New hidden miner for Mac computers detected

The blog of Malwarebytes, a cyber-security company, has a post that says about a new virus infecting Mac computers with the hidden miner of cryptocurrency Monero (XMR).

About the threat to users of Apple products said the director of Malwarebytes for Mac and mobile devices, Thomas Reed. According to him, on computers that have managed to penetrate the virus and launch the “mshelper” process, a hidden mining program is launched that mines Monero cryptocurrency in favor of an unknown intruder.

The “mshelper” process itself is harmless and easy to remove, but while it works, much of the processing power of the processor is spent on mining.

“We’ve learned about the problem from posts on Apple’s forums where users complained about the“ mshelper ”malicious process, which is beginning to devour the processor’s computing resources. This program is not complicated and is deleted without any problems. We studied the behavior of this virus and found several more suspicious processes and copies of the virus, ”said Reed.

The virus consists of three parts of the dropper (media program that installs malware), the launcher and the miner itself, created on the basis of XMRig with open source.

So far, Malwarebytes experts cannot say for sure which program is a dropper, but as a rule these are fake installers of the Adobe Flash Player, although there may be other installation programs.

It is known that the program “pplauncher”, which installs the miner on the victim’s computer, is written in the Golang language, which is a rather strange choice. According to Reed, “using this language for such a simple task is a sign that the person who did this is not familiar with the Mac.”

At the end, Reed noted that “recently there has been an increased activity of miner viruses for both Mac and Windows. And yet, although I do not consider such software to be good, I would prefer to get infected with a miner than any other malicious program. ”

