

Image: Foundry
Do you need another reminder that you shouldn’t download software from pirating sites? Then, heed this warning: () – there’s a new trojan malware bundled with apps pretending to be popular premium macOS apps.
Kaspersky explains that the app downloaders are offered as package (PKG) files rather than the usual disk image (DMG) file that launches and mounts a volume on the desktop containing the application installer. The site’s researchers uncovered the malware hidden inside 35 image editing, video compression and editing, data recovery, and network scanning tools, including numerous popular Mac apps:
- 4K Video Donwloader Pro
- Aiseesoft Mac Video Converter Ultimate
- Aissessoft Mac Data Recovery
- AnyMP4 Android Data Recovery for Mac
- Artstudio Pro
- AweCleaner
- Downie 4
- FonePaw Data Recovery
- MacDroid
- MacX Video Converter Pro
- NetShred X
- Path Finder
- Project Office X
- Sketch
- SQLPro Studio
- Vellum
- Wondershare UniConverter 13
It’s a scary scenario as attackers can use this malware to create a proxy network on an infected Mac and commit various crimes on behalf of the victim, according to Kaspersky. The trojan can also mask itself as a WindowServer system file, which is a common GPU task responsible for drawing elements on the screen, once installed. This malevolent suction would go undetected by macOS security and the user.
How to protect yourself
If you’ve already downloaded one of these apps, there isn’t much you can do other than a complete wipe and reinstall of your system. Otherwise, stay away from warez sites and download software only from official sources. Catching these types of malware and viruses before they reach your machine is always the best method but we’ve also rounded up the best Mac antivirus software that will stop viruses from infecting your Mac.
Author: Michael Simon, Executive Editor


Michael Simon has been covering Apple since the iPod was the iWalk. His obsession with technology goes back to his first PC—the IBM Thinkpad with the lift-up keyboard for swapping out the drive. He’s still waiting for that to come back in style tbh.

