Blog | G5 Cyber Security

Mac malware intercepts encrypted web traffic for ad injection

Malwarebytes for Mac detects as OSX.SearchAwesome for Mac OSX OSX. Malware is found on a rather bland disk image file without any of the usual decorations that could make it look like a legitimate installer. The only evidence that it is doing anything at all comes from two authentication requests. The second is to allow something called spi to modify the network configuration. With the certificate, the software is able to do this not just with unencrypted http traffic, but also with encrypted https traffic.”]

Source: https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/

Exit mobile version