IT之家 6 月 6 日消息,网络安全公司 MacPaw 旗下 Moonlock Lab 于 6 月 4 日发布博文,表示近期有黑客通过 macOS 破解版 CleanMyMac 或 Photoshop 等主流应用,分发新型 Mac 恶意软件。
Mac 设备一旦感染该恶意软件,该恶意软件就会使用 AppleScript 诱骗用户泄露密码,从 Chrome 和 Safari 等浏览器中窃取 cookies,如果恶意软件检测到在虚拟机上运行就会自毁。
脚本首先会从系统中获取当前用户名以及其他重要的系统路径,以供日后使用。然后,它会创建一个临时文件夹来存储被盗数据,然后再将其发送出去。
该脚本会窃取 Chrome 浏览器和 Safari 等网络浏览器中敏感的用户信息,如浏览历史、cookie 和保存的密码。IT之家从报道中获悉,该脚本的另一个功能是能够查找和访问流行的加密货币钱包,可以窃取钱包文件,使攻击者有可能访问受害者的加密资产。
脚本会复制“login.keychain-db”文件,该文件保存着密码和敏感凭证等 macOS 钥匙串数据,还会通过复制“oteStore.sqlite”和相关文件从 Apple Notes 中获取数据。

","del":0,"gnid":"97b81ab1b33d8181b","img_data":[{"flag":"2","img":[{"desc":"","height":"660","title":"","url":"http://p9.img.360kuai.com/t11508c75c8e445da19993f4a24.jpg","width":"1024"},{"desc":"","height":"493","title":"","url":"http://p9.img.360kuai.com/t11508c75c82e0fb4aaf9c4f47c.jpg","width":"1312"}]}],"original":0,"pat":"art_src_1,fts0,sts0","powerby":"cache","pub_time":1717603200000,"pure":"","rawurl":"http://zm.news.so.com/30568e7a664049bd108cd622c328ae77","redirect":0,"rptid":"dbb32380ae1e4f95","rss_ext":[],"s":"t","src":"IT之家","tag":[{"clk":"ktechnology_1:apple","k":"apple","u":""},{"clk":"ktechnology_1:mac","k":"mac","u":""},{"clk":"ktechnology_1:黑客","k":"黑客","u":""}],"title":"慎用 macOS 破解版应用,黑客用于分发恶意软件","type":"zmt","wapurl":"http://zm.news.so.com/30568e7a664049bd108cd622c328ae77","ytag":"科技:互联网:互联网安全","zmt":{"brand":{},"cert":"IT之家官方账号","desc":"爱科技,爱这里 - 前沿科技人气平台","fans_num":29241,"id":"2951916302","is_brand":"0","name":"IT之家","new_verify":"5","pic":"https://p0.img.360kuai.com/t01d48572270765952c.jpg","real":1,"textimg":"https://p9.img.360kuai.com/bl/0_3/t017c4d51e87f46986f.png","verify":"0"},"zmt_status":0}","errmsg":"","errno":0}