Trixology

General Category => General Computing/Macintosh => Topic started by: xairbusdriver on January 23, 2018, 04:46:33 PM

Title: DNS changing Malware affects Mac users
Post by: xairbusdriver on January 23, 2018, 04:46:33 PM
Quote from: TidBITS
OSX/MaMi hijacks macOS?s DNS settings to intercept traffic by routing it through malicious servers...But unless you did something to bypass macOS?s Gatekeeper security, you likely have nothing to worry about since the malware?s executable isn?t signed by Apple.
Quote from: Hacker News
Patrick [Wardle] believes that the attackers could be using lame methods like malicious emails, web-based fake security alerts/popups, or social-engineering type attacks to target Mac users.
Open System Prefs->Network. Click "Advanced" and then the "DNS" tab. Look for:If you find those IP addresses, you have been infected by the malware. Currently no fix, but you can at least delete those two addresses.
Hacker News (https://thehackernews.com/2018/01/macos-dns-hijacker.html)

I failed to mention the need to check all your internet access methods: WiFi, Ethernet, etc. WiFi usually has the modem address, 10.0.0.xxx.
Title: Thanks for the head's up. (Re: DNS changing Malware affects Mac users)
Post by: elagache on January 23, 2018, 11:03:39 PM
Dear X-Air and WeatherCat sys-admins,

Thanks for the head's up.  Indeed most of us are safe from this malware, and sure enough, I double-checked our home network and all is safe and sound.

Cheers, Edouard