{"id":339,"date":"2011-05-25T04:17:16","date_gmt":"2011-05-25T04:17:16","guid":{"rendered":"http:\/\/paulgurney.com\/whats_new_blog\/?p=339"},"modified":"2011-05-25T14:55:37","modified_gmt":"2011-05-25T14:55:37","slug":"mac-malware-spreading","status":"publish","type":"post","link":"https:\/\/paulgurney.com\/whats_new_blog\/2011\/05\/mac-malware-spreading\/","title":{"rendered":"Mac Malware spreading"},"content":{"rendered":"<p>Because of gamed SEO placements and poisoned links, some thousands of Mac users were tricked into installing a fake Mac security program.<\/p>\n<p>Mac security vendor intego.com <a title=\"anti-malware-program-attacks-macs\" href=\"http:\/\/blog.intego.com\/2011\/05\/02\/macdefender-rogue-anti-malware-program-attacks-macs-via-seo-poisoning\/\" target=\"_blank\">writes<\/a>:<\/p>\n<blockquote><p>Intego has discovered a rogue anti-malware program called  MACDefender, which attacks Macs via SEO poisoning attacks. When a user  clicks on a link after performing a search on a search engine such as  Google, this takes them to a web site whose page contains JavaScript  that automatically downloads a file. In this case, the file downloaded  is a compressed ZIP archive, which, if a specific option in a web  browser is checked (Open \u201csafe\u201d files after downloading in Safari, for  example), will open. The file is decompressed, and the installer it  contains launches presenting a user with the following screen:<\/p><\/blockquote>\n<p>UPDATE: See <a href=\"http:\/\/blog.intego.com\/2011\/05\/02\/intego-security-memo-macdefender-fake-antivirus\/\">Intego\u2019s full security memo<\/a> with detailed information about the MAC Defender fake antivirus.<\/p>\n<p><strong>PDG Recommends:<\/strong><\/p>\n<p>Sophos makes a <a title=\"Security for Mac\" href=\"https:\/\/paulgurney.com\/whats_new_blog\/2011\/04\/security-for-mac\/\">free Mac security program<\/a>. Read more about it in another post, and use it soon!<\/p>\n<p>Apple will release a cleaner update for it as well. See their <a title=\"apple, malware\" href=\"http:\/\/support.apple.com\/kb\/HT4650\" target=\"_blank\">recent tech note<\/a>.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Because of gamed SEO placements and poisoned links, some thousands of Mac users were tricked into installing a fake Mac security program. Mac security vendor intego.com writes: Intego has discovered a rogue anti-malware program called MACDefender, which attacks Macs via SEO poisoning attacks. When a user clicks on a link after performing a search on &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/paulgurney.com\/whats_new_blog\/2011\/05\/mac-malware-spreading\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Mac Malware spreading&#8221;<\/span><\/a><\/p>\n","protected":false},"author":55,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[27,22,12],"tags":[],"class_list":["post-339","post","type-post","status-publish","format-standard","hentry","category-computers-mac","category-security","category-website"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p415hC-5t","_links":{"self":[{"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/posts\/339","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/comments?post=339"}],"version-history":[{"count":4,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/posts\/339\/revisions"}],"predecessor-version":[{"id":349,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/posts\/339\/revisions\/349"}],"wp:attachment":[{"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/media?parent=339"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/categories?post=339"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/tags?post=339"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}