Mac Malware Ducks Apple’s Defenses, Reads Your Email

Editor's Note: This article originally appeared on Laptop Mag.

OSX/Dok is the latest sophisticated piece of spyware to target MacBooks and other macOS machines, and it hit systems quite quickly by exploiting a security flaw in the desktop operating system. That flaw? The fact that a legitimate Apple developer's certificate, which you can get for $99 straight from Apple, will bypass Gatekeeper, the operating system's first line of defense.

Image: Jeremy Lips/Laptop Mag

Image: Jeremy Lips/Laptop Mag

OSX/Dok's distributors used the age-old tactic of targeting victims with a email attachment, which in this case contained malware that was signed with a legitimate Apple Developer Certificate. With that certificate, OSX/Dok could casually walk past macOS's Gatekeeper security like it owned the place, trick the user into giving it admin rights, then proceed to spy on the user's encrypted communications, including Gmail and online financial transactions.

MORE: Best Antivirus Protection for PC, Mac and Android

The malware, according to a blog post late last week by the Israeli security firm Check Point, comes bundled into an email attachment dubbed "Dokument.zip" attached to German-language emails claiming to be from Swiss government agencies inquiring about tax-return inconsistencies.

Once a user opens said ZIP file, the malware copies itself to the Users/Shared directory, then deletes the original copy in the Downloads directory. It then alerts the user with a fake error message claiming that the system can't open the Dokument file, and nags the user to enter his or her administrative credentials to install a system update. It won't let the user close the nag window until he or she relents.

Of course, providing OSX/Dok with admin credentials simply supercharges its abilities and allows the malware to execute high-level processes in the background, essentially owning your system.

Once it does so, OSX/Dok installs a Tor client and re-routes your web traffic through a proxy server, It even uses a (presumably stolen) web-security certificate to decrypt secure communications, then re-encrypt them on route so that the HTTPS padlock icon stays in place and the user is none the wiser. By performing that man-in-the-middle attack, OSX/Dok might be able to read your Gmail and Facebook postings, or even steal information about online purchases or online bank accounts.

MacWorld's Glenn Fleishman reported today (May 1) that Apple has revoked the developer certificate used by OSX/Dok. Gatekeeper should now block the malware if you leave it on its default settings, but it wouldn't take much of an update to OSX/Dok to try to trick the user into temporarily disabling Gatekeeper.

So, what can you do?

  • First off, just because you have a Mac doesn't mean you don't need antivirus software. Here are our favorite picks for macOS machines.
  • As always, we advise users to never open up email attachments they are not 100 percent certain about.
  • And for complete security, install the free XFENCE tool that stops rogue apps from taking over your system.
TOPICS
Henry T. Casey
Managing Editor (Entertainment, Streaming)

Henry is a managing editor at Tom’s Guide covering streaming media, laptops and all things Apple, reviewing devices and services for the past seven years. Prior to joining Tom's Guide, he reviewed software and hardware for TechRadar Pro, and interviewed artists for Patek Philippe International Magazine. He's also covered the wild world of professional wrestling for Cageside Seats, interviewing athletes and other industry veterans.

Latest in Malware & Adware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in News
Nintendo Switch 2
Nintendo Switch 2 tipster may have just leaked release month and launch plans
Disney Plus logo
Disney Plus upgrade just fixed one of my biggest problems with the home page
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features