HomeSecurityPirated apps infect macOS systems with malware

Pirated apps infect macOS systems with malware

We've said it many times! Free pirated software downloads can carry many risks, including malware infection . Kaspersky researchers have discovered a widespread macOS malware that targets users who download pirated copies of legitimate software. The campaign has been dubbed macOS.Bkdr.Activator .

macOS malware

Malware is hiding in various applications, which are specifically designed for business purposes and enhancing productivity. These applications could potentially be very attractive.

See also: Pirated macOS apps drain users' wallets

Let's look at the method of infection in more detail:

Stage 1: Malware hides in pirated applications

The initial delivery method is via a torrent link that serves a disk image containing two applications: A seemingly “uncracked” app that shows that the program cannot be used , and an “Activator” app that fixes the software to make it usable. Users are instructed to copy both items to the /Applications folder before launching the Activator program.

Stage 2: Activation of Backdoor malware

The Activator app asks for the administrator password.

If users fall for the trap and provide the password, the malware begins its real action, which includes:

  • Disable Gatekeeper: This bypasses this macOS protection measure and allows any application.
  • Python installation: If absent, it creates a tool for further malicious activities.
  • Notification Center Silence: The malware silences potential security that could betray malicious activities.
  • Installation of a LaunchAgent: This persistent malware ensures its survival on the macOS system.

See also: MacOS info-stealer malware evades detection by XProtect

Stage 3: Further malicious actions

Malware does other things too:

  • Communicating with a remote server: Retrieves instructions on how to proceed (possibly additional malware).
  • Checks for previous infections: Avoids unnecessary actions if an infection has already occurred.
  • Runs scripts: These scripts could do anything from stealing data to turning a Mac into a bot.

According to SentinelOne, the campaign is ongoing and new malicious samples are being identified.

macOS.Bkdr.Activator

The above shows that more and more cybercriminals are creating macOS malware that is resistant to detection and bypasses device security systems

Static detection methods for security are not enough. A more robust approach should incorporate antivirus software equipped with advanced analysis capabilities.

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.

See also: Atomic Stealer: New version of malware targets macOS

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install MacOS info-stealers.

Also, don't forget to use firewalls and monitor network traffic , which will help you immediately identify suspicious activity.

Using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to account , even if they manage to steal your password.

Finally, avoiding downloading applications from untrusted sources and downloading pirated programs is important, as they are likely to contain malware, as in the case of macOS.Bkdr.Activator.

Source: cybersecuritynews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS