Skip to main content

Mac malware has been found hidden in file converter on major site

macos sierra update windows 10 creators install features
Bill Roberson/Digital Trends
A new piece of malware targeting Macs has been found in the wild, following hot on the heels of the first piece of ransomware for the platform, which was unearthed earlier this year. The malware is being referred to as Backdoor.MAC.Elanor, and it provides further evidence that Macs aren’t as impervious to attack as they were once assumed to be.

The backdoor is apparently being hidden away in a phony file converter utility that’s being distributed via major sites like MacUpdate, according to a report from 9to5Mac. EasyDoc Converter purports to be a legitimate piece of software, but offers no functionality beyond downloading the backdoor.

MacUpdate has now been alerted to the issue, and has removed download links to the utility and delisted it from its search results. However, EasyDoc Converter is likely hosted on scores of different websites, and there could potentially be plenty of other fake pieces of software serving to distribute the backdoor.

Backdoor.MAC.Elanor could potentially be used to facilitate all manner of attacks on a victim’s computer. A hacker could use the backdoor in conjunction with other techniques to execute attacks ranging from data theft to a complete takeover of the system’s webcam.

Fortunately, the malicious app is not signed with an Apple Developer ID, which should make it easier for Mac users to avoid the backdoor. So long as your computer’s settings stipulate that it will only open apps from the App Store or from known developers, it shouldn’t be able to open.

However, there’s an important lesson about security to be learned here. There was a time when Macs weren’t considered to be at risk of malware attacks to the same extent that PCs are — evidently, that is no longer the case.

Editors' Recommendations

Brad Jones
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
The next MacBook Air could come with a major disappointment
A MacBook Air on a desk with an open book in front of it.

It’s something of an open secret that Apple is working on a couple of fresh MacBook Air models, including an all-new 15-inch MacBook Air. Many details about these devices have been shrouded in mystery, but a prominent analyst has just shed some much-needed light on them -- and it’s not all good news.

Posting on Twitter, Apple analyst Ming-Chi Kuo updated his previous predictions for Apple’s lightweight laptop. In the new post, Kuo outlined a slate of ideas for what could be coming next.

Read more
One of the most exciting upcoming Mac releases may have been canceled
Members of the press photograph an Apple Pro Display XDR at WWDC 2019.

Apple's 27-inch, mini-LED display was expected to replace the $4,999 Pro Display XDR or possibly bridge the gap between the $1,600 Studio Display and the premium display. Unfortunately, the latest report suggests it has been canceled, leaving fans to speculate about why this highly anticipated product might never arrive.

Display Supply Chain Consultants CEO Ross Young, a typically reliable source of Apple supply chain information, shared the news via a subscriber-only tweet. 9to5Mac was first to pick up the story, noting that Young said despite suppliers shipping some of these advanced panels last year, the finished product has been "killed off."

Read more
This Mac malware can steal your credit card data in seconds
Apple's Craig Federighi speaking about macOS security at WWDC 2022.

Despite their reputation for security, Macs can still get viruses, and that’s just been proven by a malicious new Mac malware that can steal your credit card info and send it back to the attacker, ready to be exploited. It’s a reminder to be careful when opening apps from unknown sources.

The malware, dubbed MacStealer, was discovered by Uptycs, a threat research firm. It hoovers up a wide array of your personal data, including the iCloud Keychain password database, credit card data, cryptocurrency wallet credentials, browser cookies, documents, and more. That means there’s a lot that could be at risk if it gains a foothold on your Mac.

Read more