{"id":228422,"date":"2017-07-17T16:08:17","date_gmt":"2017-07-17T20:08:17","guid":{"rendered":"http:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/uncategorized\/apple-users-warned-of-dangerous-new-mac-malware-that-steals-banking-credentials-thaivisa-news.php"},"modified":"2017-07-17T16:08:17","modified_gmt":"2017-07-17T20:08:17","slug":"apple-users-warned-of-dangerous-new-mac-malware-that-steals-banking-credentials-thaivisa-news","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/tor-browser\/apple-users-warned-of-dangerous-new-mac-malware-that-steals-banking-credentials-thaivisa-news.php","title":{"rendered":"Apple users warned of dangerous new Mac malware that steals banking credentials &#8211; ThaiVisa News"},"content":{"rendered":"<p><p>    Apple users are being warned about a newly discovered form of    Mac malware which is spread via a phishing attack and steals    banking credentials.  <\/p>\n<p>    The malware, dubbed OSX\/Dox, was discovered by researchers from    Check Point Security and mirrors the websites of some of the    worlds leading banks to steal attempt to steal money from    users.  <\/p>\n<p>    The malware is being spread via a combination of phishing and    so called Man in the Middle attacks.  <\/p>\n<p>    Security experts say the Mac malware is extremely difficult to    detect as it is able to bypass Apples stringent security    measures and spy on all communications from the victim.  <\/p>\n<p>    Check Point said they have seen a recent surge in the malware    being used by hackers who are currently playing a game of cat    and mouse with Apple.  <\/p>\n<p>    Check Point say the hackers are purchasing dozens of Apple    certificates to sign on the application bundle and bypass    GateKeeper. As soon as Apple revokes one of the certificates    the hackers switch to another, with new certificates being used    on a daily basis.  <\/p>\n<p>    They are aiming at the victims banking credentials by    mimicking major bank sites. The fake sites prompt the victim to    install an application on their mobile devices, which could    potentially lead to further infection and data leakage from the    mobile platform as well, Check Point said in a     blog post.  <\/p>\n<p>    Once the malware has been installed on a device it downloads    the Tor browser and starts to communicate with servers    controlled by the hackers. It then records the location of the    infected device and customises the fake banking page depending    on the location of the victim, making the attack even more    convincing.  <\/p>\n<p>      Image: Check Point. The very convincing but fake banking page      by use by OSX\/Dox    <\/p>\n<p>    The malware then asks victims to login into the fake banking    page with their banking credentials and also asks for their    mobile number to setup SMS authentication.  <\/p>\n<p>    Victims are then tricked into downloading a malicious app and    the Stack encrypted messaging app.  <\/p>\n<p>    It is not known why victims are made to download Stack but    Check Point researchers speculate that it could be used by the    hackers to commit more fraud at later date.  <\/p>\n<p>    Whatever the goal may be, Signal will possibly make it harder    for law enforcement to trace the attacker.  <\/p>\n<p>    Alternatively, the perpetrator might be using Signal    temporarily, to acquire install rate statistics and prove the    method is working, while planning to install a malicious mobile    application with future victims at a later time.  <\/p>\n<p>    Unfortunately, the OSX\/Dok malware is still on the loose and    its owners continue to invest more and more in its obfuscation    by using legitimate Apple certificates, Check Point    researchers wrote.  <\/p>\n<p>    The fact that the OSX\/Dok is ported from Windows may point to    a tendency. We believe more Windows malware will be ported to    macOS, either due to the lower number of quality security    products for macOS compared to the ones for Windows, or the    rising popularity of Apple computers.  <\/p>\n<p>        Jonathan is our Google Nexus and Android        enthusiast. He is also fanatical about football which makes        it all the more strange that he should support Stockport        County. In addition to writing about tech, Jonathan has a        passion for fitness and nutrition and has previously        written for one the UKs leading watch and horology        websites.      <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more here: <\/p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"http:\/\/tech.thaivisa.com\/apple-users-warned-dangerous-new-mac-malware-steals-banking-credentials\/22977\/\" title=\"Apple users warned of dangerous new Mac malware that steals banking credentials - ThaiVisa News\">Apple users warned of dangerous new Mac malware that steals banking credentials - ThaiVisa News<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Apple users are being warned about a newly discovered form of Mac malware which is spread via a phishing attack and steals banking credentials.  <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/tor-browser\/apple-users-warned-of-dangerous-new-mac-malware-that-steals-banking-credentials-thaivisa-news.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[261457],"tags":[],"class_list":["post-228422","post","type-post","status-publish","format-standard","hentry","category-tor-browser"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/228422"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=228422"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/228422\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=228422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=228422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=228422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}