Newly discovered Mac malware uses “fileless” technique to remain stealthy
arstechnica.com
arstechnica.com
Exploit vuln -> download malware payload -> execute malware
...
> The malware isn’t entirely fileless. The first stage poses as a cryptocurrency app with the file name UnionCryptoTrader.dmg
Come on...
https://objective-see.com/blog/blog_0x51.html
The 'fileless' part is about getting the executable payload that does the actual malwarin' into memory without touching the filesystem.
Check if you're affected:
ls /Library/LaunchDaemons/vip.unioncrypto.plist
ls /Library/UnionCrypto/unioncryptoupdaterBut also how many layman users are going to crypto exchanges on a mac?
Yet here it is; still on Ars Technica.
Am I to infer that Apple censured this story in their News App?
Its not appearing as a story in the Ars Technica channel, even thought it was recently posted.
Does this then suggest that this is a hot issue for Apple?
I mean, I guess that's possible, but it seems much more likely that this is just a bug. The Apple News app can be weird sometimes.
It doesn't feel like censorship from what I've experienced, more like a link going stale or something - theres not really any common themes in the articles ice noticed.
So how many stories don't get through. Is it that tricky to get a feed of stories and match them up with items appearing in the newsfeed?
If its not going through you go back and check to see where the story is lost. I've done this on websites I was supporting, finding that people copying and pasting from PDF seem to have picked up a number of unicode control characters that hadn't been rinsed out when stored in SQL, and caused the web API to splutter.
This was for item records clients were paying for so dropping records looks a bit naff.
Enough of me though, dare I say it News has just one job, to show news.