Skip to main content

Fake MacDefender Malware Originating from Russian Payment Processor


For about a month there has been a fake MacDefender malware that has been circulating and plaguing Apple computer owners. No one seemed to know where it was coming from, but finally on Friday, May 27 a computer security researcher made the claim that the fake malware could be traced back to an online Russian payment processor called ChronoPay.

"Some of the recent scams that used bogus security alerts in a bid to frighten Mac users into purchasing worthless security software appear to have been the brainchild of ChronoPay, Russia's largest online payment processor and something of a pioneer in the rogue anti-virus business," wrote security researcher Brian Krebs on his KrebsonSecurity blog.

The fake MacDefender and the incredibly similar scareware called MacProtector and MacSecurity tended to attack from points like infected Google Image search results. Once your computer is infected, it is incredibly difficult for Mac users to remove the malware. The issue is that the malware doesn’t have a dock icon and it attaches itself to the launch menu of the computer.

Krebs was able to trace the newest strains of the scareware back to ChronoPay by simply examining the two different domains that the software directs all of its Mac users to go to for a paid software security solution. While investigating, he found out that both mac-defence.com and macbookprotection.com were associated with the e-mail address fc@mail-eye.com. According to leaked ChronoPay documents, this e-mail address is owned by Alexandra Volkova, the company’s financial controller.

According to Krebs, both of the Mac domains listed above have been suspended by Webpoint.com, which is a Czech registrar; however, Krebs said that the fc@mail-eye.com account was used recently to register appledefense.com and appleprodefense.com. Despite this, Mac users have not yet reported being directed to either of these sites via malware like MacDefender.

"ChronoPay has been an unabashed 'leader' in the scareware industry for quite some time," Krebs writes. Just in 2008, it was the core processor of a site called trafficconvertor.biz. This was an “anti-virus” program that was designed to release the first strain of the Conficker worm. It was an incredibly destructive virus that still works to infect millions of computers across the globe.

"In the coming days, Apple will deliver a Mac OS X software update that will automatically find and remove MacDefender malware and its known variants," Apple wrote. “The update will also help protect users by providing an explicit warning if they download this malware."

Apple also released a document with detailed instructions for Mac users on ways to eliminate MacDefender from their computers.



Find out what is going on in the Tech Army World.



What are the Top 10 Money Making Missions?

What other companies have joined and what do they do?

How do I join the
Tech Army Organization ?

Comments

Popular posts from this blog

Airbag Recall! Don't Risk Your Safety!

Certain vehicles, equipped with Takata Airbags are currently being recalled nationwide. Customers are being urged to go to the NHTSA website; https://vinrcl.safercar.gov/vin/ and enter the vehicles Vehicle Identification Number (VIN) to see if their vehicle is included in this recall.  VIN numbers can also be checked through the OTS website; http://www.ots.ca.gov .  If the vehicle is included, they are to immediately contact their nearest dealer and schedule an appointment to have the vehicle repaired for free. In particular, if you own a 2001-2003 Honda or Acura vehicle, you are asked to immediately take your vehicle to an authorized dealer for inspection. Even if you don't own this type of vehicle, please  visit the SaferCar.gov website and check your vehicle VIN. It will identify other recalls as well.

How to Make Money on Fiverr (How I Make $4000 a Month)

Fiverr pays if you for hobbies you play with   Drawing ,   Designing,  Graphics, Art, SEO, Article, music and audio, digital marketing, fun and live-style,  How i make up to  4000 dollar ( 1261000 naira   )  I joined Fiverr  https://michaeltrendz.blogspot.com.ng/  on September 2015 and have generated over 6 million naira from it. Prior to joining, I used to get angry with my friend who was a freelancer on Fiverr.   We were running an offline joint-venture business back then. Every minute he could steal from time, he will quickly log in to Fiverr to do what I didn’t know. Back then, I always saw Fiverr as a $5 marketplace and I couldn’t imagine how he would always dedicate more time to his Fiverr account instead of our offline business which was making us good money…..(so I thought). I didn’t miss any opportunity to make joke of him for slaving away on Fiverr and he wasn’t deterred at all by it……possibly he’d be laughing at me in his mind. It was not until my fiancé finished school and

NPOWER BUILD TRAINING FOR THE NPOWER PROGRAME COMMENCES

Good morning, N-Power Build trainees, are you ready for an exciting time? Training for #NPowerBuild commences March 1st, 2018! Are you ready N-Power Build trainees? #NPowerNG #NPowerBuild #NPowerNG