Winston Churchill

Docendo discimus - "to teach is to learn"

 

 CHRISTIAN MEMBER 

 

 
 
 
 
 
 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×