{"id":131049,"date":"2023-01-06T19:48:46","date_gmt":"2023-01-06T19:48:46","guid":{"rendered":"https:\/\/appleinsider.com\/articles\/23\/01\/06\/dridex-banking-malware-modified-to-spread-using-macos?utm_medium=rss"},"modified":"2023-01-06T19:48:46","modified_gmt":"2023-01-06T19:48:46","slug":"dridex-banking-malware-modified-to-spread-using-macos","status":"publish","type":"post","link":"https:\/\/sickgaming.net\/blog\/2023\/01\/06\/dridex-banking-malware-modified-to-spread-using-macos\/","title":{"rendered":"Dridex banking malware modified to spread using macOS"},"content":{"rendered":"<div class=\"col-sm-12\" id=\"article-hero\" aria-labelledby=\"hero-cap\" role=\"figure\">\n<p id=\"hero-cap\" class=\"hero-caption\" title=\"Dridex targets Macs\">Dridex targets Macs<\/p>\n<p> <a href=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2023\/01\/dridex-banking-malware-modified-to-spread-using-macos.jpg\"> <img decoding=\"async\" src=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2023\/01\/dridex-banking-malware-modified-to-spread-using-macos.jpg\" alt> <\/a> <\/div>\n<div class=\"col-sm-12\">\n<p> <em> AppleInsider may earn an affiliate commission on purchases made through links on our site. <\/em> <\/p>\n<\/div>\n<p class=\"col-sm-12 article-lead\">A variant of the Dridex banking malware is using <a href=\"https:\/\/appleinsider.com\/inside\/macos\" title=\"macOS\" data-kpt=\"1\">macOS<\/a> to spread to others, by using email attachments that look like regular documents.\n<\/p>\n<div class=\"col-sm-12\">\n<p>Security researchers at Trend Micro said <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/a\/-dridex-targets-macos-using-new-entry-method.html\">on Thursday<\/a> that the malware previously targeted Windows, but now the cybercriminals have changed their strategy to go after macOS.\n<\/p>\n<\/div>\n<div class=\"col-sm-12\">\n<p>The Dridex malware sample Trend Micro analyzed takes the form of a Mach-O file, an executable file that can run on macOS and iOS. File extensions they use include .o, .dylib, and .bundle.\n<\/p>\n<\/div>\n<div class=\"col-sm-12\">\n<p>The Mach-O file contains a malicious document that runs automatically once a user opens it. It then overwrites all Microsoft Word files in the macOS user directory and contacts a remote server to download more files, including a Windows executable file (.exe) that runs the Dridex malware.\n<\/p>\n<\/div>\n<div class=\"col-sm-12\">\n<figure><a href=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2023\/01\/dridex-banking-malware-modified-to-spread-using-macos-1.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2023\/01\/dridex-banking-malware-modified-to-spread-using-macos-1.jpg\" alt=\"Content of the executable file dropped by the malware. Source: Trend Micro\" height=\"676\" loading=\"lazy\" class=\"img-responsive article-image\"><\/a><figcaption>\n<p><span class=\"carousel-caption\">Content of the executable file dropped by the malware. Source: Trend Micro<\/span><\/p>\n<\/figcaption><\/figure>\n<\/div>\n<div class=\"col-sm-12\">\n<p>These executables can&#8217;t run on macOS. But, if a user&#8217;s Word files are overwritten with malicious versions, Mac users could unwittingly infect others when they share the files online. <\/p>\n<\/div>\n<div class=\"col-sm-12\">\n<p>For now, Mac users are safe from the Dridex malware. Trend Micro says it&#8217;s possible that attackers could modify it to run on macOS in the future.\n<\/p>\n<\/div>\n<p><h2 data-anchor=\"how-to-stay-safe\" id=\"how-to-stay-safe\">How to stay safe<\/h2>\n<\/p>\n<div class=\"col-sm-12\">\n<p>First and foremost, with Dridex, the best way to protect yourself is to not open attachments where the provenance is unclear. Check who the sender is, not just by the displayed name of the sender, but also the email address.\n<\/p>\n<\/div>\n<div class=\"col-sm-12\">\n<p>For instance, your credit card company won&#8217;t send you a receipt from a Gmail account.\n<\/p>\n<\/div>\n<div class=\"col-sm-12\">\n<p>Apple includes <a href=\"https:\/\/appleinsider.com\/inside\/macos\/tips\/good-mac-security-goes-beyond-antivirus\">security tools<\/a> such as Gatekeeper and the XProtect antivirus software that are built into macOS. Users can also choose to download antivirus software from a third-party company.\n<\/p>\n<\/div>\n<div class=\"col-sm-12\">\n<p>An online tool called <a href=\"https:\/\/www.virustotal.com\/gui\/home\/upload\">VirusTotal<\/a> can scan URLs and files that people upload and detect if it contains malware. For example, if an email has a Microsoft Word document or a Mach-O file as an attachment, it may be a good idea to scan it with the website.\n<\/p>\n<\/div>\n<div class=\"col-sm-12\">\n<p><em>AppleInsider<\/em> will be covering the 2023 Consumer Electronics Show in person on January 2 through January 8 where we&#8217;re expecting Wi-Fi 6e devices, HomeKit, Apple accessories, 8K monitors and more. Keep up with our coverage by downloading the <a href=\"https:\/\/apps.apple.com\/us\/app\/appleinsider\/id578462575\/?at=11l4Kw\" rel=\"sponsored\">AppleInsider app<\/a>, and <a href=\"https:\/\/www.youtube.com\/appleinsider\">follow us on YouTube<\/a>, Twitter <a href=\"https:\/\/twitter.com\/appleinsider\">@appleinsider<\/a> and <a href=\"https:\/\/www.facebook.com\/AppleInsiderdotcom\/\">Facebook<\/a> for live, late-breaking coverage. You can also check out our official <a href=\"https:\/\/www.instagram.com\/appleinsiderofficial\/\">Instagram<\/a> account for exclusive photos throughout the event.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Dridex targets Macs AppleInsider may earn an affiliate commission on purchases made through links on our site. A variant of the Dridex banking malware is using macOS to spread to others, by using email attachments that look like regular documents. Security researchers at Trend Micro said on Thursday that the malware previously targeted Windows, but [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":131050,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[57],"tags":[],"class_list":["post-131049","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apple-insider"],"_links":{"self":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts\/131049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/comments?post=131049"}],"version-history":[{"count":0,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts\/131049\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/media\/131050"}],"wp:attachment":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/media?parent=131049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/categories?post=131049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/tags?post=131049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}