New Mac Malware Reported: a Malicious Word Doc and a Fake Software Update

Advertisement
By Tasneem Akolawala | Updated: 10 February 2017 18:44 IST
Highlights
  • Malicious Word doc found infecting Mac machines through macros
  • The second exploit posed as a fake software update
  • Ensure that you only download updates from official websites

Researchers have found instances of Mac exploits through malicious Microsoft Word documents that abuse macros, and fake software updates that download malicious code. While a boobytrapped Word document is found to be infecting Mac machines, a first such instance to be reported, and a fake software update of Adobe Flash Player is also doing the rounds.

Word document-based malware is something that is commonly seen infecting Windows machines, but has been spotted to infect Macs for the first time in the real-world scenario. Ars Technica reports that the attack was spotted in a Word file titled, "U.S. Allies and Rivals Digest Trump's Victory - Carnegie Endowment for International Peace."

Unknowingly, if a Mac user opens this document, it will download and execute an encrypted payload without any warning to the user. The researchers were unable to understand what this attack actually did, but because it was copied precisely from EmPyre, it is presumed that it could "monitor webcams, steal passwords and encryption keys stored in the keychain, and accessing browsing histories."

Advertisement

Director of research at security firm Synack, Patrick Wardle, analysed the document and published his analysis. He wrote, "By using macros in Word documents, they are exploiting the weakest link; humans! And moreover since macros are 'legitimate' functionality (vs. say a memory corruption vulnerability) the malware's infection vector doesn't have to worry about crashing the system nor being 'patched' out."

However, Wardle said that overall the malware isn't particularly advanced as it relies on user interaction, as well as need macros to be enabled. However, even though this particular malware was poorly written and macOS malware has yet to catch up to its Windows counterparts, Ars Technica notes that the gap is steadily closing. We recommend you to never let unknown Word Docs run macros.

The other malware found attacking Mac machines earlier this week, was a MacDownloader virus posing as an Adobe Flash Player update. This is again a tactic found in many Windows exploits, where a fake software update of an app pops-up, but when you hit update, malicious code gets downloaded. This is more sophisticated than Word malware, and it potentially puts your usernames, passwords, and other sensitive data at risk. Users are of course, cautioned to not click random update links, and only rely on system tools or official sites for updates. However, if it's a Flash update, we'd recommend you to uninstall the app instead.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPad Pro With M5 Chip, OLED Display Launched in India at This Price
  2. Vivo Announces OriginOS 6 for Vivo and iQOO Handsets Globally
  3. Honor Magic 8, Magic 8 Pro With Snapdragon 8 Elite Gen 5 Launched: See Price
  4. Google Pixel 10 Pro Fold Explodes During YouTuber's Durability Test
  5. iQOO Neo 11 Launch, Design Teased; Pre-Reservations Begin Ahead of Debut
  6. Oppo Find X9 Series, Oppo Pad 5 Launching Today: All You Need to Know
  7. Oppo Unveils ColorOS 16; Will Debut in India With Oppo Find X9 Series
  8. Oppo Find X9 Series Could Launch in India on This Date
  1. Dyson Purifier Cool PC1 – TP11 Launched in India With HEPA Filtration, Smart Controls: Price, Features
  2. Vivo Announces Android 16-Based OriginOS 6 Globally With Origin Animation, AI Features: Release Timeline
  3. Redmi K90, Redmi K90 Pro Max Set for China Launch in October; Teased to Be Priced Under Rs. 50,000
  4. Scientists Solve Decades-Old Photosynthesis Puzzle With IISc–Caltech Study
  5. Solar Wind Cuts Comet Lemmon’s Tail In Rare Disconnection Event
  6. SpaceX Eyes V3 Rocket With Raptor 3 Engines After Wrapping Starship V2 Tests
  7. Researchers Develop Wetsuits That Protect Against Shark Bites And Stings
  8. Final Destination Bloodlines to Be Available for Streaming on JioHotstar Soon: What You Need to Know
  9. Caltech Unveils X1 Robot-Drone Hybrid Capable Of Walking, Driving And Flying
  10. Astronomers Detect Hints Of Hidden Earth-Sized Planet Beyond Neptune
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.