3 ms·
We don't actually know what attack vector it's using so it's pretty much impossible to say at this point. It could be a simple trojan or it could be an advanced
by 2cb 6y ago
We don't actually know what attack vector it's using so it's pretty much impossible to say at this point. It could be a simple trojan or it could be an advanced 0day chain. We have no clue.
There'd be no point manually creating the file, by the time the malware sees it, you are already infected.
My advice: keep your OS and browser and everything else updated, use uBlock Origin in the browser, and use a network-wide ad blocker (Pi Hole, AdGuard Home - personally I prefer the latter) with a few malware blocklists and keep them updated.
Malwarebytes were the ones who discovered how big this thing is so you can install that on your Mac and run scans.
You may also want to invest in Little Snitch which won't necessarily protect you against an infection but it will alert you to the calls the malware keeps making to its C&C servers. It's also entirely possible the self-destruct mechanism they found is triggered by such software being installed on the machine. Past Mac malware often removes itself if it detects Little Snitch.
And, obviously, don't install random software from shady sources, but I assume anyone on HN knows this already.
- pfortuny 6y agoSee PROTIP above by lapcatsoftware (several threads above)
- forgotmypw17 6y agoOne more: browse the web without JS, except on trusted sites, and tell everyone else to sod off. Bonus: Avoid a lot of low-quality content.