{"id":2139,"date":"2020-10-19T09:23:57","date_gmt":"2020-10-19T09:23:57","guid":{"rendered":"https:\/\/partnernews.sophos.com\/en-us\/?p=2139"},"modified":"2020-10-19T09:26:27","modified_gmt":"2020-10-19T09:26:27","slug":"no-protection-for-me-thanks-ive-got-a-mac-oh-wait","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/en-us\/2020\/10\/products\/no-protection-for-me-thanks-ive-got-a-mac-oh-wait\/","title":{"rendered":"No protection for me thanks I\u2019ve got a Mac&#8230;.. oh wait."},"content":{"rendered":"<p>It\u2019s increasingly rare these days to speak to a customer who is not aware of the need Mac OS protection however I\u2019m sure those of you reading this will have come across at least a few in your time.\u00a0Although like all great myths there is often a small element of truth and one thing Apple is great at is marketing.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-2148 alignleft\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-1.png?w=300\" alt=\"\" width=\"428\" height=\"409\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-1.png 1126w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-1.png?resize=300,287 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-1.png?resize=768,734 768w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-1.png?resize=1024,979 1024w\" sizes=\"auto, (max-width: 428px) 100vw, 428px\" \/><\/p>\n<p>Ah the good old days! If Only the number of \u201cViruses\u201d was still this low!<\/p>\n<p>This Ad from 2006 can still be seen <a href=\"https:\/\/www.apple.com\/chatterbox\/us\/2006\/07\/3059\/3059.html\">here\u00a0<\/a>and so perhaps it\u2019s unsurprising that there is still some misconception around Apple Mac devices and security in the workplace as ads such as these can linger in the mind. So, let&#8217;s take an up to date look at Mac threats and what Sophos can now do in terms of providing visibility and protection against these threats.<\/p>\n<p>The truth is proportionally, there isn\u2019t as much Mac Malware out in the wild as we see on Windows.\u00a0\u00a0However, there\u2019s certainly is enough to be getting on with! A list of current OSX specific detections from Sophos Labs can be seen <a href=\"https:\/\/search.sophos.com\/#q=osx&amp;t=All&amp;sort=date%20descending&amp;f:@sophossourcetype=[Detections]\">here.<\/a><\/p>\n<p>Apple is also aware of\u00a0OSX threats\u00a0and has been for some time,\u00a0which\u00a0is why\u00a0current\u00a0versions of OSX comes\u00a0with a client firewall and a security feature called Gatekeeper. Gatekeeper\u00a0is\u00a0designed to help prevent users downloading malware from compromised web sites.\u00a0Unfortunately, Mac users are also very good at installing all sorts of \u201cinteresting\u201d applications and tend to disable or ignore Gatekeeper \u2013 so making it useless.\u00a0Back in 2016 we saw OSX\/Keydnap\u00a0allow cyber criminals to remotely access your Mac and use it as a beach head as for a more widespread attack into your organisation. It was also able to bypass Gatekeeper by packing\u00a0OSX.Keydnap\u00a0within a legitimate signing key. As was the case when the \u201cTransmission\u201d app was compromised.<\/p>\n<p>For close to two years now, the\u00a0Shlayer\u00a0Trojan has been the most common threat on the macOS platform: in 2019, one in ten of our Mac security solutions encountered this malware at least once, and it accounts for almost 30% of all detections for this OS. The first specimens of this family fell into our\u00a0hands back in February 2018, and we have since collected almost 32,000 different malicious samples of the Trojan and identified 143 C&amp;C server domains<\/p>\n<p>A\u00a0more current\u00a0example of this is\u00a0a new\u00a0variant of this\u00a0Trojan that is specifically designed to circumvent macOS Catalina&#8217;s\u00a0security\u00a0measures\u00a0&#8211;\u00a0Intego\u00a0who discovered the malware, describe it in their security blog,\u00a0<a href=\"https:\/\/go.redirectingat.com\/?id=803X112722&amp;xcust=41-3790719-11-0000000&amp;sref=https%3A%2F%2Fwww.macworld.co.uk%2Fnews%2Fmac-software%2Fnew-malware-google-results-3790719%2F&amp;xs=1&amp;url=https%3A%2F%2Fwww.intego.com%2Fmac-security-blog%2Fnew-mac-malware-reveals-google-searches-can-be-unsafe%2F\">here<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-2149 alignright\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-2.png?w=300\" alt=\"\" width=\"351\" height=\"273\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-2.png 640w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-2.png?resize=300,233 300w\" sizes=\"auto, (max-width: 351px) 100vw, 351px\" \/><\/p>\n<p style=\"text-align: left;\">It\u2019s\u00a0hard to talk about endpoint security without mentioning ransomware these days and as you might have guessed Macs are no exception. Indeed, this summer, Security researchers have discovered a new ransomware strain targeting macOS users named OSX.ThiefQuest (or EvilQuest). Security researcher Patrick Wardle publised an in-depth analysis of the malware\u00a0<a href=\"https:\/\/objective-see.com\/blog\/blog_0x59.html\">in his security blog<\/a>, observing that\u00a0encrypting the victim&#8217;s files,\u00a0Thief Quest\u00a0also installs a keylogger, a reverse shell, and steals cryptocurrency wallet-related files from infected hosts.<\/p>\n<p><strong>The Bigger Picture<\/strong><\/p>\n<p>At an organisational level a Mac should be seen for what it is, just one more endpoint that an attacker could compromise. Increasingly we are seeing more targeted attacks and adversaries \u201cliving of the land\u201d. If a criminal can steal credentials via phishing or brute force it doesn\u2019t matter all that much what OS you are running. They can potentially use your own internal tools, file shares and protocols against you. What does matter is being able to detect a breach and have tools to see what a cybercriminal or insider threat may be doing and how they&#8217;re doing it so you can mitigate and protect against that threat.<\/p>\n<p>This is where the need for\u00a0Endpoint Detection and Response\u00a0tools come into play.<\/p>\n<p>As of September 15th,\u00a0we have made Intercept X Advanced with EDR\u00a0available for Macs this allows your customers to not only have Intercept X protecting them against the latest threats and Mac Ransomware but\u00a0with EDR\u00a0also gives them the\u00a0visibility\u00a0they need across their entire estate\u00a0which as of now includes Windows Mac and\u00a0Linux!<\/p>\n<p>EDR\u00a0for\u00a0Mac includes both live query and liver response which\u00a0leverages\u00a0Osquery\u00a0technology to query all your\u00a0assets in your estate in\u00a0real-time. These tools can be used\u00a0to investigate\u00a0a\u00a0threat or\u00a0just to get better visibility or your\u00a0estate.\u00a0To learn more about how the EDR product works\u00a0look\u00a0at the following <a href=\"https:\/\/news.sophos.com\/en-us\/2020\/09\/15\/sophos-endpoint-detection-and-response-now-available-for-macs\/\">release article<\/a>.<\/p>\n<p>The EDR release on Mac gives you that full across state visibility and is something that\u00a0as well as providing you with the tools to do threat hunting can be used for day to day admin tasks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2150\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-3.png?w=300\" alt=\"\" width=\"1328\" height=\"611\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-3.png?resize=300,138 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-3.png?resize=768,354 768w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-3.png?resize=1024,472 1024w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-3.png?resize=1536,708 1536w\" sizes=\"auto, (max-width: 1328px) 100vw, 1328px\" \/><\/p>\n<p>As great as EDR tools are we realise not all customers and partners have the time or expertise to use these tools to do active threat hunting. That\u2019s&#8217; why we a few months back now,\u00a0released our <a href=\"https:\/\/www.sophos.com\/en-us\/products\/managed-threat-response.aspx\">Managed Threat Response service<\/a>. Which allows you and the customer to take advantage of all the great EDR tools but leave the threat hunting up to\u00a0Sophos\u2019s\u00a0team of threat hunters providing 24\/7\u00a0cover of your customer\u2019s\u00a0estate.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2151\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-4.png?w=300\" alt=\"\" width=\"474\" height=\"267\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-4.png 960w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-4.png?resize=300,169 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/10\/Image-4.png?resize=768,432 768w\" sizes=\"auto, (max-width: 474px) 100vw, 474px\" \/><\/p>\n<p>For an overview of protections, you can offer you customers with a Mac estate please refer to the following <a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/factsheets\/sophos-intercept-x-mac-ds.pdf\">datasheet<\/a> or reach out to your account manager.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s increasingly rare these days to speak to a customer who is not aware of the need Mac OS protection however I\u2019m sure those of you reading this will have come across at least a few in your time.\u00a0Although like [&hellip;]<\/p>\n","protected":false},"author":57,"featured_media":1190,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[2],"tags":[30,41,105],"coauthors":[65],"class_list":["post-2139","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-products","tag-intercept-x","tag-managed-threat-response","tag-sophos-edr"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/featured-image-UKI-tech-update-Partner-app-icon-1600x960-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/2139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/comments?post=2139"}],"version-history":[{"count":12,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/2139\/revisions"}],"predecessor-version":[{"id":2166,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/2139\/revisions\/2166"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media\/1190"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media?parent=2139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/categories?post=2139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/tags?post=2139"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/coauthors?post=2139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}