OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
intego.com
intego.com
Or turned it off after the first sample. Or switches proxies randomly. It's good they brought up that the IP can be masked, but they could go one step further...
sudo vi /etc/auto_master
#/net -hosts -nobrowse,hidefromfinder,nosuid
For home users, unfortunately there isn't a simple solution for preventing this type of attack, until or unless Apple releases a macOS security update to mitigate the vulnerability. Cavallarin describes a possible temporary mitigation (opening /etc/auto_master in a text editor and adding # to the beginning of the line that starts with /net).
The first legit feature is automount (aka autofs) that allows a user to automatically mount a network share just by accessing a "special" path, in this case, any path beginning with "/net/". [..]
[1] https://www.fcvl.net/vulnerabilities/macosx-gatekeeper-bypas...
Assumably commenting out the line quoted by gp disables automount for network shares which start with "/net" in their path.
Wait, what? This makes no sense: dynamic linking means that it would pull in different libraries on the user’s machine…
> [...] creating a symbolic link (or "symlink"—similar to an alias) to an app hosted on an attacker-controlled Network File System (NFS) server, and then creating a .zip archive containing that symlink [...]
Most Mac users know that Flash is a piece of malware itself and would never be fooled into installing it.