Skip to main content

New MacDefender malware infecting unsuspecting Apple users

installerIt’s easy to get lured into a false sense of security as a Mac user – after all, Apple’s personal computers are paraded about as virus immune machines.  Of course that isn’t a catch-all, and a new report from the Intego Mac Security Blog says there is new malware targeting Mac computers. Apple Discussion forums are also rife with complaints of a program called MacDefender (not to be confused with this site).

The trojan appears to be targeting users browsing Google Images via Safari, who receive a notice claiming their system is infected and they need to install a MacDefender application to remove viruses. MacDefender is able to bypass Safari’s protection system, which automatically accepts trusted software. MacDefender then relaunches every time a user logs in or restarts the computer. There are no terribly obvious effects: The virus doesn’t install anything to run in the background, but it does attempt to swindle users into buying the application via credit card.

MacDefender is using SEO poisoning tactics to infiltrate the systems, meaning that the virus is using popular search terms and forcing its own malicious site to the top of the search results. Unlike most malware and spyware, the link appears completely credible and clicking it allows the trojan to automatically open via Safari’s “Open Safe Files” feature.

The good news is that MacDefender doesn’t really have the potential to spread like wildfire. You first have to search for the specific search term, click on the malware infected option, and authorize installation. The bad news is that it’s fairly hard to spot and has an incredibly professional feel to it. Intego points out that it’s also opening pornographic web pages periodically to try and convince users they have a virus worth buying MacDefender’s supposed software to remove.

If you want to protect yourself

If you haven’t been affected by MacDender and want it to stay that way, simply uncheck the “open safe files after downloading” option by going to Safari, Preferences, and then General. You could also use an alternative browser. Another option is to defer to running in Standard of Managed mode, versus as an Administrator – this just keeps viruses from being able to access every nook and cranny of your system.

safari-safe open

If you’ve been infected

If your system has already been infected, The Next Web explains how you can fairly easily get rid of MacDefender.

  1. Go to Applications, and then Utilities to check the Activity Monitor. Disable anything with “MacDefender” in the name.
  2. Go to Library, Startup Items, and in there look for in LaunchAgents and LaunchDaemons for anything with “MacDefender” in the name. Quit any running applications.
  3. Go back to the Applications folder and drag and drop MacDefender from there to the trash. Delete trash.
  4. Search for anything on your system with “MacDefender” in the name and delete anything returned.

Editors' Recommendations

Molly McHugh
Former Digital Trends Contributor
Before coming to Digital Trends, Molly worked as a freelance writer, occasional photographer, and general technical lackey…
This devious scam app proves that Macs aren’t bulletproof
A close-up of a MacBook illuminated under neon lights.

Pirated software can cause all kinds of headaches, but Mac users might have thought themselves largely immune thanks to Apple’s reputation for solid security. Yet, that complacency could prove quite problematic, as a new strain of nearly undetectable malware has shown.

According to research from security firm Jamf Threat Labs, pirated versions of Apple’s Final Cut Pro moviemaking app have been modified to contain cryptojacking payloads. When installed, the app starts using your Mac to mine the Monero cryptocurrency behind your back, potentially slowing down your machine as system resources are illegitimately gobbled up.

Read more
This major Apple bug could let hackers steal your photos and wipe your device
A physical lock placed on a keyboard to represent a locked keyboard.

Apple’s macOS and iOS are often considered to be more secure than their rivals, but that doesn’t make them invulnerable. One security team recently proved that by showing how hackers could exploit Apple’s systems to access your messages, location data, and photos -- and even wipe your device entirely.

The discoveries were published on the blog of security research firm Trellix, and will be of major concern to iOS and macOS users alike, since the vulnerabilities can be exploited on both operating systems. Trellix explains that Apple patched the exploits in macOS 13.2 and iOS 16.3, which were released in January 2023, so you should update your devices as soon as you can.

Read more
Apple may launch a groundbreaking new Mac in a few weeks
The MacBook Air on a table in front of a window.

This spring could be a momentous one for Apple fans, with a top-secret mixed-reality headset and new Apple silicon Mac Pro lined up for release. We’ve also heard whispers that Apple is planning to launch a 15.5-inch MacBook Air, and that idea just received a major boost from a well-known industry expert.

That’s because display industry analyst Ross Young has just claimed in a post to his Twitter subscribers that screen panel production for the larger MacBook Air has already begun, with Apple lining up an early April release date for the device. If he’s correct, that means there are just a couple of months to wait. It follows previous reporting from Bloomberg journalist Mark Gurman and Young himself pointing toward a spring release.

Read more