The malware named OSX.PROTON is back and is now spreading via a fake Symantec blog, targeting MacOS users.
symantecblog[dot]com is a very good imitation of the real Symantec blog. The registration information displayed to the user using the same Symantec name and address looks correct but the email address is fake.
Even more suspicious is the site's certificate, which appears to come from Comodo and not Symantec.
The site reported in a post that a new version of the CoinThief malware had been detected and urged users to download the “Symantec Malware Detector” program, which will detect and remove the malware if it is found on your computer. This is of course not the case, as neither has a new version of CoinThief been officially reported nor does a “Symantec Malware Detector” program exist.
The spread of OSX.PROTON also occurred via Twitter after many accounts were identified as having shared the fake post.
If someone finally downloads the application and runs it, a check window appears that supposedly checks the computer for malware. Even if the user closes the window, the malware runs in the background, performing the installation.
Malwarebytes has announced that using its app, anyone can detect and remove the Proton malware if they are infected. However, this is only half the solution as Proton has the ability to steal passwords. Therefore, it is recommended to change them on all online sites you use.

