CERT mailing list archives

Current Activity - Apple Mac Defender, MacProtector, and MacSecurity Fake Anti-Virus Software


From: Current Activity <us-cert () us-cert gov>
Date: Wed, 25 May 2011 10:25:51 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

Apple Mac Defender, MacProtector, and MacSecurity Fake Anti-Virus Software

Original release date: May 25, 2011 at 9:33 am
Last revised: May 25, 2011 at 9:33 am


Apple has released a security advisory related to the recent Mac fake
anti-virus software. The most common names for this fake anti-virus
software are MacDefender, MacProtector, and MacSecurity. This fake
anti-virus software is the result of a phishing scam targeting Mac
users that redirects them from legitimate websites to fake websites.
These fake websites notify the user that their computer is infected
with a virus, and the user is tricked into installing the fake
anti-virus software to solve the issue. The ultimate goal of the fake
anti-virus software is to steal the user's credit card information.

US-CERT encourages users to perform the following preventative
measures to help mitigate the risks:
  * Review Apple article HT4650 for avoidance and mitigation
    strategies.
  * Do not follow unsolicited web links or attachments in email
    messages.
  * Review the Recognizing Fake Antivirus document for additional
    information regarding fake antivirus software.

Apple plans to deliver a security update to address the issue. US-CERT
will provide additional details as they become available.

Relevant Url(s):
<https://www.us-cert.gov/cas/tips/ST10-001.html>

<http://support.apple.com/kb/ht4650>

====
This entry is available at
http://www.us-cert.gov/current/index.html#apple_mac_defender_macprotector_and

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBTd0RUz6pPKYJORa3AQKmXQf+INjOAIagRV1Z5kVHw+7f/DG6F78LMHRA
mUlXD/+xypn0Jw6qQToPs5Q05bPyl+xXGsF0KCi9Z5R87jfXBVMsI4VhJlsq13/l
4mPqUqYFp10jo1U0ifDEEjKGpb1VIxiKpWXiQeQill1XLDM9W/fVSDTm8M/PAdiV
SNVIPGJpn+3vOvZ/KD0j6qUrfkClaIgTlmRmVwJrlFm5E6zGlvC3jDw93tbm1h+P
hksTyW/2Ymch9uZ5xzowxVCSkRmNaEuic32CjDADBW0NkuHaY27o4IxGl7dDrLNq
/7Gxm7KbAU7uGZEovFXKTE6rb0S4P1xXcsy0L9vbh9Q/feQegdoNMg==
=CDPa
-----END PGP SIGNATURE-----


Current thread: