Mac

More Maliciousness: Don’t Follow Instructions to Drop a File into Terminal

Thing #17 to never do: Follow instructions to drop a text file into Terminal. It’s a great way to install malware and let cybercriminals steal your passwords, financial information, and more.

Thing #17 to never do: Follow instructions to drop a text file into Terminal. It’s a great way to install malware and let cybercriminals steal your passwords, financial information, and more. | CreativeTechs.com

More Maliciousness: Don’t Follow Instructions to Drop a File into Terminal

In macOS 15 Sequoia, Apple made it more difficult to bypass Gatekeeper to run apps that aren’t notarized. (Notarization is one of the ways Apple ensures that apps distributed outside the Mac App Store are unmodified and free from malware.) Cybercriminals have responded to this increase in security with a new social engineering attack. They provide the victim with a disk image, ostensibly to install some desired piece of software, instructing the user to drag a text file into Terminal. Doing so executes a malicious script that installs an “infostealer” designed to exfiltrate a wide variety of data from your Mac. The simple advice here is to treat any guidance to drop a file into Terminal with extreme suspicion—no legitimate software or developer will ever ask you to do that.

Read more:

More great tips from the archives…

Apple Premium Technical Partner
Deep Apple expertise, wherever your team works.

Not sure your Macs are ready for what’s next?

Book a free, no-pressure call. We’ll review your fleet, flag what needs attention, and you’ll leave with a plan either way.

Let’s Talk →
The CreativeTechs Way

Apple news worth your inbox.

One monthly note on the updates that actually affect your workplace. No noise.

Keep reading