Mac and MacBook hit with ‘Cuckoo’ malware stealing sensitive information

 

What we know about the ‘Cuckoo’ malware

 

MORE: TWO NEW STEALTH MALWARE THREATS ARE TARGETING THOSE OF YOU WHO USE MACS

 

How does it work?

Cuckoo is distributed via malicious websites that promote a supposed tool for ripping music from streaming services and converting these into .MP3 files. This tool is offered in free and paid versions, tempting users to download and install it. Once installed, the malware relies on annoying and persistent pop-ups using LaunchAgent, a method used in other malware campaigns like XLoader.

 

Who is behind Cuckoo?

No one threat actor has taken responsibility for the malware campaign. Still, it’s worth noting that Cuckoo refuses to operate if the device is located in certain countries—like Kazakhstan, Russia, Belarus, Ukraine, and Armenia—which could mean it’s coming from a group in one of these countries or operating out of this region as a whole.

 

MORE: BEWARE OF ENCRYPTED PDFS AS THE LATEST TRICK TO DELIVER MALWARE TO YOU

 

How to keep yourself safe from malware attacks

1) Use good antivirus software: Install and maintain reliable antivirus protection tailored for macOS. 

Best Antivirus Protection 2024

2) Don’t get software from strangers

3) Check the software maker’s credentialsBefore installing any software, check the developer’s credentials and read reviews to ensure their legitimacy. This is particularly important for software that handles sensitive information.

4) Stay fresh. Perform regular updates

5) Enable firewall

6) Be wary of strange requests

7) Use strong passwords and 2FA

8) Backup your data

9) Create strong passwords:

 

MORE: HOW CRYPTO IMPOSTERS ARE USING CALENDLY TO INFECT MACS WITH MALWARE

 

Kurt’s key takeaways

With the rise of more cyber attacks aiming at Mac and MacBook, have you added protection to help keep out the bad guys? Or worse, has one infected you yet?  Let us know in the comments below. 

FOR MORE OF MY SECURITY ALERTS, SUBSCRIBE TO MY FREE CYBERGUY REPORT NEWSLETTER HERE

 

 

Copyright 2024 CyberGuy.com.  All rights reserved.  CyberGuy.com articles and content may contain affiliate links that earn a commission when purchases are made.

Related posts

Is your Social Security number at risk? Signs someone might be stealing it

Updated Android malware can hijack calls you make to your bank

Robot dog is making waves with its underwater skills