Skip to main content

New MacDefender malware infecting unsuspecting Apple users

installerIt’s easy to get lured into a false sense of security as a Mac user – after all, Apple’s personal computers are paraded about as virus immune machines.  Of course that isn’t a catch-all, and a new report from the Intego Mac Security Blog says there is new malware targeting Mac computers. Apple Discussion forums are also rife with complaints of a program called MacDefender (not to be confused with this site).

The trojan appears to be targeting users browsing Google Images via Safari, who receive a notice claiming their system is infected and they need to install a MacDefender application to remove viruses. MacDefender is able to bypass Safari’s protection system, which automatically accepts trusted software. MacDefender then relaunches every time a user logs in or restarts the computer. There are no terribly obvious effects: The virus doesn’t install anything to run in the background, but it does attempt to swindle users into buying the application via credit card.

MacDefender is using SEO poisoning tactics to infiltrate the systems, meaning that the virus is using popular search terms and forcing its own malicious site to the top of the search results. Unlike most malware and spyware, the link appears completely credible and clicking it allows the trojan to automatically open via Safari’s “Open Safe Files” feature.

The good news is that MacDefender doesn’t really have the potential to spread like wildfire. You first have to search for the specific search term, click on the malware infected option, and authorize installation. The bad news is that it’s fairly hard to spot and has an incredibly professional feel to it. Intego points out that it’s also opening pornographic web pages periodically to try and convince users they have a virus worth buying MacDefender’s supposed software to remove.

If you want to protect yourself

If you haven’t been affected by MacDender and want it to stay that way, simply uncheck the “open safe files after downloading” option by going to Safari, Preferences, and then General. You could also use an alternative browser. Another option is to defer to running in Standard of Managed mode, versus as an Administrator – this just keeps viruses from being able to access every nook and cranny of your system.

safari-safe open
Image used with permission by copyright holder

If you’ve been infected

If your system has already been infected, The Next Web explains how you can fairly easily get rid of MacDefender.

  1. Go to Applications, and then Utilities to check the Activity Monitor. Disable anything with “MacDefender” in the name.
  2. Go to Library, Startup Items, and in there look for in LaunchAgents and LaunchDaemons for anything with “MacDefender” in the name. Quit any running applications.
  3. Go back to the Applications folder and drag and drop MacDefender from there to the trash. Delete trash.
  4. Search for anything on your system with “MacDefender” in the name and delete anything returned.

Editors' Recommendations

Molly McHugh
Former Digital Trends Contributor
Before coming to Digital Trends, Molly worked as a freelance writer, occasional photographer, and general technical lackey…
These are the 10 settings I always change on a new Mac
A MacBook Air on a desk with an open book in front of it.

Every time I buy a new Mac, there are a bunch of settings I change to improve the macOS experience. Some are quick tweaks that solve minor annoyances, while others are vital changes that make my Mac safer, faster, or just plain better.

I recently wrote about a few key settings to change in macOS Sonoma, but the ones contained in the article you’re perusing now aren’t just for Apple’s latest operating system. Whether you’re running an earlier version of macOS or are reading this long after Sonoma has become old news, there are plenty of macOS settings you can adjust to get more from your Mac.
Turn on FileVault

Read more
Apple’s new M3 Macs could launch any day now, leak claims
A MacBook Pro running macOS Sonoma at Apple's Worldwide Developers Conference (WWDC) in June 2023.

We’ve heard for months that Apple’s brand-new Macs with M3 chips will be launching in the fall, but a fresh leak suggests their release could be just around the corner. If you’ve been waiting to upgrade, your moment may have almost arrived.

The information comes from the news site MacRumors, which cites “a verified source” in its report. According to the outlet, Apple is about to change the list of Macs available to be traded in at the company’s stores.

Read more
Apple fixed one of my biggest macOS gripes with Sonoma — but I still want more
Federighi talking about Continuity Camera.

Apple’s macOS Sonoma update has just been launched and, let’s be honest here, it’s a pretty modest upgrade (probably thanks to the work required on the Vision Pro’s software). Still, when Apple unveiled Sonoma a few months ago, there was one feature that got me excited: Continuity Camera.

This nifty tool lets you use your iPhone as a high-quality webcam. Sure, it actually debuted with macOS Ventura, but this year we’ve got much more control over how it works. Sliders! Toggles! Yes, it’s all here.

Read more