New Variant of Chinese Gimmick Malware Targeting macOS Users

Discussion in 'all things Mac' started by Rasheed187, Apr 3, 2022.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Seems to be a sophisticated attack on certain targeted macOS users. And XProtect couldn't block it, but it's also not sure how it was delivered, I'm guessing either via email attachment or browser exploit.

    https://thehackernews.com/2022/03/new-variant-of-chinese-gimmick-malware.html
     
  2. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    2,313
    Location:
    .
    Hello @Rasheed187

    Prior to the 17-March-2022 update to the macOS XProtect antivirus technology, the above was most likely to have been true.

    My take away, from a similar news story, is that Apple's last month macOS XProtect update to 2158 serves to defend Mac users from macOS.Gimmick (Chinese spyware). Unfortunately, Apple does not ordinarily release XProtect/MRT update details.

    Although that Chinese spyware is said to have targeted victims in Asia, it was not made clear if all the Google One - Cloud Storage accounts, used by that spyware, were entirely closed & deleted. One can always hope.

    https://appleinsider.com/articles/22/03/23/sophisticated-gimmick-malware-found-custom-made-for-macos

    Thank you always for the news story!
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    No correct, protection against this malware has been added. But my point is that you can't blindly rely on XProtect. Because I get this impression that it's not as advanced as Windows Defender, most likely because there is so little malware available for macOS. I personally would love to see more advanced behavior blocking on macOS, for example a tool like SpyShelter. But the market simply isn't big enough and I'm also not sure if macOS provides the API's to developers in order to build advanced anti-malware tools like behavior blocking and anti-exploit.
     
  4. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    2,313
    Location:
    .
    Hello @Rasheed187

    I strongly do agree with your statement.

    Thank you!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.