Digita Security

Cybersecurity solutions for the

  • modern
  • mobile
  • independent
  • innovative
  • enterprising

macOS workforce

11.06.2017 ( Version 2096 )

XProtect_OSX_Mughthesec_B


OSX/Mughthesec is macOS Adware that masquerades as a Flash Installer named Player.dmg. The installer is legitimately signed and was written with VM and AV avoidance techniques. Upon execution of the installer, Adware and other Potentially Unwanted Programs (PUPs) are offered along with the Flash player install. Once accepted the malware installs a Safari extension and hijacks the user's search experience and homepage to serve its advertising [1].

References:
  1. https://objective-see.com/blog/blog_0x20.html