New Mac malware raises more questions about Apple’s security patching

Discussion in 'all things Mac' started by Rasheed187, Nov 18, 2021.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    As most of us know, in Windows we can easily tackle most of these ''drive by'' attacks with stuff like anti-exploit, anti-executable, HIPS and virtualization. But do you guys know of any similar tools on the macOS? I have searched for it, but couldn't find any, besides third party AV's and firewalls, but I'm talking about specialized tools. And please don't come with that nonsense about not needing any third party anti-malware tools on Unix, stay on topic please. :p
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    And BTW, I have looked for macOS security apps on this site, but most of them see to be quite basic. I'm looking for tools similar to HitmanPro.Alert, OSArmor, SpyShelter and Sandboxie for example. Perhaps some macOS guru knows about them.

    https://www.macupdate.com/explore/categories/security
     
  4. ParadigmShift

    ParadigmShift Registered Member

    Joined:
    Aug 7, 2008
    Posts:
    241
    This is a pretty good site for Mac security:

    Objective-See

    I have been using BlockBlock
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, I knew about Objective-See, it's just about the only company focused on making behavior blocking tools for the macOS. But they are still not as advanced as third party tools on Windows. Makes you wonder if it's even possible to develop tools similar to SpyShelter and HMPA on the macOS.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    And BTW, seems like their tools were good enough to interfere with the backdoor malware that was dropped via the Safari and macOS zero day exploit. This backdoor was able to get persistence on the system and seems like it bypassed macOS built-in security like Gatekeeper and XProtect.

    https://objective-see.com/blog/blog_0x69.html
     
  7. ParadigmShift

    ParadigmShift Registered Member

    Joined:
    Aug 7, 2008
    Posts:
    241
    It's good to see that. I've been using BlockBlock since back in it's Beta days. Good stuff.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, sometimes it does pay off to use third party tools, even on the macOS. Of course on the macOS it's less likely that you will encounter malware, but if it does happen, it's nice to have a bit more advanced mitigations tools. And eventhough Gatekeeper and XProtect are probably good enough to block most malware, they still seem to be a bit basic. But I haven't got a clue if third party AV's would do any better.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.