Mac users: be careful!

© https://blog.confiant.com/@taha.karim

© https://blog.confiant.com/@taha.karim

Fraudulent software targeting the MacOS operating system has been detected on campus: our tips to avoid infection.

According to the analyst who detailed the different components of this malware, there are actually two different malicious codes, the first one preparing the installation of the second. The Shlayer/Tarmac duo uses malicious adverts (maladverising) to trick users into downloading a Flash Player update: they are are deceived by the perfect imitation of the usual update interface and are therefore convinced to install legitimate software.

Good practices:

  • Never download updates that do not come directly from the vendor's website: always check its SSL certificate (padlock icon in the address bar)
  • Avoid browsing websites that offer pirated versions of software, movies or music albums
  • Stay vigilant at all times, even on high-traffic sites