Mobile menu toggle

Stealthy OSX/MaMi malware discovered targeting Macs

By •

macOS High Sierra
Your antivirus won't save you from OSX/MaMi.
Photo: Ste Smith/Cult of Mac

The first nasty bit of undetectable malware of 2018 has been unearthed after it was found targeting Macs this week.

Security researchers revealed info about the new OSX/MaMi malware which is a lot like the popular DNSChanger malware from 2012 that infected millions of machines.

In a blog post detailing the new malware, ex-NSA hacker Patrick Wardle says the OSX/MaMi malware could be used by attackers to steal personal information from victims. Current anti-virus software won’t detect an infection for now.

“OSX/MaMi isn’t particular advanced – but does alter infected systems in rather nasty and persistent ways,” writes Wardle. “By installing a new root certifcate and hijacking the DNS servers, the attackers can perform a variety of nefarious actions such as man-in-the-middle’ing traffic (perhaps to steal credentials, or inject ads).”

It’s still unknown who is behind OSX/MaMi or how it is spreading. The distribution methods are likely your run of the mill phishing and email attachment attacks though.

To see if you’ve been infected, go to the System Preferences app to check your DNS settings and see if they’ve been changed to 82.163.143.135 and 82.163.142.137.

  • Subscribe to the Newsletter

    Our daily roundup of Apple news, reviews and how-tos. Plus the best Apple tweets, fun polls and inspiring Steve Jobs bons mots. Our readers say: "Love what you do" -- Christi Cardenas. "Absolutely love the content!" -- Harshita Arora. "Genuinely one of the highlights of my inbox" -- Lee Barnett.

Popular This Week

4 responses to “Stealthy OSX/MaMi malware discovered targeting Macs”

  1. Emma says:

    I do not understand ….”go to system preferences app”….. please detail how to do that.

    • Dalucci says:

      go to system preferences (apple menu, system preferences), then go to “network” icon, select your active network device (like Wi-Fi or Ethernet) , click “advanced” and then “DNS” tab

  2. fabrica64 says:

    But you need to run as administrator, so “infection” has to be authorized by the user, isn’t it? You can’t install a system certificate or change system preference without authorizing it

  3. Tom says:

    Why anti-virus companies are failing?

Leave a Reply