6 ms·
Any advice on what to do if you might be a victim to this?
by beginning_end 2y ago
Any advice on what to do if you might be a victim to this?
- deleted 2y ago[deleted]
- addandsubtract 2y agoApparently, it was collecting passwords from victim machines. So, step one would be to remove everything the script put onto your machine. Step two would be to change your passwords.
- watermelon0 2y agoStep 3 should probably be reinstalling the OS, and restoring data from backup (ideally from before the malicious version was installed).
- NotYourLawyer 2y agoAnd install ublock origin going forward.
- chatmasta 2y agoStep one is to unplug the machine from the internet. Step two is to use another machine to change all your passwords, starting with the “pivot” passwords - your password manager master password, your email accounts, your AppleID, your mobile provider - followed by financial accounts and then all others. While changing passwords, make sure to “invalidate all sessions” where possible. Only after you’ve done all this should you move onto Step 3: reformat your computer and install the OS from scratch.
- hollin 2y agoIs there any way to check if you're affected? I just happened to install Homebrew while the malicious site was up and now I'm not sure if I installed the legit version.
- Shank 2y agoCheck if /tmp/update exists. If it does, you’re infected.
- seenukarthi 2y agoI think the malware tries to delete this file. So, it won't be a reliable method to identify whether you were infected.
- npteljes 2y agoI'd isolate the machine from the internet, change my passwords from a trusted machine, save the media and documents from the isolated machine, and then reinstall the OS / factory reset the isolated machine. Still, I'm sure that there are technical possibilities that this doesn't account for, but I think I would be okay with the procedure nevertheless.