A malware research team has discovered a new piece of Mac malware that reportedly affects all versions of MacOS and is signed with a valid developer certificate authenticated by Apple (via The Hacker News).

The malware has been dubbed "DOK" and is being disseminated through an email phishing campaign which researchers at CheckPoint say is specifically targeting macOS users, making it the first of its kind.

Screen Shot 3 3
The malware works by gaining administration privileges in order to install a new root certificate on the user's system. This enables it to gain access to all communications between the host Mac and the internet, including traffic flowing through connections encrypted with SSL.

The initial email pretends to be informing the recipient of inconsistencies in their tax return and asks them to download a zip file attachment to their Mac that harbors the malware. Apple's built-in Gatekeeper security feature reportedly fails to recognize it as a threat because of its valid developer certificate, and the malware copies itself to the /Users/Shared/ folder and creates a login item to make itself persistent, even in a rebooted system.

The malware later presents the user with a security message claiming an update is available for the system, for which a password input is required. Following the "update", the malware gains complete control of admin privileges, adjusts the network settings to divert all outgoing connections through a proxy, and installs additional tools that enable it to perform a man-in-the-middle attack on all traffic.

Screen Shot 2 3
According to the researchers, Mac antivirus programs have yet to update their databases to detect the DOK malware, and advises that Apple revoke the developer certificate associated with the author immediately.

Back in January, researchers discovered a piece of Mac malware called Fruitfly that successfully spied on computers in medical research centers for years before being detected.

The latest discovery of malware, which appears to target predominantly European users, underlines the fact that Macs are not immune to the threat as is sometimes supposed. As always, users should avoid clicking links or downloading attachments in emails from unknown and untrusted sources.

Top Rated Comments

netwalker Avatar
104 months ago
The initial email pretends to be informing the recipient of inconsistencies in their tax return and asks them to download a zip file attachment to their Mac that harbors the malware.
People that actually do this should not have admin rights on their machines.
Score: 25 Votes (Like | Disagree)
darkpaw Avatar
104 months ago
Looking at the screenshot in this story, the spelling mistakes are enough for me to not want to click any further.

I received that email earlier today, but it's to an email address that's not associated with the tax people, so I immediately deleted it.

To avoid all this, I have my own domain and use a separate email for each company/service I interact with, i.e. tesco@mydomain.com, amazon@mydomain.com etc. When I receive spam to a given address, say, tesco@... I change the email for that service to tesco2@... and bin all emails that go to the original. It's a little bit of admin, but it cuts spam down a lot.
Score: 11 Votes (Like | Disagree)
spazzcat Avatar
104 months ago
Wow, more and more reports of malware occurring - need to be even more vigilant


The money quote right here, we as Mac users cannot blindly ignore the threat.
The IRS isn't going to email you zip file about your taxes. If fact no one you don't know is going to email you a zip file that is real.
Score: 7 Votes (Like | Disagree)
justperry Avatar
104 months ago
If People see "OS X Updates available" while on MacOs and still clicking Update All they should think first.

Not only that, always update through the AppStore and you won't get this.
.
.
.
.
.
.
.

Edited: Appsore=Appstore.
Score: 4 Votes (Like | Disagree)
shareef777 Avatar
104 months ago
People that actually do this should not have admin rights on their machines.
Downloading ANY file in an email from someone you don't know is bad. If everyone knew that, then the internet would be a (slightly) safer place.
Score: 4 Votes (Like | Disagree)
newyorksole Avatar
104 months ago
Sooo you're only affected if you click/open suspicious links? Ok I'm safe.

Can't believe people believe these IRS emails/scams...
Score: 3 Votes (Like | Disagree)

Popular Stories

CarPlay Hero

Apple Releases Wireless CarPlay Fix

Wednesday April 16, 2025 11:28 am PDT by
If you have been experiencing issues with wireless CarPlay in your vehicle lately, it was likely due to a software bug that has now been fixed. Apple released iOS 18.4.1 today, and the update's release notes say it "addresses a rare issue that prevents wireless CarPlay connection in certain vehicles." If wireless CarPlay was acting up for you, updating your iPhone to iOS 18.4.1 should...
AirPods Pro 3 Mock Feature

AirPods Pro 3 Just Months Away – Here's What We Know

Friday April 18, 2025 5:16 am PDT by
Despite being more than two years old, Apple's AirPods Pro 2 still dominate the premium wireless‑earbud space, thanks to a potent mix of top‑tier audio, class‑leading noise cancellation, and Apple's habit of delivering major new features through software updates. With AirPods Pro 3 widely expected to arrive in 2025, prospective buyers now face a familiar dilemma: snap up the proven...
iphone 16 pro models 1

17 Reasons to Wait for the iPhone 17

Thursday April 17, 2025 4:12 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models simultaneously, which is why we often get rumored features months ahead of launch. The iPhone 17 series is no different, and we already have a good idea of what to expect from Apple's 2025 smartphone lineup. If you skipped the iPhone...
Beyond iPhone 13 Better Triad

Apple's 20th Anniversary iPhone May Finally Go All Screen

Tuesday April 15, 2025 6:31 am PDT by
Apple is preparing a "bold" new iPhone Pro model for the iPhone's 20th anniversary in 2027, according to Bloomberg's Mark Gurman. As part of what's being described as a "major shake-up," Apple is said to be developing a design that makes more extensive use of glass – and this could point directly to the display itself. Here's the case for Apple releasing a truly all-screen iPhone with no...
maxresdefault

iPhone 17 Pro Launching Later This Year With These 12 New Features

Sunday April 13, 2025 7:52 am PDT by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch until September, there are already plenty of rumors about the devices. Subscribe to the MacRumors YouTube channel for more videos. Below, we recap key changes rumored for the iPhone 17 Pro models as of April 2025: Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and ...
iOS 19 Roundup Feature

iOS 19 Will Add These New Features to Your iPhone

Tuesday April 15, 2025 7:37 am PDT by
The first iOS 19 beta is less than two months away, and there are already a handful of new features that are expected with the update. Apple should release the first iOS 19 beta to developers immediately following the WWDC 2025 keynote, which is scheduled for Monday, June 9. Following beta testing, the update should be released to the general public in September. Below, we recap the key...
tvOS 18 Thumb 1

Apple Releases tvOS 18.4.1

Wednesday April 16, 2025 10:04 am PDT by
Apple today released tvOS 18.4.1, a minor update to the tvOS 18 operating system that came out last September. tvOS 18.4.1 comes two weeks after Apple released tvOS 18.4, and it is available for the Apple TV 4K and Apple TV HD models. tvOS 18.4.1 can be downloaded using the Settings app on the ‌Apple TV‌. Open up Settings and go to System > Software Update to get the new software....
iPhone Security Feature 25

Five iPhone Security Features You Should Be Using

Wednesday April 16, 2025 4:15 pm PDT by
Apple has quite a few security features that it's added to iPhones, iPads, and Macs over the years. Now more than ever, it's important to make sure you're taking advantage of the built-in security tools that are available to keep yourself and your data safe, so we've rounded up a list of the most important options. If you don't already have these enabled, you might want to consider turning...
vision air cable

Images of Apple 'Vision Air' Power Cable Emerge Online

Thursday April 17, 2025 5:55 am PDT by
More images of a redesigned power cable allegedly for a future Apple "Vision Air" headset were today shared online by the prototype collector and leaker known as "Kosutami." Yesterday, the leaker explained that the Apple "Vision Air" will feature a thinner design and switch the battery enclosure and several of its internal structures to titanium to reduce the device's overall weight. Most of ...