Skip to main content

Mac malware has been found hidden in file converter on major site

macos sierra update windows 10 creators install features
Bill Roberson/Digital Trends
A new piece of malware targeting Macs has been found in the wild, following hot on the heels of the first piece of ransomware for the platform, which was unearthed earlier this year. The malware is being referred to as Backdoor.MAC.Elanor, and it provides further evidence that Macs aren’t as impervious to attack as they were once assumed to be.

The backdoor is apparently being hidden away in a phony file converter utility that’s being distributed via major sites like MacUpdate, according to a report from 9to5Mac. EasyDoc Converter purports to be a legitimate piece of software, but offers no functionality beyond downloading the backdoor.

MacUpdate has now been alerted to the issue, and has removed download links to the utility and delisted it from its search results. However, EasyDoc Converter is likely hosted on scores of different websites, and there could potentially be plenty of other fake pieces of software serving to distribute the backdoor.

Backdoor.MAC.Elanor could potentially be used to facilitate all manner of attacks on a victim’s computer. A hacker could use the backdoor in conjunction with other techniques to execute attacks ranging from data theft to a complete takeover of the system’s webcam.

Fortunately, the malicious app is not signed with an Apple Developer ID, which should make it easier for Mac users to avoid the backdoor. So long as your computer’s settings stipulate that it will only open apps from the App Store or from known developers, it shouldn’t be able to open.

However, there’s an important lesson about security to be learned here. There was a time when Macs weren’t considered to be at risk of malware attacks to the same extent that PCs are — evidently, that is no longer the case.

Editors' Recommendations

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
The Magic Mouse has been fixed, but not by Apple
Magic Mouse next to a Mac keyboard on a desk.

The design of Apple's Magic Mouse continues to be a major complaint among Mac users, a blight on Apple's otherwise fantastic design choices. The ergonomics are inhuman, it still uses a Lightning charging port (even on the new M3 iMac), and it can't be charged while being used.

However, an engineer has introduced his design concept that would not only solve the charging issue on the Magic Mouse but also make the design ergonomic and comfortable for natural handling.

Read more
The MacBook Pro M3 doesn’t have a memory problem — it has a pricing problem
The MacBook Pro open on a table in front of a couch.

Apple just upset everyone, claiming that the 8GB of Unified Memory available in the base MacBook Pro M3 is "probably analogous to 16GB on other systems."

The MacBook Pro M3 has already come under fire for only including 8GB of Unified Memory in its base configuration, which runs $1,600. MacWorld recently ran a story criticizing the 8GB of memory in the MacBook Pro M3, saying, "If 8GB will be a bottleneck for many today, imagine the performance of that non-upgradeable laptop in a few years’ time."

Read more
Hackers are using this incredibly sneaky trick to hide malware
A hacker typing on an Apple MacBook laptop, which shows code on its screen.

One of the most important things you can do to protect your online security is install one of the best password managers, but a recent cyberattack proves that you have to be careful even when doing that. Thanks to some sneaky malware hidden in Google Ads, you could end up with viruses riddling your PC.

The issue affects popular password manager KeePass -- or rather, it attempts to impersonate KeePass by using misleading Google Ads. First spotted by Malwarebytes, the nefarious link appears at the top of search results, meaning you’ll likely see it before the legitimate websites that follow beneath it.

Read more