Mastodon
Go back

macOS Safety Tips In Light Of The ChromeLoader Campaign

Almost every outlet had some version of these four bullets (via Malwarebytes) when it comes to advice regarding how to prevent similar, future attacks:

From what I understand, the first bullet was the cause of much of the pain for folks (so def avoid risky behavior moving forward is 100% the first step to help prevent future attacks).

I have a hard time recommending non-enterprise-grade endpoint security solutions. Most clever attacks easily bypass non-enterprise solutions (and also bypass many enterprise solutions until rulesets get updated).

Having said that, LuLu, KnockKnock, BlockBlock, and RansomWhere? from ObjectiveSee (https://objective-see.org/tools.html) are default installs for me on any new Mac and can help notify you when things start to go awry on your system (early behavioral detection is one of the only methods to quickly stop attacks like this). They’re free, but def drop some coin if you can. They do good work. If running something besides Apple’s own (hidden) anti-malware agent will make you feel better, Malwarebytes is what I recommend.

Be very picky with browser extensions. I run with a very limited set of them, and most of the ones I use are safety-related:

– uBlock Origin (https://ublockorigin.com); I have nearly every rule enabled

Their URL/domain/IP lists are updated weirdly fast and they also block alot of malicious adverts on pages. It does mean having to spend some time each week tweaking settings for various new sites. Your world will be more painful after installing them, but it’s worth it (and you’ll be amazed how nice the web looks again).

I’d say “don’t use Chromium-based browsers” but WebKit-based browsers have their fair share of attacks & weaknesses. Having said that, running something besides Chrome from Google-proper can help. When forced to use a Chromium browser, I use Vivaldi (https://vivaldi.com/download/) and have all the safety features enabled by default, and only whitelist sites I absolutely need to access.

My main, daily brwoser of choice is Orion (https://browser.kagi.com). It’s WebKit-based (like Safari) but it’s wrapped in a different shell and has more Safety features than Safari. It also supports Chrome extensions, so I have uBlock, Disconnect, and Trace installed in it. I also default every site into “Reader” mode on Orion, and only enable sites I really trust to be in non-Reader mode. That’ll prevent a ton of popups on its own.

If, for some reason, you need to use Chrome-proper, run with the Chrome Beta channel version (https://www.google.com/chrome/beta/). It’s weeks ahead of the Stable releases, which can help protect from malware that relies on vulnerabilities in the Stable release.

Always let Chromium- and WebKit-based browsers update when you get the prompt or the toolbar icon tells you to. You have to be a bit careful if it’s a dialog prompt (like Orion) since some malicious sites pop up similar looking ones.

Use something else besides in-built browser password managers. I use Bitwarden (https://bitwarden.com) personally and my workplace uses 1Password (https://1password.com). Don’t set either to never lock.

Enable multi-factor authentication on EVERY site you can, and consider deleting accounts on ones that don’t. Try to use sites that work with apps like Duo (https://duo.com/product/multi-factor-authentication-mfa) or Microsoft Authenticator (https://www.microsoft.com/en-us/security/mobile-authenticator-app). For the latter, if a site works with their “tap the number” feature, use it.

I also always run macOS new betas. That causes alot of pain, sometimes, but it also catches many malware families off guard. This is not something everyone can easily do, but definitely consider it.

I wish the advice were easier and more bulletproof, but the modern threat landscape is pretty complex and dangerous.