Skip to main content

This new Mac malware freezes your computer with email drafts

mac malware dos email drafts malwarebytes mail
A new form of malware is targeting Macs and launching denial-of-service attacks on users by creating multiple email drafts that crash the computer.

The method is simple but devious. According to security company Malwarebytes, which analyzed the malware with the help of researcher @TheWack0lian, it exploits vulnerabilities in the Safari browser and Mail app. Once operating, the malware starts creating countless email drafts, which uses up tons of memory and causes the computer to freeze.

In its report, the security company compared the new discovery to a similar HTML5 bug used in Windows devices last year that caused computers to freeze.

The delivery method of the malware is a classic, too – a regular-looking email purporting to be from tech support. The security researchers found two email addresses that were responsible — dean.jones9875@gmail.com and amannn.2917@gmail.com — and if these senders appear in your inbox, you should delete straight away without even opening. Consider placing blocks against these two email addresses in your settings. However it’s still not known if there are any other malicious email addresses in on the act.

Malwarebytes further noted that several compromised websites were being used to deliver the malware as well. Keep an eye out for these URLs and avoid them: safari-get[.]com, safari-get[.]net, safari-serverhost[.]com, and safari-serverhost[.]net. Again, much like the email addresses, these are only the URLs that we’re aware of so far.

The researchers also found that some variants of the malware opened up iTunes without any prompt but it is not clear what the reason or function of that is.

If you’re running the latest version of MacOS (10.12.2), you will be fine as Apple has patched the vulnerability, but users of older versions should be wary.

Tech support scams may be an old tactic but they keep evolving with clever but underhanded methods of delivering malware.

Editors' Recommendations

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
Will my Mac get macOS 14?
MacOS Sonoma.

MacOS 14 is coming and coming soon, and thanks to Apple's big keynote address at WWDC 2023, we now know what it can do, what it's called, and who can get it. The next generation Mac operating system is codenamed Sonoma, and it's bringing gaming to macOS in a big way, as well as improving video calls, and security. It's going to be available for most modern Mac and MacBook users, but there are some legacy systems that are unfortunately being left out in the cold.

Wondering if your Mac can get macOS 14? Here's everything we know about what Macs are and aren't compatible with Sonoma.

Read more
Apple’s macOS Sonoma has a game-changing feature — literally
apple could fix mac game porting wwdc 2023 gaming 1

Apple’s Worldwide Developers Conference (WWDC) was chock-full of new announcements, and it’s fair to say that between the Vision Pro headset and all of Apple’s new Macs, macOS was far from the biggest new reveal. Yet, there was one new macOS feature that could be absolutely game-changing.

That’s because right now, Mac gaming is in a pretty bad way. Gamers don’t buy Macs because there aren’t enough good games, and developers don’t port their games to the Mac because there aren’t enough people to play them. It’s a chicken-and-egg situation caught in a death spiral.

Read more
This critical exploit could let hackers bypass your Mac’s defenses
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.

Microsoft has discovered a critical exploit in macOS that could grant hackers easy access to your Mac’s most important data. Dubbed ‘Migraine,’ it shows why it’s vital to update your Mac as soon as possible.

Migraine is so damaging because it can bypass Apple’s System Integrity Protection, or SIP for short. SIP is enabled by default on modern Macs and works by sandboxing sensitive parts of the computer from outside meddling. Only processes that are signed by Apple (or those with special privileges, like Apple installers) are allowed to alter something guarded by SIP.

Read more