Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
I wish they could be a little bit more clarity on how to really check for this. Interesting how things have come full circle. I remember years ago reading Total Panther from Macworld and guest columnist David Pogue was bragging about Mac OS X being a better choice than Windows and the upcoming 'Longhorn' because its a smaller user base and hackers are not interested. It was so naive to think that hackers would ignore macOS because its a smaller user base.

These changes to the security landscape will only force Apples hand to potentially lock down macOS, iOS style. It wouldn't be a bad idea for the vast majority of users. Just have a special easy to enable mode for power users who know what they are doing. But for grand ma, Cindy and Todd who just want email, spotify and download apps from the App Store, it shouldn't be a big deal.
Isnt that already the case? Im not 100% sure but when you do a clean install, in Settings>Security the "Allow apps from" option has only "AppStore" checked instead of "AppStore and identified developers".
Also if Cindy and Todd are that simple that only use the App Store they wouldnt encounter this problems as they won't go downloading .dmg from Internet and If they do, just use a bit of common sense and check that is the official website. If we let Apple do everything they will just lock our devices
 
  • Like
Reactions: peanuts_of_pathos
Found something at 9to5mac

1. Go to /Users/[username]/Library/LaunchAgents directory
2. Check for suspicious filenames in this directory (example below is a random name)

/Users/user/Library/LaunchAgents/com.wznlVRt83Jsd.HPyT0b4Hwxh.plist

if there is a file named like above, it's very likely you have been infected
Checked in my Big Sur and Mojave installation, nothing suspicious in either. Thanks for the tip.
 
  • Like
Reactions: peanuts_of_pathos
No matter what these Mac’s are protected. Let’s be real here.

When was the last time you encountered your Mac got a virus?
Are they? Stolen dev certs allow malicious apps to bypass Gatekeeper. Happens a lot more than you think.
Sure, Apple can revoke the cert, but that doesn't fix infected systems.
Being complacent is how one gets infected, be it a trojan, malware, or a virus.

A good article for the overly complacent Mac user.
 
Found something at 9to5mac

1. Go to /Users/[username]/Library/LaunchAgents directory
2. Check for suspicious filenames in this directory (example below is a random name)

/Users/user/Library/LaunchAgents/com.wznlVRt83Jsd.HPyT0b4Hwxh.plist

if there is a file named like above, it's very likely you have been infected

Being fairly new to Macs I too was a little confused by "Apple's Autorun...". Makes it sound like it's a terminal utility or something. But is he saying just check all the folders that house autorun commands including Users and Groups login items?
 
To get to that launch agents folder, click your Desktop to bring focus to the Finder. Then hit shift-command-g keys (all three at once) and you will get the popup window below. Paste in ~/Library/LaunchAgents/ and hit return and you be taken to the users launch agents folder.

Screen Shot 2021-07-21 at 9.15.34 AM.png
 

The 9to5 article says it is the users folder.
Agreed, but I'd also check the other in case a malware has obtained elevated permissions. Obviously the user shouldn't go deleting everything they think is suspicious. Do the due diligence and check authenticity prior to deletion.
 
Found something at 9to5mac

1. Go to /Users/[username]/Library/LaunchAgents directory
2. Check for suspicious filenames in this directory (example below is a random name)

I do this regularly anyway (plus /Library/LaunchDaemons and /Library/LaunchAgents). A lot of "legitimate" companies load crap in there as well - much of it pointless, yet still slowing down your computer.
 
macOS is much more secure but users often doesn't have a clue. Macs can install software other than App Store and you like it or not, this is the main cause of malware diffusion. Cheap users want to download movies and software without paying = they get infected.
Yes, absolutely, the greed factor is in play. Users get an offer of something of value for free (movie, app, music, etc) and the greedy ones click away and get pwned. Torrents have been the main source of malware for decades. You pirate a movie, music, app only to find out it’s loaded with malware.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.