Automatically translated.View original post

macOS Beware of Fake Codex Apps

Alarm macOS residents beware of fake Codex apps. Inadvertently believed it could lead to installing AMOS malware onto the machine.

According to a report by the website SiliconAngle, a new campaign of malware thieves from the victim's machine, or Infostealer, specifically attacks users of the macOS operating system, AMOS, through impersonation of a Codex application, an AI assistant application, or AI Agent, from OpenAI, the developer of the same as ChatGPT, the number one popular AI tool, by the CTRL research team from Cato Networks, a network security management specialist.

The research team found that the hackers behind it used a strategy to trick the victim into following on-screen instructions to install malware or ClickFix through a fake website that claimed to be a website for downloading Codex applications, starting with the use of fake ads through Google Ads aimed at a group of people who searched for the word "codex macos download" or nearby, and this advertisement caused the fake website to appear above the real website, misleading the victim into a fake website instead of a genuine website. Once clicked, it took the victim to a website created on the Google Sites system that was decorated exactly like a genuine Codex download page.

After the victim has successfully entered the fake website, the victim will find a button that claims to be used for downloading macOS and Linux versions of the Codex app. But the research indicates that whichever button is pressed, it will download the macOS version of the fake app. When pressed successfully, it will lead to the ClickFix page being loaded from another server via iFrame. So that the malware installation code is not dangerous on the Google Sites website, which may be vulnerable to Google closing the website. Verifying that the ClickFix page will use the Path of the website. It is called / codexx /. The path / codex / is used when returning to the product page. In addition, the website is found to detect which operating system the visitor is using. If it is found to be using a non-macOS operating system, it will immediately lead to a harmless page.

On the ClickFix page, it instructs the victim to open the Terminal application and paste automatically copied code to run (Run) through Terminal. It claims to download the Codex application to the machine. It is actually a malware installation. The malware installation is divided into three steps, starting with the Shell script, which acts as a malware extension, or the Encoded Blob Loader, which is encapsulated by dead code, and many unused Variables. This Blob will also be decoded. Era

Step 2 will send an HTTP Request to the hacker's Endpoint tool with parameters such as event = pasted to confirm that the victim has successfully copied, pasted, and executed the command. To enter step 3, download the real malware (Payload) into the .clears file type / tmp / helper folder with Extended Attribute like xattr -c. Without Attribute, the malware will be detected and the victim will be notified of the malware entry.

# Trending # lemon 8 diary # macos # codex # freedomhack

4 days agoEdited to

... Read moreประสบการณ์ส่วนตัวกับการใช้งาน macOS ทำให้ผมตระหนักถึงความสำคัญของการดาวน์โหลดโปรแกรมจากแหล่งที่น่าเชื่อถือ เพราะเคยได้ยินข่าวเกี่ยวกับแอปปลอมที่แฝงมัลแวร์อย่างกรณีของแอป Codex ที่ตั้งใจโจมตีผู้ใช้ macOS ผ่านมัลแวร์ AMOS ซึ่งมัลแวร์ตัวนี้ทำหน้าที่ขโมยข้อมูลสำคัญจากเครื่อง สิ่งที่น่าสนใจและควรรู้คือ แฮกเกอร์ใช้กลยุทธ์โฆษณาปลอมบน Google Ads เพื่อดึงดูดผู้ใช้ที่ค้นหาคำว่า "codex macos download" ไปยังเว็บไซต์ปลอมที่เหมือนกับเวอร์ชันจริงมาก ทำให้ผู้ใช้ที่ไม่ทันระวังคลิกดาวน์โหลดแล้วติดมัลแวร์โดยไม่รู้ตัว ผมได้เรียนรู้ว่าตัวเว็บไซต์ปลอมจะใช้ระบบตรวจจับว่าผู้เยี่ยมชมใช้ระบบปฏิบัติการอะไร หากไม่ใช่ macOS จะถูกพาไปยังหน้าเว็บปลอดภัย ซึ่งเป็นหนึ่งในวิธีซ่อนความผิดปกติได้ดีและหลอกลวงผู้ใช้ได้ง่ายในวงกว้าง ขั้นตอนติดตั้งมัลแวร์ยังซับซ้อน โดยให้ผู้ใช้เปิด Terminal และรันคำสั่งที่ถูกคัดลอกอัตโนมัติ โดยอ้างว่าเป็นการติดตั้งแอป Codex จริง ๆ แต่แท้จริงคือการรันสคริปต์แบบเข้ารหัสทำหน้าที่เป็นตัวดาวน์โหลดมัลแวร์หลักลงในเครื่อง ซึ่งผู้ใช้ทั่วไปอาจไม่ทันสังเกตถึงความผิดปกติ คำแนะนำสำหรับผู้ใช้ macOS คือ - หลีกเลี่ยงการดาวน์โหลดแอปจากเว็บไซต์ที่ไม่รู้จักหรือไม่น่าเชื่อถือ - ไม่กดปุ่มลิงก์บนโฆษณาที่ไม่น่าเชื่อถือโดยเฉพาะจาก Google Ads - ระวังคำสั่งใด ๆ ที่ขอให้เปิด Terminal เพื่อวางและรันคำสั่งโดยตรง - ติดตั้งและใช้งานซอฟต์แวร์แอนตี้มัลแวร์ที่มีประสิทธิภาพเพื่อตรวจจับพฤติกรรมแปลก ๆ ทั้งนี้ การอัปเดตระบบปฏิบัติการ macOS อยู่เสมอก็ช่วยป้องกันช่องโหว่จากการโจมตีในรูปแบบต่าง ๆ ได้ด้วย การรู้เท่าทันและมีสติในการดาวน์โหลดและติดตั้งซอฟต์แวร์จะช่วยลดความเสี่ยงในการถูกโจมตีด้วยมัลแวร์อย่างมาก