• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Hackers infiltrate the popular software download site MacUpdate to distribute Mac cryptocurrency miner
  • Malware

Hackers infiltrate the popular software download site MacUpdate to distribute Mac cryptocurrency miner

Ddos February 8, 2018 2 minutes read

According to ibtimes media reported on February 6, security researcher SentinelOne network security company found that hackers use the popular software download site MacUpdate to Mac users to distribute a named OSX.CreativeUpdate encrypted currency mining mine, the main purpose is to hijack user devices CPU, secretly steal Monero.

According to the researchers, the official download link provided by the MacUpdate website has been replaced by a hacker, resulting in a user device being infected. In addition, the fake link domain names have been subtly changed to make them appear legitimate and convincing. Once a user downloads and installs, the legitimate website public.adobecc.com will be forced to install a payload and attempt to open a copy of the original application as a decoy to trigger malware activation.

Now through the investigation found that Firefox, OnyX and Deeper applications such as hackers replaced the download link. The reason why researchers think hackers choose these three applications is that they were developed by Platypus. Because Platypus development tools generate complete macOS applications from various scripts, such as shells or Python scripts, this means that the threshold for creating an application is not high.

It is reported, MacUpdate respect for the incident has apologized to the user, and how to delete the malware provides instructions.

  • Delete any copies of the above titles [Firefox, Onyx, Deeper] you might have installed.
  • Download and install fresh copies of the titles.
  • In Finder, open a window for your home directory (Cmd-Shift-H).
  • If the Library folder is not displayed, hold down the Option/Alt key, click on the “Go” menu, and select “Library (Cmd-Shift-L)”.
  • Scroll down to find the “mdworker” folder (~/Library/mdworker/).
  • Delete the entire folder.
  • Scroll down to find the “LaunchAgents” folder (~/Library/LaunchAgents/).
  • From that folder, delete “MacOS.plist” and “MacOSupdate.plist” (~/Library/LaunchAgents/MacOS.plist and ~/Library/LaunchAgents/MacOSupdate.plist).
  • Empty the Trash.
  • Restart your system.

The person in charge of MacUpdate advises users to check that they are legal before downloading software, and do not completely believe in the stars or reviews on third-party websites or the Mac App Store as these may be counterfeit.

Source: IBTimes

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. TA402 Uses IronWind Malware in Targeted Attacks
  2. Malware Exploiting IoT Devices on the Rise, SonicWall Warns
  3. Mint Stealer: New MaaS Malware Threatens Confidential Data
  4. Fake Game Hacks on YouTube Target Kids with Malware
  5. Meet ZynorRAT: The New Cross-Platform Malware Controlled via Telegram
Tags: MacUpdate

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.