MacDefender traced to ChronoPay

MacDefender traced to ChronoPayThe MacDefender malware, which has been troubling Mac users since earlier this month, is linked to an online payment processor called ChronoPay based in Russia.

The MacDefender phishing attack and MacProtector and MacSecurity mainly attacks Mac users through Google Image search results and is difficult to detect and remove as it simply attacked itself to computer's launch menu and does not have no icon on the dock.

Security researcher Brian Krebs wrote in his KrebsonSecurity blog that "Some of the recent scams that used bogus security alerts in a bid to frighten Mac users into purchasing worthless security software appear to have been the brainchild of ChronoPay, Russia's largest online payment processor and something of a pioneer in the rogue anti-virus business."

The hackers tricked Mac users by displaying pictures showing an antivirus scan taking place on their machines. The images then tell users that their system is infected by a serious malware and urges them to download and install the antivirus package. Users who download the ‘anti-virus program’ are then infected by the malware. MacDefender and its malicious software variants have been infecting Macs since at least May 2.

Krebs said that he traced the notorious programme to ChronoPay by investigating two domains used by the attackers where the Mac users are directed. The researcher found that both mac-defence. com and macbookprotection.com are associated with the email address fc@mail-eye.com, which is believed to be owned by a company official as it was used to leak ChronoPay documents.

Meanwhile, Apple has released new entry in a support forum advising users on how to avoid or remove the MacDefender malware. Apple may be coming to a realization that Mac systems, so far believed to be free from any malware, now appear to be untargeted and unprotected target for hackers, phishers, and scammers.