{"id":8529,"date":"2018-01-24T16:24:17","date_gmt":"2018-01-24T16:24:17","guid":{"rendered":"https:\/\/igotoffer.com\/blog\/?p=8529"},"modified":"2022-12-29T20:20:31","modified_gmt":"2022-12-29T20:20:31","slug":"mami-malware-struck-macos","status":"publish","type":"post","link":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos","title":{"rendered":"MaMi Malware Struck MacOS"},"content":{"rendered":"<h2>MaMi Malware Struck MacOS<\/h2>\n<h3>What is MaMi Malware?<\/h3>\n<p>MaMi is a DNS hijacker. While Windows users are well acquainted with different kinds of malwares, Mac owners are not. For many years Apple products were considered as virus-safe ones. Recently, the situation has changed. The thing is, MacBooks and iMacs became very popular and virus makers turned their attention to them.<br \/>\nWhat does it do to my computer?<\/p>\n<p>It changes the DNS you use to enter the Web. Domain Names System is like a navigator for your computer. It names all the other computers and servers and maps the path for you. Now imagine what will happen if someone doctored your navigator and messed up your routes and destination points. You\u2019ll get lost and won\u2019t get anywhere.<\/p>\n<p>In the computer world it means you\u2019ll get nowhere at all as well. You won\u2019t be able to reach any site. The DNS hijackers may look innocent enough when compared to other malwares, but they are very dangerous. They can covertly download other malwares and viruses and even turn your computer into a bot.<\/p>\n<h3>Who discovered it?<\/h3>\n<p>The first victim of MaMi malware was an unknown teacher. She had a friend ask on her behalf on a Malwarebytes forum , and was able to get some answers. Simultaneously, a cyber security expert Patrick Wardle, who happened to be researching this in his own blog for a bit, came up with a few solution tips of his own.<\/p>\n<h3>What does it look like?<\/h3>\n<p>If your computer is infected, your DNS will change and you can identify this in the System Preference app (Network pane). What the malicious DNS can look like:<\/p>\n<div id=\"attachment_8560\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-8560\" loading=\"lazy\" class=\"wp-image-8560 size-full\" src=\"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/malicious-dns.png\" alt=\"What the malicious DNS can look like\" width=\"600\" height=\"506\" srcset=\"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/malicious-dns.png 600w, https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/malicious-dns-300x253.png 300w, https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/malicious-dns-178x150.png 178w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-8560\" class=\"wp-caption-text\">What the malicious DNS can look like. Image source: <a href=\"https:\/\/objective-see.com\" target=\"_blank\" rel=\"noopener\">Objective-See.com<\/a>.<\/p><\/div>\n<p>Looking into the System Preference is the only way to detect MaMi so far. It\u2019s a fresh malware and it is not yet listed in the Virus Total. Likewise, it cannot be detected by AV softwares. The cunning malware immediately downloads a certificate to disguise itself as a properly signed app.<\/p>\n<p>The cloudguard.me certificate can be found in the System Keychain:<\/p>\n<div id=\"attachment_8561\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-8561\" loading=\"lazy\" class=\"size-full wp-image-8561\" src=\"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/cloudguard-me-certificate.png\" alt=\"The cloudguard.me certificate can be found in the System Keychain\" width=\"600\" height=\"432\" srcset=\"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/cloudguard-me-certificate.png 600w, https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/cloudguard-me-certificate-300x216.png 300w, https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/cloudguard-me-certificate-208x150.png 208w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-8561\" class=\"wp-caption-text\">The cloudguard.me certificate can be found in the System Keychain. Image source: <a href=\"https:\/\/objective-see.com\" target=\"_blank\" rel=\"noopener\">Objective-See.com<\/a>.<\/p><\/div>\n<h3 style=\"text-align: center;\">How can I get rid of MaMi?<\/h3>\n<p>Since there\u2019s no AV tool to exterminate the malware, Patrick Wardle\u2019s advice is to re-install the macOS. if you&#8217;re an advanced user you can try and reset the DNS servers according to the manual that he has posted in his blog. [https:\/\/objective-see.com\/blog\/blog_0x26.html]\n<h3 style=\"text-align: center;\">Will any protection by AVs eventually be created?<\/h3>\n<p>Sure! But the protection will take time to develop. MaMi, for instance, is a very complicated malware. The DNS servers it used were the only thing that betrayed its presence. You see, these very DNS servers were used for the Windows DNS hijackers many years ago.<\/p>\n<p>So someone somewhere took the time to re-invent the malware for the macOS. So, there will be more to come this way.<\/p>\n<h2>Links<\/h2>\n<ul>\n<li><a href=\"http:\/\/www.zdnet.com\/article\/mami-malware-targets-mac-os-x-dns-settings\/\" target=\"_blank\" rel=\"noopener\">MaMi malware targets Mac OS X DNS settings<\/a> &#8211; ZDNet<\/li>\n<li>Thinking to <a href=\"https:\/\/igotoffer.com\" target=\"_blank\" rel=\"noopener\">sell your Mac<\/a>? iGotOffer is the best place to sell cumputers and other devices online.<\/li>\n<li><a href=\"https:\/\/igotoffer.com\/apple\/\" target=\"_blank\" rel=\"noopener\">Everything About Apple\u2019s Products<\/a> &#8211; The complete guide to all Apple consumer electronic products, including technical specifications, identifiers and other valuable information.<\/li>\n<\/ul>\n<h2>[FIX] macOS MaMi DNS Hijacking Malware Identifying and Removal [Video]<\/h2>\n<div class=\"ytb\">\n<p style=\"text-align: center;\"><iframe title=\"[FIX] macOS MaMi DNS Hijacking Malware Identifying and Removal\" width=\"620\" height=\"349\" src=\"https:\/\/www.youtube.com\/embed\/RE27t68VteQ?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe>\n<\/p>\n<\/div>\n<p style=\"text-align:center\">Video uploaded by <a class=\"yt-simple-endpoint style-scope yt-formatted-string\" rel=\"noopener noreferrer\" href=\"https:\/\/www.youtube.com\/@dailytut\" target=\"_blank\">dailytut<\/a> on <strong class=\"watch-time-text\">January 16, 2018<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>MaMi Malware Struck MacOS What is MaMi Malware? MaMi is a DNS hijacker. While Windows users are well acquainted with different kinds of malwares, Mac owners are not. For many years Apple products were considered as virus-safe ones. Recently, the situation has changed. The thing is, MacBooks and iMacs became very popular and virus makers [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":8558,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[442,460],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v19.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>MaMi Malware Struck MacOS | iGotOffer<\/title>\n<meta name=\"description\" content=\"What is MaMi Malware? MaMi is a DNS hijacker. While Windows users are well acquainted with different kinds of malwares, Mac owners are not. For many years Apple products were considered as virus-safe ones.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"MaMi Malware Struck MacOS | iGotOffer\" \/>\n<meta property=\"og:description\" content=\"What is MaMi Malware? MaMi is a DNS hijacker. While Windows users are well acquainted with different kinds of malwares, Mac owners are not. For many years Apple products were considered as virus-safe ones.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos\" \/>\n<meta property=\"og:site_name\" content=\"iGotOffer Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/iGotOffer\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/svetlana.ustinova2\" \/>\n<meta property=\"article:published_time\" content=\"2018-01-24T16:24:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-29T20:20:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/mami-malware-struck-macos.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@iGotOffer\" \/>\n<meta name=\"twitter:site\" content=\"@iGotOffer\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Steve\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/igotoffer.com\/blog\/#website\",\"url\":\"https:\/\/igotoffer.com\/blog\/\",\"name\":\"iGotOffer Blog\",\"description\":\"News and reviews about electronics &amp; apps\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/igotoffer.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#primaryimage\",\"url\":\"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/mami-malware-struck-macos.jpg\",\"contentUrl\":\"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/mami-malware-struck-macos.jpg\",\"width\":600,\"height\":400,\"caption\":\"MaMi Malware Struck MacOS\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#webpage\",\"url\":\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos\",\"name\":\"MaMi Malware Struck MacOS | iGotOffer\",\"isPartOf\":{\"@id\":\"https:\/\/igotoffer.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#primaryimage\"},\"datePublished\":\"2018-01-24T16:24:17+00:00\",\"dateModified\":\"2022-12-29T20:20:31+00:00\",\"author\":{\"@id\":\"https:\/\/igotoffer.com\/blog\/#\/schema\/person\/2e5559af8f4c85b3c121b665ccef1e16\"},\"description\":\"What is MaMi Malware? MaMi is a DNS hijacker. While Windows users are well acquainted with different kinds of malwares, Mac owners are not. For many years Apple products were considered as virus-safe ones.\",\"breadcrumb\":{\"@id\":\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/igotoffer.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"MaMi Malware Struck MacOS\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/igotoffer.com\/blog\/#\/schema\/person\/2e5559af8f4c85b3c121b665ccef1e16\",\"name\":\"Steve\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/igotoffer.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ef902dfdf5f1c30f261fa557b8d6d80a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ef902dfdf5f1c30f261fa557b8d6d80a?s=96&d=mm&r=g\",\"caption\":\"Steve\"},\"sameAs\":[\"https:\/\/igotoffer.com\/\",\"https:\/\/www.facebook.com\/svetlana.ustinova2\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"MaMi Malware Struck MacOS | iGotOffer","description":"What is MaMi Malware? MaMi is a DNS hijacker. While Windows users are well acquainted with different kinds of malwares, Mac owners are not. For many years Apple products were considered as virus-safe ones.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos","og_locale":"en_US","og_type":"article","og_title":"MaMi Malware Struck MacOS | iGotOffer","og_description":"What is MaMi Malware? MaMi is a DNS hijacker. While Windows users are well acquainted with different kinds of malwares, Mac owners are not. For many years Apple products were considered as virus-safe ones.","og_url":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos","og_site_name":"iGotOffer Blog","article_publisher":"https:\/\/www.facebook.com\/iGotOffer","article_author":"https:\/\/www.facebook.com\/svetlana.ustinova2","article_published_time":"2018-01-24T16:24:17+00:00","article_modified_time":"2022-12-29T20:20:31+00:00","og_image":[{"width":600,"height":400,"url":"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/mami-malware-struck-macos.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_creator":"@iGotOffer","twitter_site":"@iGotOffer","twitter_misc":{"Written by":"Steve","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/igotoffer.com\/blog\/#website","url":"https:\/\/igotoffer.com\/blog\/","name":"iGotOffer Blog","description":"News and reviews about electronics &amp; apps","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/igotoffer.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#primaryimage","url":"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/mami-malware-struck-macos.jpg","contentUrl":"https:\/\/igotoffer.com\/blog\/wp-content\/uploads\/2018\/01\/mami-malware-struck-macos.jpg","width":600,"height":400,"caption":"MaMi Malware Struck MacOS"},{"@type":"WebPage","@id":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#webpage","url":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos","name":"MaMi Malware Struck MacOS | iGotOffer","isPartOf":{"@id":"https:\/\/igotoffer.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#primaryimage"},"datePublished":"2018-01-24T16:24:17+00:00","dateModified":"2022-12-29T20:20:31+00:00","author":{"@id":"https:\/\/igotoffer.com\/blog\/#\/schema\/person\/2e5559af8f4c85b3c121b665ccef1e16"},"description":"What is MaMi Malware? MaMi is a DNS hijacker. While Windows users are well acquainted with different kinds of malwares, Mac owners are not. For many years Apple products were considered as virus-safe ones.","breadcrumb":{"@id":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/igotoffer.com\/blog\/mami-malware-struck-macos#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/igotoffer.com\/blog\/"},{"@type":"ListItem","position":2,"name":"MaMi Malware Struck MacOS"}]},{"@type":"Person","@id":"https:\/\/igotoffer.com\/blog\/#\/schema\/person\/2e5559af8f4c85b3c121b665ccef1e16","name":"Steve","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/igotoffer.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ef902dfdf5f1c30f261fa557b8d6d80a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ef902dfdf5f1c30f261fa557b8d6d80a?s=96&d=mm&r=g","caption":"Steve"},"sameAs":["https:\/\/igotoffer.com\/","https:\/\/www.facebook.com\/svetlana.ustinova2"]}]}},"_links":{"self":[{"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/posts\/8529"}],"collection":[{"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/comments?post=8529"}],"version-history":[{"count":2,"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/posts\/8529\/revisions"}],"predecessor-version":[{"id":13711,"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/posts\/8529\/revisions\/13711"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/media\/8558"}],"wp:attachment":[{"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/media?parent=8529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/categories?post=8529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/igotoffer.com\/blog\/wp-json\/wp\/v2\/tags?post=8529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}