4 ms·
Has anyone seen Mac malware that involves hyjacking accessibly/mouse input? I've come across several Macs in the last year with mysterious self moving cursors.
by jsz0 4y ago
Has anyone seen Mac malware that involves hyjacking accessibly/mouse input? I've come across several Macs in the last year with mysterious self moving cursors. I don't know what benefit there would be for malware to hyjack a mouse cursor so my assumption is they simply have hardware problems with their trackpads. Makes me paranoid tough.
- duxup 4y agoTypically random mouse movements are Bluetooth mice people forget are connected. I suggest checking for that/ disable Bluetooth to see what happens.
- kitsunesoba 4y agoYeah, I'd bet that this is what is happening. A few times in the offices of my workplaces I've seen cases of BT keyboards and mice randomly reconnecting to Macs they'd been paired with at some point in the past (even years back) and causing a short bout of chaos.
- varenc 4y agoI'm doubtful. It's certainly possible for malware to hijack mouse/keyboard control, with a local privilege escalation exploit, but I'm not sure what the point would be. Escalating to mouse/keyboard control is hard and any malware capable of doing that likely wouldn't need to.
- LeSaucy 4y agoAny app that allows accessibility persmissions has access. For example, I run a program called "Jiggler" whos job it is to jiggle my mouse during work hours as to prevent the teams "Away" status.
- 0xCMP 4y agoIf it's a closed laptop sometimes when they get very warm the touch pad starts getting activated. At least that is what the problem was for me a few years ago with Intel MBPs. There is an option to disable the track pad when using an external keyboard which was the perfect solution.
- btgeekboy 4y agoI once spent far, far too much time debugging my “broken” laptop to realize a book was touching the corner of my external trackpad that I wasn’t actively using.
- Mandatum 4y agoWould be a trivial way of pretending the user is active and preventing sleep, useful for miners or ensuring the device is accessible when the attacker is online. However, Apple has made substantial changes to how it handles hardware and system-level extensions, and I doubt this would be possible without exploiting either the OS or existing software on the system. It would require a sysadmin to install, as the approval process requires accessibility access.