{"id":17213,"date":"2019-12-16T11:10:02","date_gmt":"2019-12-16T19:10:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/12\/16\/news-10949\/"},"modified":"2019-12-16T11:10:02","modified_gmt":"2019-12-16T19:10:02","slug":"news-10949","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/12\/16\/news-10949\/","title":{"rendered":"Mac threat detections on the rise in 2019"},"content":{"rendered":"<p><strong>Credit to Author: Thomas Reed| Date: Mon, 16 Dec 2019 18:40:06 +0000<\/strong><\/p>\n<p>Conventional wisdom has been that, although not invulnerable to cyberthreats (<a rel=\"noreferrer noopener\" aria-label=\"as some old Apple ads would have you believe (opens in a new tab)\" href=\"https:\/\/www.youtube.com\/watch?v=eF7habaTvAY\" data-rel=\"lightbox-video-0\" target=\"_blank\">as some old Apple ads would have you believe<\/a>), Macs are afflicted with considerably fewer infections than Windows PCs. However, when reviewing our 2019 Mac detection telemetry, we noticed a startling upward trend. Indeed, the times, they are a-changin&#8217;.<\/p>\n<p>To get a sense of how Mac malware performed against all other threats in 2019, we looked at the top detections across all platforms: Windows PCs, Macs, Android, and iOS. Of the top 25 detections, six of them were Mac threats. Overall, Mac threats accounted for more than 16 percent of total detections.<\/p>\n<p>Perhaps 16 percent doesn&#8217;t sound impressive, but when you consider the number of devices on which these threats were detected, the results become <em>extremely<\/em> interesting. Although the total number of Mac threats is smaller than the total number of PC threats, so is the total number of Macs. Considering that our Mac user base is about 1\/12 the size of our Windows user base, that 16 percent figure becomes more significant.<\/p>\n<h3>Detections per device<\/h3>\n<p>The most interesting statistic that emerged from our data was how many Mac detections we saw per machine in 2019. On Windows, we saw 4.2 detections per device this year. Our Mac users, on the other hand, saw 9.8 detections per device\u2014more than double the amount of detections than Windows users.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"41578\" data-permalink=\"https:\/\/blog.malwarebytes.com\/mac\/2019\/12\/mac-threat-detections-on-the-rise-in-2019\/attachment\/2019-detections-per-endpoint\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/2019-detections-per-endpoint.png\" data-orig-size=\"871,625\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"2019 detections per endpoint\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/2019-detections-per-endpoint-300x215.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/2019-detections-per-endpoint-600x431.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/2019-detections-per-endpoint-600x431.png\" alt=\"\" class=\"wp-image-41578\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/2019-detections-per-endpoint-600x431.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/2019-detections-per-endpoint-300x215.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/2019-detections-per-endpoint.png 871w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<p>Of course, there are obviously biases in this data. For example, these machines are all devices with Malwarebytes installed, and many Mac users still believe antivirus software is not needed. This means the Macs represented by the data may be machines that already had some kind of suspected infection, which is why Malwarebytes was installed in the first place. <\/p>\n<p>However, the same could be said for PC users, who often believe that free Windows Defender is adequate protection, but then download Malwarebytes for Windows when their computer begins demonstrating signs of infection. Still, the overall threat detection rate for all Macs (and not just those with Malwarebytes installed) is likely not as high as this data sample. <\/p>\n<h3>Top five global threats<\/h3>\n<p>For the first time ever, Mac malware broke into the top five most-detected threats in the world. In fact, Mac malware represented the second- and fifth-most detected threats. <\/p>\n<p>The Malwarebytes detection ranked as the second-highest of 2019 is a <a rel=\"noreferrer noopener\" aria-label=\"Mac adware (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/101\/2015\/07\/faqs-about-mac-adware\/\" target=\"_blank\">Mac adware<\/a> family known as NewTab, clocking in at around 4 percent of our overall detections across all platforms. <\/p>\n<p>NewTab is adware that uses <a rel=\"noreferrer noopener\" aria-label=\"browser extensions (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/07\/third-party-dangers-ads-pipelines-and-plugins\/\" target=\"_blank\">browser extensions<\/a> to modify the content of web pages. It can be found in the form of Chrome extensions, with some older versions available as outdated Safari extensions. However, due to Apple phasing out support for these older Safari extensions in favor of extensions bundled inside apps, NewTab often poses as apps, such as flight trackers, maps\/navigation, email access, or tax forms.<\/p>\n<p>Recently, NewTab has proliferated and is using a variety of seemingly randomly-chosen names. Although some earlier variants tricked users into downloading an app from something like a fake flight or package tracking website, more recently these have been bundled into more widely-distributed <a href=\"https:\/\/blog.malwarebytes.com\/101\/2015\/07\/how-to-remove-adware-from-macs\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"adware bundle installers (opens in a new tab)\">adware bundle installers<\/a>.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"41577\" data-permalink=\"https:\/\/blog.malwarebytes.com\/mac\/2019\/12\/mac-threat-detections-on-the-rise-in-2019\/attachment\/newtab-examples\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/NewTab-examples.png\" data-orig-size=\"1318,660\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"NewTab examples\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/NewTab-examples-300x150.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/NewTab-examples-600x300.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/NewTab-examples-600x300.png\" alt=\"\" class=\"wp-image-41577\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/NewTab-examples-600x300.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/NewTab-examples-300x150.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/NewTab-examples.png 1318w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption>Samples of NewTab apps<br \/><\/figcaption><\/figure>\n<p>In fifth place, at 3 percent of the total detections, we see a detection named <a rel=\"noreferrer noopener\" aria-label=\"PUP.PCVARK (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/detections\/pup-pcvark\/\" target=\"_blank\">PUP.PCVARK<\/a>. These are a variety of <a rel=\"noreferrer noopener\" aria-label=\"potentially unwanted programs (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2019\/01\/users-right-to-choose-why-malwarebytes-detects-potentially-unwanted-programs-pups\/\" target=\"_blank\">potentially unwanted programs<\/a> from a particular developer, most of them clones of Advanced MacKeeper. (This app was so notorious that its site was eventually blacklisted by Google Safe Browsing, which is not something that typically happens for PUPs.)<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>PUP (n): abbreviation for potentially unwanted program<\/p>\n<p>PUPs are programs that are generally not installed intentionally by the user, or that may use a variety of scare tactics or other unethical techniques to trick the user into installing or purchasing.<\/p>\n<\/blockquote>\n<h3>Growing Mac threat<\/h3>\n<p>If we delve further into our data, we see that Mac detections primarily consist of adware and PUPs. Traditional, &#8220;full&#8221; malware does exist for the Mac, of course, but it tends to be more targeted or otherwise limited in scope. For example, the <a rel=\"noreferrer noopener\" aria-label=\"Mokes and Wirenet malware (opens in a new tab)\" href=\"https:\/\/www.securityweek.com\/mac-malware-delivered-firefox-exploits-analyzed\" target=\"_blank\">Mokes and Wirenet malware<\/a> targeted Mac users through a Firefox vulnerability this year, but only users at certain <a href=\"https:\/\/blog.malwarebytes.com\/101\/2017\/11\/cryptocurrency-works-cybercriminals-love\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"cryptocurrency (opens in a new tab)\">cryptocurrency<\/a> companies were targeted, so infections were not widespread.<\/p>\n<p>We&#8217;ve known for a long time that the &#8220;Macs don&#8217;t get viruses&#8221; wive&#8217;s tale was completely wrong. As time goes on, though, we&#8217;re seeing that Macs are increasingly popular targets, and the bad guys are ramping up their efforts to get a piece of the Mac market. If you use a Mac, stay alert, <a href=\"http:\/\/www.malwarebytes.com\/mac\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"use antivirus software (opens in a new tab)\">use antivirus software<\/a>, and don&#8217;t allow yourself to be lulled into a false sense of security.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/mac\/2019\/12\/mac-threat-detections-on-the-rise-in-2019\/\">Mac threat detections on the rise in 2019<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/mac\/2019\/12\/mac-threat-detections-on-the-rise-in-2019\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Thomas Reed| Date: Mon, 16 Dec 2019 18:40:06 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/mac\/2019\/12\/mac-threat-detections-on-the-rise-in-2019\/' title='Mac threat detections on the rise in 2019'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/shutterstock_1428590726.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>For the first time ever, Mac threats broke into Malwarebytes&#8217; top five overall detections of 2019. Take a look at this and other telemetry that shows Mac malware is certainly on the rise.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/mac\/\" rel=\"category tag\">Mac<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/browser-extensions\/\" rel=\"tag\">browser extensions<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mac-adware\/\" rel=\"tag\">Mac adware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mac-malware\/\" rel=\"tag\">mac malware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mac-telemetry\/\" rel=\"tag\">mac telemetry<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mac-threat-detections\/\" rel=\"tag\">mac threat detections<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mac-threats\/\" rel=\"tag\">mac threats<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/newtab\/\" rel=\"tag\">newtab<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/potentially-unwanted-programs\/\" rel=\"tag\">potentially unwanted programs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pups\/\" rel=\"tag\">PUPs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/safari\/\" rel=\"tag\">safari<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/mac\/2019\/12\/mac-threat-detections-on-the-rise-in-2019\/' title='Mac threat detections on the rise in 2019'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/mac\/2019\/12\/mac-threat-detections-on-the-rise-in-2019\/\">Mac threat detections on the rise in 2019<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[19414,10454,19943,11976,23773,23774,23775,23776,11279,2130,10543],"class_list":["post-17213","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-browser-extensions","tag-mac","tag-mac-adware","tag-mac-malware","tag-mac-telemetry","tag-mac-threat-detections","tag-mac-threats","tag-newtab","tag-potentially-unwanted-programs","tag-pups","tag-safari"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17213"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17213\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}