News

Mac users banking credentials threatened by new malware

Monday 17 July 2017 13:40 CET | News

A new scheme that steals banking credentials from Mac users via the Signal private-messaging app has been revealed.

The malware is called OSX/Dok and uses phishing mail filled with a malicious application as its attack vector. Upon successful installation, the malware modifies the OS settings with a shell command that disables security updates. MacbookNext, OSX/Dok gets to work via a man-in-the-middle (MitM) attack designed to intercept the victim’s traffic. Only after it has completed its MitM attack does the malware strap in for its main event. When the victim visits a web page for one of the targeted banks, they see a malicious copy of the actual banks website prompting them to download an application onto their mobile devices “for security reasons”.

If the user submits a working phone number, the attackers send them a link to download the mobile application. At this time, those behind this malware campaign are sending victims a link to Signal, the encrypted messaging app. 

Therefore, with the influx of macOS-based malware it is important that Mac users take some steps to protect their computers and can begin with the installation of an anti-virus solution.


Free Headlines in your E-mail

Every day we send out a free e-mail with the most important headlines of the last 24 hours.

Subscribe now

Keywords: banking credentials, malware, Mac users, phishing, man in the middle attack, fraud prevention, online security
Categories: Fraud & Financial Crime
Companies:
Countries: World
This article is part of category

Fraud & Financial Crime






Industry Events