Fake macOS installers spread OtterCookie spyware
Fake macOS installers are spreading OtterCookie, a backdoor that lets attackers spy on your Mac. These fake installers look like real Apple software but secretly install spyware instead.
- Report priority
- Medium
- Targets
- macOS
How it works
- Attackers create fake macOS installers that look like real Apple software.
- When you download and run them, they secretly install OtterCookie spyware on your Mac.
- This spyware lets attackers monitor your activity, steal data, and run malicious code.
What to do
Check if you downloaded any macOS installers from untrusted websites or sources outside Apple's normal update channel. If you ran any fake installers, your Mac may have OtterCookie spyware installed. Visit Apple's official support site to verify your installed software and remove any unauthorized apps.
Immediately uninstall any suspicious or unknown installers from your Mac. Use Apple's built-in tools to scan for and remove malware. If you suspect your Mac is infected, contact Apple Support or a trusted tech professional for further assistance.
Technical details
A user downloads what they think is a legitimate macOS update from a third-party website. After running the installer, OtterCookie spyware is installed on their Mac, allowing attackers to spy on their activity.
Security teams uncovered trojanized fake macOS installers tied to North Korean campaigns that deploy OtterCookie malware on Apple devices.