dcsimg

What’s in the spam mailbox this week?

We’ve seen a fair few spam emails in circulation this week, ranging from phishing to money muling to sexploitation. Shall we take a look? The FBI wants to give you back your money First out of the gate, we have a missive claiming to be from the FBI. Turns out you lost a huge sum of money that you somehow don’t have any recollection of, and now the FBI wants to give it back to you via … [Read more...]

New strain of Mac malware Proton found after two years

Last week, Kaspersky reported on a new variant of the Mac malware Proton, which they have dubbed Calisto, that has been around for at least two years. Calisto is thoroughly dead at this point, but there are still potential security implications involved with these older infections. Proton was first revealed to the world back in February 2017 via an Apple security update. It was later seen in the … [Read more...]

New Mac cryptominer uses XMRig

A new Mac cryptominer was discovered this week, after affected users saw their fans whirring out of control and a process named “mshelper” gobbling up CPU time like Cookie Monster. Fortunately, this malware is not very sophisticated and is easy to remove. The malware became public knowledge in a post on Apple’s discussion forums, where the “mshelper” process was found … [Read more...]

Seven security tips for staying safe on an iPhone

iPhones have a reputation for being notoriously secure. After all, they caused quite the kerfuffle between Apple and the FBI because they are, from the FBI’s point of view, too secure! However, don’t let that lull you into a false sense of security. Using an iPhone is not an automatic guarantee of invulnerability. The good news is that there are easy things to do to avoid causing … [Read more...]

Netflix phish claims your membership is on hold

The days of ugly-looking phish pages hosted on something akin to a Geocities page are slowly receding into the distance. For quite some time now, phish attacks have made attempts to look fairly sophisticated and stand a decent chance of fooling anyone not keeping their guard up. Today, we have a good example of this with a Netflix phish currently in circulation and (potentially) dropping into a … [Read more...]

Investors concerned about smartphone addiction; Apple responds with new webpage

Hot on the heels of an open letter from investors urging Apple to do more to protect children from smartphone addiction, the tech giant has recently dedicated a page on their website to families. The “Families” page, which can be accessed at apple.com/families, contains tools parents can use to set restrictions on devices accessible to their kids, manage in-app purchases, keep track of … [Read more...]

The state of Mac malware

Mac users are often told that they don’t need antivirus software, because there are no Mac viruses. However, this is not true at all, as Macs actually are affected by malware, and have been for most of their existence. Even the first well-known virus—Elk Cloner—affected Apple computers rather than MS-DOS computers. In 2018, the state of Mac malware has evolved, with more and more threats … [Read more...]

Panic attack: Apple scams apply pressure

We’ve seen a number of Apple-related phishes in circulation over the last few days. While most of them already lead to deactivated phishing sites, we thought it was worth highlighting some of the tricks being used to bait people into handing over payment details at the moment. Fake receipt emails First up, a number of fake “receipt” emails ranging in date from February 2–6. While … [Read more...]

Can You Run a VM from an External Drive?

At a recent conference for Mac® IT admins, I was asked, “Can you run a VM from an external drive?” Short answer: “Yes, absolutely. I do this all the time.” Longer answer: You have always been able to run a Parallels Desktop® for Mac virtual machine from an external drive. In Parallels Desktop 13, this [...] The post Can You Run a VM from an External Drive? appeared first on Parallels Blog. … [Read more...]

Interesting disguise employed by new Mac malware HiddenLotus

On November 30, Apple silently added a signature to the macOS XProtect anti-malware system for something called OSX.HiddenLotus.A. It was a mystery what HiddenLotus was until, later that same day, Arnaud Abbati found the sample and shared it with other security researchers on Twitter. The HiddenLotus “dropper” is an application named Lê Thu Hà (HAEDC).pdf, using an old trick of … [Read more...]