{"id":98617,"date":"2023-08-14T20:28:05","date_gmt":"2023-08-15T03:28:05","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=98617"},"modified":"2024-05-21T01:49:48","modified_gmt":"2024-05-21T08:49:48","slug":"did-the-nightowl-app-really-join-macs-to-a-botnet-army","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/","title":{"rendered":"Did the NightOwl app really join Macs to a botnet army?"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-98630\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-600x300-1.jpg\" alt=\"\" width=\"600\" height=\"300\" \/><\/p>\n<p>In late June, a web developer named Taylor Robinson wrote a blog post titled, &#8220;<a href=\"https:\/\/robins.one\/notes\/uninstall-the-nightowl-app-now.html\" target=\"_blank\" rel=\"noopener\">Uninstall the Nightowl App, now.<\/a>&#8221;<\/p>\n<p>NightOwl is a third-party app that has been around since 2018. It&#8217;s supposed to offer more customizability than Apple&#8217;s built-in <a href=\"https:\/\/support.apple.com\/en-us\/HT207513\" target=\"_blank\" rel=\"noopener\">Night Shift<\/a> feature in macOS; both can automatically toggle your display to warmer colors after dark.<\/p>\n<p>But Robinson claims that NightOwl has taken a turn toward the dark side. Supposedly, it silently enlists Macs in a botnet army.<\/p>\n<p>Apple seems to agree that something shady is afoot; the company revoked the NightOwl developer&#8217;s code-signing certificate, forcing the developer to remove NightOwl&#8217;s download link from its site.<\/p>\n<p>So what&#8217;s really going on? Let&#8217;s break down what we know about NightOwl.<\/p>\n<p><em>In this article:<\/em><\/p>\n<ul>\n<li><a href=\"#whatisnightowl\">What is NightOwl?<\/a><\/li>\n<li><a href=\"#events\">What events led up to Robinson&#8217;s blog post in June?<\/a><\/li>\n<li><a href=\"#reallyjoin\">Does NightOwl really join Macs to a botnet?<\/a>\n<ul>\n<li><a href=\"#whatisabotnet\">What is a botnet?<\/a><\/li>\n<li><a href=\"#doesnightowlinclude\">Does NightOwl include bot-like functionality?<\/a><\/li>\n<li><a href=\"#otherbehavior\">What other behavior does NightOwl engage in?<\/a><\/li>\n<li><a href=\"#proxy\">Residential proxy services could get you into trouble with the law<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#whyaugust\">Why is this suddenly a hot topic in August?<\/a><\/li>\n<li><a href=\"#origdev\">What does NightOwl&#8217;s original developer think about the situation?<\/a><\/li>\n<li><a href=\"#currentdev\">What does NightOwl&#8217;s current developer have to say?<\/a>\n<ul>\n<li><a href=\"#dispute\">The developer disputes some of Robinson&#8217;s claims<\/a><\/li>\n<li><a href=\"#plans\">The developer&#8217;s plans moving forward<\/a><\/li>\n<li><a href=\"#monetization\">Will monetization functionality be opt-in, or opt-out?<\/a><\/li>\n<li><a href=\"#qanda\">Additional Q&amp;A with the current NightOwl developer<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#malwarepua\">Is NightOwl malware, a PUA, or something else?<\/a><\/li>\n<li><a href=\"#cautionary\">A cautionary tale: good apps can take a turn for the worse<\/a>\n<ul>\n<li><a href=\"#vigilant\">Stay vigilant; read EULAs, and use protection software<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#uninstall\">Should I uninstall NightOwl? How can I do so?<\/a><\/li>\n<li><a href=\"#removeprevent\">How can one remove or prevent Mac malware and PUAs?<\/a><\/li>\n<li><a href=\"#iocs\">Indicators of compromise (IoCs) for affected NightOwl versions<\/a><\/li>\n<li><a href=\"#other-names\">Do security vendors detect this by any other names?<\/a><\/li>\n<li><a href=\"#learnmore\">How can I learn more?<\/a><a name=\"whatisnightowl\"><\/a><\/li>\n<\/ul>\n<h3>What is NightOwl?<\/h3>\n<p>NightOwl is an app that lets you control the macOS Dark Mode and Light Mode on a much more granular level. You can pick which apps remain Light when the rest of the system goes Dark, and vice versa. You can set it to toggle modes at a certain schedule, or as the sun rises and sets. Moreover, you can toggle between modes with a hotkey. And the cute owl sounds when switching between modes are just icing on the cake.<\/p>\n<p>The utility offered Mac users an extra level of control beyond what&#8217;s built into macOS. It has remained popular ever since.<a name=\"events\"><\/a><\/p>\n<h3>What events led to Robinson&#8217;s blog post in June?<\/h3>\n<p>NightOwl&#8217;s original developer, <a href=\"https:\/\/www.kramser.xyz\/\" target=\"_blank\" rel=\"noopener nofollow\">Benjamin Kramser<\/a>, says that he was no longer able to personally continue to develop the app due to time constraints. This led him to sell the project to a company called TPE.FYI LLC in November 2022.<\/p>\n<p>It isn&#8217;t uncommon for apps to get acquired by a bigger company. Even companies as big as Apple have been known to acquire smaller companies to obtain all the rights to their software.<\/p>\n<p>According to <a href=\"https:\/\/opencorporates.com\/companies\/us_tx\/0803112154\" target=\"_blank\" rel=\"noopener\">public records<\/a>, TPE.FYI LLC was formally established as a business entity in September 2018, but was dissolved in March 2023.<\/p>\n<p>The same month that TPE.FYI was supposedly dissolved, the NightOwl website apparently introduced a new Terms and Conditions page. For anyone who may have happened to read it, this page contains some potentially concerning statements, such as:<\/p>\n<blockquote><p>&#8220;WHEREAS, NightOwl app enables Users to share internet traffic by modifying their device\u2019s network settings to be used as a gateway for internet traffic. Additionally, the User\u2019s device acts as a gateway for NightOwl app\u2019s Clients, including companies that specialize in web and market research, SEO, brand protection, content delivery, cybersecurity, etc.&#8221;<\/p><\/blockquote>\n<p>While such language might stop you from installing an app, this change apparently wasn&#8217;t called out very clearly to users. What&#8217;s worse, this functionality could neither be opted into nor opted out of; it was simply baked into the product.<a name=\"reallyjoin\"><\/a><\/p>\n<h3>Does NightOwl really join Macs to a botnet?<\/h3>\n<p>The claim in Taylor Robinson&#8217;s blog post that NightOwl &#8220;forcibly joins your devices into a botnet&#8221; is quite a strong accusation. <a name=\"whatisabotnet\"><\/a>Let&#8217;s examine what that implies, and whether the current version of NightOwl has such capabilities.<\/p>\n<h4><strong>What is a botnet?<\/strong><\/h4>\n<p>When a computer or device is part of a botnet, that means software is installed that uses computing resources and Internet bandwidth to carry out tasks on behalf of a botmaster (bot operator). Such tasks may including participating in distributed denial of service (DDoS) attacks, sending spam, generating fake views or clicks, or other unethical behavior.<\/p>\n<p>Generally, all of this is done without the knowledge or explicit consent of the owner of that device or computer.<a name=\"doesnightowlinclude\"><\/a><\/p>\n<p>A bot (or zombie) is an infected computer or device that is part of a botnet army.<\/p>\n<h4><strong>Does NightOwl include bot-like functionality?<\/strong><\/h4>\n<p>According to Robinson, NightOwl was connecting to a remote SSH server, and acted as an HTTP(S) proxy server for the developer. Theoretically, this could mean that the current NightOwl developer could try to leverage users&#8217; devices as part of a botnet to conduct DDoS attacks against Web servers, or generate fake clicks or views.<\/p>\n<p>Robinson also notes that NightOwl contains code related to a service called Pawns (or Pawns.app), which supposedly pays users up to 20 cents per gigabyte for sharing their network bandwidth. Again, this seems to imply that some third party could theoretically leverage NightOwl users&#8217; Internet connections as proxies to send DoS or click fraud traffic.<\/p>\n<p>Notably, <strong>Robinson did not claim to have observed NightOwl actually engaging in these types of activities<\/strong> commonly associated with botnets.<\/p>\n<p>Of course, this behavior happens behind the scenes; users of NightOwl will generally have no idea that any of this is happening. <a name=\"otherbehavior\"><\/a>Users also wouldn&#8217;t get a share of any revenue generated by Pawns traffic; all of the potential profits would go to the current NightOwl developer.<\/p>\n<h4><strong>What other behavior does NightOwl engage in?<\/strong><\/h4>\n<p><img loading=\"lazy\" class=\"aligncenter wp-image-98632 size-full\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-download-pop-up-original.png\" alt=\"\" width=\"600\" height=\"454\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-download-pop-up-original.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-download-pop-up-original-300x227.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-download-pop-up-original-150x114.png 150w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>Robinson goes into further technical detail about how NightOwl uses a LaunchAgent to kick off an AutoUpdate daemon. The daemon runs as root, and it cannot be disabled through the app. Turning off the &#8220;Send Statistics&#8221; option in the app does not disable the LaunchAgent, either.<\/p>\n<p>Further details include how NightOwl may be making use of several open-source software packages without including the appropriate licenses.<\/p>\n<p>Finally, Robinson explains the Pawns component:<\/p>\n<blockquote><p>The application also seems to use the Pawns SDK, which is an app offers to pay users $0.20 per GB of their internet shared. This service is operated by IPRoyal, a proxy company that will sell you residential proxy connections for $1.75\/GB, and advertises \u201c100% ethically sourced IPs\u201d.<\/p><\/blockquote>\n<p>IPRoyal is apparently overconfident, at best, about its &#8220;100% ethically sourced IPs&#8221; claim. The company boasts of more than 8 million IP addresses. <a name=\"proxy\"><\/a>Pawns, for its part, advertises that its clients (evidently including the current NightOwl developer) can get paid up to $2 per month, per unique IP address.<\/p>\n<h4><strong>Residential proxy services could get you into trouble with the law<\/strong><\/h4>\n<p>And what precisely could such a &#8220;residential proxy&#8221; service do? It could route its clients&#8217; Internet traffic through any computer with the software installed.<\/p>\n<p>And why might a client want to pay for such a proxy service? Perhaps to do sketchy things\u2014such as making malicious edits to Wikipedia to spread disinformation, creating social media accounts en masse for fake engagement, or even accessing illegal pornography\u2014<strong>all of which appear to originate from your home or workplace<\/strong>.<\/p>\n<p>So, in a worst-case scenario, you could potentially be investigated and arrested for crimes you did not commit, all because of software on your computer that you didn&#8217;t even know existed.<a name=\"whyaugust\"><\/a><\/p>\n<h3>Why is this suddenly a hot topic in August?<\/h3>\n<p>The recent press coverage about NightOwl typically just links back to Robinson&#8217;s blog post from June, offering little additional information. The likely source of the sudden interest is an <a href=\"https:\/\/news.ycombinator.com\/item?id=37052508\" target=\"_blank\" rel=\"noopener\">August 8 post<\/a> on Y Combinator&#8217;s Hacker News. From there, the story seems to have been picked up by several online tech publications.<\/p>\n<p>Due to this new attention, the current NightOwl developer gave a statement to <a href=\"https:\/\/www.howtogeek.com\/this-mac-utility-is-now-malware\/\" target=\"_blank\" rel=\"noopener\">HowToGeek<\/a> that reads, in part:<\/p>\n<blockquote><p>&#8220;Given some users high level of concern we are working to give users an option to opt out of this. If we are able to re-release the app we will either completely remove this SDK or give an easy option for disabling. We apologize for the inconvenience and concern created.&#8221;<\/p><\/blockquote>\n<p>Around this time the download was made unavailable on the NightOwl website.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter wp-image-98631 size-full\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-download-pop-up-not-available.png\" alt=\"\" width=\"600\" height=\"535\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-download-pop-up-not-available.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-download-pop-up-not-available-300x268.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-download-pop-up-not-available-150x134.png 150w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>While an opt-out is a start, this is not the best approach. &#8220;Opt in&#8221; would be preferable, as the user must manually check a box to enable the functionality. It also isn&#8217;t clear from that statement whether the company plans to make the potentially undesirable behavior much more apparent to end users, with notifications upon installation or upgrade.<\/p>\n<p>The desire to somehow make money from NightOwl or any app makes sense, but it&#8217;s important to do so in a fully transparent and ethical way. At the time the company acquired NightOwl, TPE.FYI LLC communicated to the original developer that it would use normal, ethical methods of monetizing the app, namely a subscription model with more advanced features.<a name=\"origdev\"><\/a><\/p>\n<h3>What does NightOwl&#8217;s original developer think about the situation?<\/h3>\n<p>NightOwl&#8217;s original developer, Benjamin Kramser, makes the following statement on <a href=\"https:\/\/www.kramser.xyz\/\" target=\"_blank\" rel=\"noopener\">his site<\/a>:<\/p>\n<blockquote><p>&#8220;<strong>Nightowl got acquired by TPE.FYI LLC in November 2022<\/strong><\/p>\n<p>&#8220;Due to time constraints, I could no longer personally continue the development of NightOwl. Therefore, in November 2022, I made the decision to sell my beloved tool to &#8216;TPE.FYI LLC&#8217;. This decision was made with the understanding that new (Pro) features and a subscription model would be introduced. Unfortunately, &#8216;TPE.FYI LLC&#8217; has opted to monetize the app by integrating a third-party SDK. This decision is not affiliated with me in any way, and I do not endorse it in any form.&#8221;<\/p><\/blockquote>\n<p>We reached out to Kramser with follow-up questions, and he responded:<\/p>\n<blockquote><p>&#8220;I regret the current situation surrounding NightOwl.<\/p>\n<p>&#8220;There&#8217;s not much I can add to what has already been communicated on my website. I can only supplement that TPE.FYI didn&#8217;t approach me [to buy NightOwl] actively on their own initiative. As described on the website, due to time constraints, I was actively searching for a developer\/company to continue the project and provide users with new features.&#8221;<\/p><\/blockquote>\n<p>Unfortunately, the company that acquired NightOwl appears to have not stayed true to its word about how it would monetize the app; either that, or perhaps another developer took over the project after TPE.FYI was reportedly dissolved.<a name=\"currentdev\"><\/a><\/p>\n<h3>What does NightOwl&#8217;s current developer have to say?<\/h3>\n<p>The current NightOwl developer has updated the nightowlapp.co site with a pop-up message stating the following:<\/p>\n<blockquote><p>&#8220;We want to address recent claims that NightOwl contains malware. We want to assure you that these claims are inaccurate and false. Our app does not contain any form of malware. The concerns raised are based on a mistaken identification, and we are actively working with all major antivirus companies to rectify this situation promptly.<\/p>\n<p>&#8220;Your security and trust are of utmost importance to us. We kindly ask for your patience as we address this matter with the necessary parties. Thank you for your understanding.&#8221;<\/p><\/blockquote>\n<p>We reached out via e-mail with follow-up questions. In a reply to Intego, NightOwl&#8217;s current developer added:<\/p>\n<blockquote><p>&#8220;It is of crucial importance to us that our users feel comfortable and informed about the usage of NightOwl.<\/p>\n<p>&#8220;We have partnered with a highly reputable residential proxy service to monetize NightOwl. We added their SDK to the backend of the app that allows our partner&#8217;s users to send some requests through the NightOwl user\u2019s IP address. It&#8217;s important to note that we solely collect users&#8217; IP addresses. No other user data is collected. We have disclosed this in our terms and conditions.<\/p>\n<p>&#8220;We understand that some users have expressed concerns about this, and we apologize for any inconvenience or worry this situation may have caused. In response to this feedback, we are actively working to provide users with an option to opt out. Should we have the opportunity to re-release the app, we are committed to implementing a straightforward method for users to disable this feature.<\/p>\n<p>&#8220;Our team is dedicated to resolving this matter swiftly and effectively, ensuring that NightOwl can once again be enjoyed by users without any reservations. <a name=\"dispute\"><\/a>We greatly value the trust our users place in us and want to assure them that their satisfaction, security, and privacy remain our utmost priorities.&#8221;<\/p><\/blockquote>\n<h4><strong>The developer disputes some of Robinson&#8217;s claims<\/strong><\/h4>\n<p>When asked whether they disputed any of the claims in Robinson&#8217;s blog post, the company stated:<\/p>\n<blockquote><p>&#8220;Yes, we dispute the claims made in the post regarding (a) that this blogger contacted us for comment, they did not. If concerns had been raised directly we would have happily addressed and them. (b) that this is a botnet or in some way malicious. It is not malicious. <a name=\"plans\"><\/a>We made some mistakes in the implementation that we have been working to resolve for several weeks already.&#8221;<\/p><\/blockquote>\n<h4><strong>The developer&#8217;s plans moving forward<\/strong><\/h4>\n<p>Intego also asked whether the developer intends to re-release NightOwl under a different developer ID, since Apple appears to have blocked the previous account. The company responded:<\/p>\n<blockquote><p>&#8220;Our dev team has made several changes related to the concerns in this blog post and are taking the feedback we are receiving from ESET, Microsoft, etc. We hope that we can solve these issues with the antivirus companies and with our Apple Developer account and push an update that solves these problems. If we are not able to we will likely shut down NightOwl or we will sell it.&#8221;<\/p><\/blockquote>\n<p>This seems to imply that, at least for the time being, the company does not plan to attempt to obtain a second Apple developer account under which to re-release the app\u2014at least not without first making changes to try to comply with Apple&#8217;s terms of service. Perhaps the company might change its approach if it&#8217;s unable to return to Apple&#8217;s good graces.<\/p>\n<p>When asked whether the company plans to continue using tinyproxy, Pawns, or similar frameworks or monetizable behavior in NightOwl, the company responded, &#8220;If we are able to distribute the NightOwl app again we will look at all legitimate monetization options that are available.&#8221; <a name=\"monetization\"><\/a>Presumably, this may include continuing to use Pawns, since the company considers it &#8220;highly reputable.&#8221;<\/p>\n<h4><strong>Will monetization functionality be opt-in, or opt-out?<\/strong><\/h4>\n<p>The developer had stated earlier that &#8220;we are actively working to provide users with an option to opt out.&#8221; We sought further clarification. Was their intention to change the monetization functionality to an opt-in or opt-out model going forward?<\/p>\n<p>They stated, &#8220;If we are able to distribute the app again we will definitely make this feature optional and clear as to what it does.&#8221;<\/p>\n<p>This sounds like an improvement, but doesn&#8217;t clearly indicate the developer&#8217;s intentions. It&#8217;s unclear from this statement whether users will have to opt in to enable monetization features, <a name=\"qanda\"><\/a>or whether the functionality will remain enabled by default, requiring users to take action to opt out.<\/p>\n<h4><strong>Additional Q&amp;A with the current NightOwl developer<\/strong><\/h4>\n<p>We also asked several other follow-up questions. Here are our questions and their responses:<\/p>\n<p><strong>Q.<\/strong> How do you plan to earn back the trust of NightOwl users?<br \/>\n<strong>A.\u00a0<\/strong>We will add more clarity around our monetization practices.<\/p>\n<p><strong>Q. <\/strong>Will you rectify the alleged GPL violation over the use of tinyproxy?<br \/>\n<strong>A.\u00a0<\/strong>Yes, definitely. That has already been addressed if we were allowed to push an update.<\/p>\n<p><strong>Q. <\/strong>What have you learned from this experience? How will your company&#8217;s business practices change going forward?<br \/>\n<strong>A.<\/strong> We have taken several painful lessons from this experience that we will use to try and improve our practices and communication with our customers.<\/p>\n<p>In a later e-mail, we also asked whether TPE.FYI LLC is the current owner of NightOwl. We noted that the company name is nowhere to be found on the nightowlapp.co Web site, and public records seem to indicate that the company was dissolved around the same time that the new monetization behavior appears to have been implemented. As of publication time, the current developer had not responded to this inquiry.<\/p>\n<p>Oddly, the current developer&#8217;s site continues to strongly imply that Kramser is still developing NightOwl. The app&#8217;s homepage contains the original developer&#8217;s story, &#8220;Why I developed NightOwl,&#8221; without offering any indication that Kramser is no longer involved with the project.<a name=\"malwarepua\"><\/a><\/p>\n<h3>Is NightOwl malware, a PUA, or something else?<\/h3>\n<p>So is NightOwl malware or not? In our brief testing, we have not observed direct evidence that the software itself is overtly malicious or directly dangerous to users, so it does not appear to meet the strictest definition of harmful malware.<\/p>\n<p>However, broader definitions of malware can include software with behavior that some users would find undesirable, objectionable, deceptive, or a violation of trust.<\/p>\n<p>The current version of NightOwl does properly fall under the category of &#8220;potentially unwanted apps&#8221; (PUA, also known as &#8220;potentially unwanted programs&#8221; or PUP). This is specifically because of the unrelated background functionality of NightOwl that has nothing to do with its stated purpose, and which isn&#8217;t perfectly transparent to users.<\/p>\n<p>The app should have informed users\u2014either upon upgrading from a version by the original developer, or upon initial installation\u2014that the app contained functionality designed to earn revenue for the current developer by utilizing the user&#8217;s computer and Internet connection. Ideally, this would have been presented to the user in an explanatory dialog box, with the functionality disabled by default, requiring the user to click a checkbox to &#8220;opt in&#8221; to monetarily support the developer.<\/p>\n<p>If the developer really wanted some kind of payment from its users, another alternative could have been to switch the app to a paid model, or a &#8220;freemium&#8221; model that offered additional features with a paid upgrade.<\/p>\n<p>Defaulting to behavior such as Internet connectivity sharing, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/unwanted-cryptomining-debuts-briefly-in-mac-app-store\/\">cryptocurrency mining<\/a>, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/\">injecting ads<\/a>, or similar\u2014without verifying that the user understands the implications and can change their mind later\u2014is arguably a less-than-ethical practice. Such behavior often leads to security products detecting an app or some of its components as &#8220;potentially unwanted,&#8221; as was the case with NightOwl.<a name=\"cautionary\"><\/a><\/p>\n<h3>A cautionary tale: good apps can take a turn for the worse<\/h3>\n<p>In this case, NightOwl\u2014a popular and perfectly legitimate app\u2014changed ownership, after which a new owner introduced potentially unwanted changes the end-user was likely not aware of. The app updated and continued to work, so why would users go looking for updated terms of service?<\/p>\n<p>You might recall that back in 2016, a threat actor <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-hit-by-rare-ransomware-attack-spread-via-transmission-bittorrent-app\/\" target=\"_blank\" rel=\"noopener\">replaced a legitimate BitTorrent client, Transmission, with a modified version<\/a> on the company&#8217;s official servers. Users who updated the app during that time wound up with their Macs infected with malware. Five months later, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/malware-spreads-through-modified-transmission-application-again\/\">the same thing happened again<\/a>; the same legitimate app was compromised by a threat actor twice in the same year.<\/p>\n<p>The stories of NightOwl and Transmission are very different in terms of both who was responsible for the apps&#8217; changes and the level of potential harm imposed by those changes. However, both stories are similar in that users downloaded an app that was supposed to be safe based on past experience, but it turned out to have been modified with unexpected and undesirable functionality.<\/p>\n<p>In May of this year, we <a href=\"https:\/\/www.intego.com\/mac-security-blog\/wwdc-new-macs-macos-sonoma-ios-ipados-17-and-vision-pro-intego-mac-podcast-episode-295\/#:~:text=Malicious%20Chrome%20browser%20extensions%20purged%20from%20the%20Chrome%20Web%20Store\">reported<\/a> on the <a href=\"https:\/\/podcast.intego.com\">Intego Mac Podcast<\/a> that nearly three dozen browser extensions in the Chrome Web Store contained search-hijacking code. Some of the extensions had contained that unadvertised malicious functionality for nearly two years before <a href=\"https:\/\/palant.info\/2023\/05\/31\/more-malicious-extensions-in-chrome-web-store\/\" target=\"_blank\" rel=\"noopener\">Wladimir Palant blogged about the problem<\/a>, and Google finally took them down. But in the mean time, those 34 extensions had amassed 87 million users.<\/p>\n<p>Intego&#8217;s Chief Security Analyst, Josh Long, pointed out on the podcast that sometimes this sort of thing happens &#8220;when a developer stops working on an extension or app, [and] someone else comes along and offers the developer a bunch of money and says, &#8216;Here, I\u2019ll take over development.&#8217; And then they start developing it and add malicious things to it.&#8221; While it&#8217;s unclear whether that may have been the case with the 34 Chrome extensions, <strong>it has certainly happened before, and will inevitably happen again\u2014quite possibly with other Mac apps<\/strong>.<\/p>\n<p>In fact, just days ago, the developer of a Chrome extension with 300,000 users spoke out about having received <strong><a href=\"https:\/\/www.theregister.com\/2023\/08\/11\/chrome_extension_developer_pressure\/\" target=\"_blank\" rel=\"noopener\">more than 130 solicitations to &#8220;monetize&#8221; his extension<\/a><\/strong>. If cybercriminals can find a way to infect or exploit hundreds of thousands of users at once, wouldn&#8217;t you expect them to at least try? And wouldn&#8217;t you expect that some developer, at some point, will take the bait, perhaps not fully understanding what they&#8217;re getting into? This is a serious problem, and it&#8217;s not going away anytime soon.<a name=\"vigilant\"><\/a><\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/player.fireside.fm\/v2\/GegHgcrH+sWfMXGLd?theme=dark\" width=\"740\" height=\"200\" frameborder=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<h4><strong>Stay vigilant; read EULAs, and use protection software<\/strong><\/h4>\n<p>In short, there are many ways that software with potentially unwanted behavior can find its way onto your Mac.<\/p>\n<p>Unless an app makes its terms of use very clear\u2014and makes it obvious whenever there are changes\u2014users will likely not notice. With almost every app, service, and website you use, you must agree to terms of use (TOU) or end-user license agreements (EULA). Sometimes these can change overnight, without any fanfare\u2014though often you&#8217;ll get an e-mail or a pop-up in your app to notify you that something has changed.<\/p>\n<p>The reality is that very few people actually read (and understand) all of the terms of use before clicking or tapping &#8220;Accept.&#8221; If we did, we&#8217;d all use a lot fewer apps and services, as most of them contain clauses with which we would not be comfortable.<\/p>\n<p>Back in 2019, we <a href=\"https:\/\/podcast.intego.com\/87\">discussed<\/a> on the Intego Mac Podcast a <a href=\"https:\/\/www.nytimes.com\/interactive\/2019\/06\/12\/opinion\/facebook-google-privacy-policies.html\" target=\"_blank\" rel=\"noopener\">New York Times expos\u00e9<\/a>. In it, the Times claimed that privacy policies (which are full of legalese, much like TOUs and EULAs) &#8220;were an incomprehensible disaster.&#8221; In fact, &#8220;Only Immanuel Kant\u2019s famously difficult &#8216;Critique of Pure Reason&#8217; registers a more challenging readability score than Facebook\u2019s privacy policy,&#8221; according to the piece&#8217;s author.<\/p>\n<p>But even if you can&#8217;t fully comprehend legalese, it&#8217;s a good idea to at least try to understand what you&#8217;re getting into. At least skim through the text to see if any key words stand out. Even if you do decide to hit that &#8220;Accept&#8221; button, at least you&#8217;ll have a somewhat better idea of potential privacy or security implications.<\/p>\n<p>As additional layers of protection, <a href=\"https:\/\/www.intego.com\/business\/virus-barrier\" target=\"_blank\" rel=\"noopener\">Intego VirusBarrier<\/a> can watch for malware and PUAs for you, and <a href=\"https:\/\/www.intego.com\/business\/network-protection\" target=\"_blank\" rel=\"noopener\">Intego NetBarrier<\/a> can alert you if suspicious connections are attempted by any app or background process. Both tools are available as part of Intego&#8217;s <a href=\"https:\/\/www.intego.com\/antivirus-mac-internet-security\">Mac Internet Security X9<\/a> and full-featured <a href=\"https:\/\/www.intego.com\/mac-protection-bundle\">Mac Premium Bundle X9<\/a> software suites.<a name=\"uninstall\"><\/a><\/p>\n<h3>Should I uninstall NightOwl? How can I do so?<\/h3>\n<p>Although NightOwl is not overtly malicious, the app does contain background monetization functionality that cannot be opted out of within the app itself. Some third-party sites that have mentioned NightOwl in the past have either removed their articles or added warning text, citing concerns.<\/p>\n<p>Until the app introduces a way to opt out, and provides clear notices during installation and upon launching the app, some users may wish to uninstall it. Some of NightOwl&#8217;s functionality is built into macOS, so removing it will not be a devastating loss to most users.<\/p>\n<p><strong>If you currently have NightOwl installed and want to manually uninstall it<\/strong>, you can run the following commands in the Terminal app. (These commands are a modified version of Robinson&#8217;s manual removal instructions.) Note that there is no need to run these commands if you&#8217;ve never used NightOwl on your Mac, or if you uninstalled it before October 2022.\u00a0<strong>Always be careful when running Terminal commands.<\/strong><\/p>\n<ol>\n<li>First, you&#8217;ll ensure that NightOwl isn&#8217;t running for anyone who&#8217;s currently logged into your Mac. Copy and paste (or type) the following into Terminal, and press the Enter key on the keyboard.<code>sudo killall NightOwl<\/code>You&#8217;ll be prompted to enter your password. Type it and press Enter.<\/li>\n<li>Next, you&#8217;ll unload NightOwl&#8217;s LaunchAgent (its method of persistence). Copy and paste the following into Terminal, and press the Enter key on the keyboard.<code>launchctl unload ~\/Library\/LaunchAgents\/NightOwlUpdater.plist<\/code><\/li>\n<li>Third, you&#8217;ll verify whether NightOwl&#8217;s AutoUpdate app is running, and if so, you&#8217;ll quit it. Copy and paste this entire command into Terminal, then press Enter.<code>sudo ps -ax | grep \/Applications\/NightOwl.app\/Contents\/Helpers\/AutoUpdate | grep -v grep<\/code>If you&#8217;re immediately taken back to the <code>%<\/code> prompt, then the AutoUpdate app isn&#8217;t running, and you can move on to step 4. If, however, you get a line that starts with a number, for example\u2026\n<pre>#### ?? 0:01.09 \/Applications\/NightOwl.app\/Contents\/Helpers\/AutoUpdate<\/pre>\n<p>\u2026that means the app is running, so you&#8217;ll need to type the following into the Terminal (replacing &#8220;####&#8221; with the unique number for your system) and press Enter.<\/p>\n<p><code>sudo kill -9 ####<\/code><\/li>\n<li>Next, you&#8217;ll remove the app from your Applications folder. You can either drag it to the Trash, or copy and paste the following command into Terminal and press Enter.<code>sudo rm -rf \/Applications\/NightOwl.app<\/code><\/li>\n<li>Finally, you&#8217;ll uninstall the LaunchAgent. Since the LaunchAgent file is installed on a per-user basis, the following command should remove any copies from all user accounts on your Mac. Copy and paste this entire command into Terminal, then press Enter.<code>sudo zsh -c \"rm \/Users\/*\/Library\/LaunchAgents\/NightOwlUpdater.plist\"<\/code><\/li>\n<\/ol>\n<p>Again, it&#8217;s only necessary to run these commands if you currently have NightOwl installed and wish to remove it from your Mac.<a name=\"removeprevent\"><\/a><\/p>\n<h3>How can one remove or prevent Mac malware and PUAs?<\/h3>\n<p><img loading=\"lazy\" class=\"alignright size-medium wp-image-54214\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png\" alt=\"Intego X9 software boxes\" width=\"200\" height=\"100\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch.png 600w\" sizes=\"(max-width: 200px) 100vw, 200px\" \/><\/p>\n<p>Intego VirusBarrier X9, included with <strong><a href=\"https:\/\/www.intego.com\/mac-protection-bundle\">Intego&#8217;s Mac Premium Bundle X9<\/a><\/strong>, can protect against, detect, and eliminate potentially unwanted components of NightOwl. Intego products detect components of applicable versions of NightOwl as variants of <strong>OSX\/Agent<\/strong> or <strong>OSX\/Downloader.go<\/strong>.<\/p>\n<p>VirusBarrier had already been detecting many components related to NightOwl&#8217;s potentially unwanted background behavior for months before this story hit the news. Additionally, Intego NetBarrier would have warned users about NightOwl&#8217;s attempts to connect to the developer&#8217;s sketchy-sounding &#8220;squidyproxy&#8221; servers.<\/p>\n<p>If you believe your Mac may have a PUA or may be infected with malware\u2014or to prevent future infections\u2014use trusted endpoint protection software. VirusBarrier is an award-winning antivirus, designed by Mac security experts, that includes <a href=\"https:\/\/www.intego.com\/mac-security-blog\/why-your-antivirus-needs-real-time-scanning\/\">real-time protection<\/a>. It&#8217;s compatible with a variety of Mac hardware and OS versions, including the latest Apple silicon Macs running macOS Ventura.<\/p>\n<p>Additionally, if you use a Windows PC, <a href=\"https:\/\/www.intego.com\/intego-antivirus\"><strong>Intego Antivirus for Windows<\/strong><\/a> can keep your computer protected from malware.<\/p>\n<p><span style=\"font-size: small;\">VirusBarrier X6, X7, and X8 on older Mac OS X versions also provide protection. Note, however, that it is best to upgrade to the latest versions of macOS and VirusBarrier; this will help ensure your Mac gets all the latest security updates from Apple.<a name=\"iocs\"><\/a><\/span><\/p>\n<h3>Indicators of compromise (IoCs) for affected NightOwl versions<\/h3>\n<p>The following SHA-256 hashes relate to components of affected versions of NightOwl:<\/p>\n<pre>0f6413100fbdc43bf4a8a044f3d1a9bb5394d04eb2f2006a5337d640eb668176\r\n0f709d2ddd851cd97faa9e873d9a733fa125b5f2c0d90448bf48b1e00558f33b\r\n0fc3cc3c6557c12551adfec80e68cd16605fa2c306e792dc2a3e6e50b7389e37\r\n14d1da4c833f3171c7d1a15c680673438ec899da1f524e8b1389c42e209412df\r\n22d3b5e8dbaaa0956ff18580f3298fbe7a2e93c22714b8a47a810052e544e20d\r\n266f3dd7a0c27b0730e9a893cde59ede22e49aa6c93d5e3b1fbba1436f3336ee\r\n2e32ca66934d2395d4b05a5d91408f3fc9d633e0fa2a4b6ec27e5d9ccbd1c558\r\n2e9baf82d33185d6c26b839dc27c9de3fcbb6e26831288c2b5233a66c7b9127a\r\n34fd2f6671fb633aa91547abb5c169aeace49ad5150df1dba52a09f6bc09b25f\r\n375ef0eb310d3fa82ddb5357ecd35e6991cfd0540635616ffc799bf9c6fe8816\r\n3d4c278b1f19aa5a57ab12a6ccb4f9fa6039ee77c6c292ce541a252a99769404\r\n3fae06e5604a30725c1076a80c89d944570603781c7426c90d8d6801d1b7d328\r\n41fabb080f831f05e555112c040482a1f500b70c1517c4f81e41aa1d54092b8e\r\n4c0621a1a5cb64639e530706ae187862cd0886bc6da32746186dc82a0be56469\r\n4f2e2df0cfe52ad44f7d4a84607536054ff6b7fc653152719f60867328aedf4f\r\n51f0c20476c14e879a71c649826e0a48d78a8b7b26dad0029ee514abdba32e90\r\n636a445be68622390c77e2d251e546580d460f1ca53ed39cb1739afc68b3cd64\r\n696efc15b94f425925bdc6bee015a23718d18f3838287fb906cfc4ccc0ffa887\r\n81348ba0b13fd617ab5127bbbc21b5fbced41400ed933cc438fe79fa75453682\r\n83fba898df5dab1720ec6e402f5056c42792028c84056c9d3b3971823f49bc1d\r\n840fd039b2509fb50b328c0b5ada8c7300608e57bce8ce1bce822ee34b23fa52\r\n854d48bcc399be41e357f14b551aaf5d84481971932e2ebad3b9a213d95e0101\r\n87054757a431e9d123829c5e5c357efe934d5bccf80b51f107c34df903cc198e\r\n8cd7093915b08264160bd37a973f5cf8e11b5e61e419481edbf264f06a311088\r\n92b04da46ffb7318b1b0eb42c203fabd859abd743cff4389b4eeb00d57941cf5\r\n968be90244a7ff16d3b0b759e3ae26b4b6becf82de6d5da664d53a1041efeee2\r\n97c1e9a931d70c1675533a5ca58c4035f4d7ffd295dd30be79a62d7d58bcde1c\r\na9b1b3bfeec9a35fccb8a805f149cbe50e7ff9f3e0732e237f5ff937e38e8f9b\r\nb8d2bea73a19c2dd257bb31288cf7a2e44e22ae0f047adb90f8cb5f6dd0462d2\r\nbabc7a17f4a78acbea5687871dcd2c0e7b76ec2dd118bc96f589f1d5c9e3ec4f\r\nd99f067016eb476b3cc96b2d9ad17597a3cd0138375536ee26e017c78f9113ab\r\ne06ae6061d743b928171b459105e939917f387b043ef91d4000d518415f8a958\r\ne15d354c385a065f8c01fb2b7df37fffe7d80dc3a6767480f05893f5939024a9\r\ne2e1a7f638f85139b9188e1c60d47a7832a0b3388dfa0269583e89924fa4f47e\r\nf3cadf4e43b13f9ed7ad0325c6ec27aa52046a8ad5858e70143f82ed6d177d51\r\nf86dd4bc66540323fdd88ec058be87f1535be2cd6843846453b59cfc1f8bb1ae<\/pre>\n<p>Affected versions of NightOwl are signed with the following Team Identifier:<\/p>\n<pre>TPE-FYI, LLC (7J27HUBW2X)<\/pre>\n<p>Apple recently revoked the developer&#8217;s code-signing certificate.<\/p>\n<p>Note that older versions of NightOwl, prior to its sale, are code-signed with a Team Identifier belonging to Benjamin Kramser (2AVLWWC6KL). Antivirus software should not detect these files as malicious.<\/p>\n<p>If installed, NightOwl&#8217;s components can be found at the following locations:<\/p>\n<pre>\/Applications\/NightOwl.app\r\n~\/Library\/LaunchAgents\/NightOwlUpdater.plist<\/pre>\n<p>Note that <code>~<\/code> indicates the current user&#8217;s home directory, for example <code>\/Users\/username<\/code>. If you have multiple user accounts on an affected system, you may need to check for the LaunchAgent plist file in those accounts as well.<\/p>\n<p>The following domain and subdomains have reportedly been used by affected NightOwl versions to tunnel communications over SSH:<\/p>\n<pre>*.squidyproxy[.]com\r\nproxy-api1.squidyproxy[.]com\r\nproxy-gw1-europe.squidyproxy[.]com<\/pre>\n<p>This domain was registered in early April 2022, approximately seven months before TPE.FYI LCC acquired NightOwl.<\/p>\n<p>Network administrators can check recent network traffic logs to try to identify whether any computers on their network may have attempted to contact this domain or any subdomain thereof. Its presence in logs could indicate that a Mac on the network may have an affected version of NightOwl installed.<a name=\"other-names\"><\/a><\/p>\n<h3>Do security vendors detect this by any other names?<\/h3>\n<p>Other antivirus vendors&#8217; names for various components of affected versions of NightOwl may include variations of the following:<\/p>\n<p><span style=\"font-size: small;\">A Variant Of OSX\/HackTool.Chisel.A, A Variant Of OSX\/IPRoyal.Pawns.A Potentially Unwanted, A Variant Of OSX\/Packed.Obfuscated.A Suspicious, ABRisk.ZWCO-7, Adware\/Chisel!OSX, Adware\/IPRoyal_Pawns!OSX, Application.Mac.Agent.IS (B), Application.MAC.Generic.1621 (B), Backdoor:MacOS\/Multiverze, HackTool:MacOS\/Chisel.A!MTB, Hacktool.OSX.Chisel.3!c, HEUR:Backdoor.OSX.Sliver.gen, HEUR:HackTool.OSX.Agent.q, HEUR:Trojan-Proxy.OSX.Agent.gen, HEUR:Trojan.OSX.Agent.gen, Heuristic.HEUR\/OSX.MalSource.coekb, Heuristic.HEUR\/OSX.MalSource.ejnsf, Heuristic.HEUR\/OSX.MalSource.gzsbj, heuristic\/HEUR\/OSX.MalSource.zfkkg, MacOS:Chisel-A [PUP], Malware.OSX\/Agent.epnfc, Malware.OSX\/Agent.ichko, Malware.OSX\/Agent.jbpzj, Malware.OSX\/Agent.kciip, Malware.OSX\/Agent.mzltd, Malware.OSX\/Agent.ofrgi, Malware.OSX\/Agent.qwkuf, Malware.OSX\/Agent.whlfq, Malware.OSX\/Agent.wojiw, Malware.OSX\/AVI.Agent.muate, Malware.OSX\/AVI.Agent.pxing, Malware.OSX\/Sliver.igtnf, Not-a-virus:HEUR:Server-Proxy.OSX.Chisel.a, Not-a-virus:HEUR:Server-Proxy.OSX.Monetizer.c, Not-a-virus:HEUR:Server-Proxy.OSX.Monetizer.d, Not-a-virus:UDS:Server-Proxy.OSX.Monetizer, Osx.Server-Proxy.Chisel.Jajl, Osx.Server-Proxy.Chisel.Vwhl, Osx.Trojan.Agent.Cdhl, Osx.Trojan.Agent.Etgl, Osx.Trojan.Agent.Gkjl, Osx.Trojan.Agent.Hajl, Osx.Trojan.Agent.Lajl, Osx.Trojan.Agent.Lqil, Osx.Trojan.Agent.Msmw, Osx.Trojan.Agent.Nsmw, Osx.Trojan.Agent.Osmw, Osx.Trojan.Agent.Pgil, Osx.Trojan.Agent.Rwhl, Osx.Trojan.Agent.Sgil, Osx.Trojan.Agent.Vwhl, OSX.Trojan.Gen.2, Osx.Trojan.Sliver.Vgil, OSX\/Agent-BKCU, OSX\/Agent.fs, OSX\/Agent.gen, OSX\/Chisel.ext, Other:PUP-gen [PUP], Packed:MacOS\/Obfuscated.1e476793, Program:MacOS\/Multiverze, Program.APPL\/GM.Agent.BK, Program.APPL\/GM.Pawns.LS, ProxyTool:MacOS\/Monetizer.c, PUA:Win32\/Puwaders.C!ml, PUA:Win32\/Vigua.A, PUA.Generic, Riskware.OSX.Monetizer.1!c, Riskware.OSX.Pawns.1!c, Riskware.ZIP.Monetizer.1!c, Riskware\/Application!OSX, Static AI &#8211; Suspicious Mach-O, Trojan:MacOS\/Multiverze, Trojan:Win32\/Vigorf.A, Trojan.MAC.Generic.112645 (B), Trojan.OSX.Agent.4!c, Trojan.OSX.Generic.4!c, Trojan.OSX.Poseidon, Trojan.OSX.Psw, Trojan.OSX.Sliver.4!c, Trojan.ZIP.Generic.4!c, virus\/OSX\/Agent.epnfc, virus\/OSX\/Agent.illay, virus\/OSX\/Agent.udgyc, virus\/OSX\/Agent.uppvw<\/span><a name=\"learnmore\"><\/a><\/p>\n<h3>How can I learn more?<\/h3>\n<p>For additional technical details about the NightOwl kerfuffle, you can read <a href=\"https:\/\/robins.one\/notes\/uninstall-the-nightowl-app-now.html\" target=\"_blank\" rel=\"noopener nofollow\">Taylor Robinson&#8217;s original write-up<\/a> from June 28.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/04\/intego-podcast-artwork-400.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"><img class=\"alignleft\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/04\/intego-podcast-artwork-400.jpg\" alt=\"\" width=\"80\" \/><\/a><\/p>\n<p>Each week on the <a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Intego Mac Podcast<\/strong><\/a>, Intego&#8217;s Mac security experts discuss the latest Apple news, including security and privacy stories, and offer practical advice on getting the most out of your Apple devices. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" rel=\"noopener\"><strong>follow the podcast<\/strong><\/a> to make sure you don\u2019t miss any episodes.<\/p>\n<p>You can also subscribe to our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-security-newsletter\/\"><strong>e-mail newsletter<\/strong><\/a> and keep an eye here on <a href=\"https:\/\/www.intego.com\/mac-security-blog\"><strong>The Mac Security Blog<\/strong><\/a> for the latest Apple security and privacy news. And don&#8217;t forget to follow Intego on your favorite social media channels: <a href=\"https:\/\/twitter.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on \ud835\udd4f\/Twitter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/X-Twitter-logo-icon-225.gif\" alt=\"Follow Intego on X\/Twitter\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Facebook\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Facebook-logo-icon-225.gif\" alt=\"Follow Intego on Facebook\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on YouTube\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/YouTube-logo-icon-225.png\" alt=\"Follow Intego on YouTube\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.pinterest.com\/intego\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on Pinterest\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Pinterest-logo-icon-225.png\" alt=\"Follow Intego on Pinterest\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on LinkedIn\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/LinkedIn-logo-icon-225.gif\" alt=\"Follow Intego on LinkedIn\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Instagram\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Instagram-logo-icon-225.gif\" alt=\"Follow Intego on Instagram\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow the Intego Mac Podcast on Apple Podcasts\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png\" alt=\"Follow the Intego Mac Podcast on Apple Podcasts\" width=\"16\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A blogger recently claimed that NightOwl, a popular app, enlists Macs in a botnet. Apple seemed to agree that something was off, revoking the NightOwl code-signing certificate. But is the app really malware? Here is the full story.<\/p>\n","protected":false},"author":79,"featured_media":98627,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[190],"tags":[513,505,86,2032,114],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"A blogger recently claimed that NightOwl, a popular app, enlists Macs in a botnet. Apple seemed to agree that something was off, revoking the NightOwl code-signing certificate. But is the app really malware? Here is the full story.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Did the NightOwl app really join Macs to a botnet army? - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"A blogger recently claimed that NightOwl, a popular app, enlists Macs in a botnet. Apple seemed to agree that something was off, revoking the NightOwl code-signing certificate. But is the app really malware? Here is the full story.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-15T03:28:05+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-21T08:49:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jay Vrijenhoek\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"24 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg\",\"width\":400,\"height\":260,\"caption\":\"NightOwl becomes a PUA, adds undesirable background behavior\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/\",\"name\":\"Did the NightOwl app really join Macs to a botnet army? - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#primaryimage\"},\"datePublished\":\"2023-08-15T03:28:05+00:00\",\"dateModified\":\"2024-05-21T08:49:48+00:00\",\"description\":\"A blogger recently claimed that NightOwl, a popular app, enlists Macs in a botnet. Apple seemed to agree that something was off, revoking the NightOwl code-signing certificate. But is the app really malware? Here is the full story.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Did the NightOwl app really join Macs to a botnet army?\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0\"},\"headline\":\"Did the NightOwl app really join Macs to a botnet army?\",\"datePublished\":\"2023-08-15T03:28:05+00:00\",\"dateModified\":\"2024-05-21T08:49:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#webpage\"},\"wordCount\":5069,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg\",\"keywords\":[\"Bot\/Zombie\",\"Botnet\",\"Malware\",\"PUA\/PUP\",\"Rogue Software\"],\"articleSection\":[\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0\",\"name\":\"Jay Vrijenhoek\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g\",\"caption\":\"Jay Vrijenhoek\"},\"description\":\"Jay Vrijenhoek is an IT consultant with a passion for Mac security research.\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/jay-vrijenhoek\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"A blogger recently claimed that NightOwl, a popular app, enlists Macs in a botnet. Apple seemed to agree that something was off, revoking the NightOwl code-signing certificate. But is the app really malware? Here is the full story.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/","og_locale":"en_US","og_type":"article","og_title":"Did the NightOwl app really join Macs to a botnet army? - The Mac Security Blog","og_description":"A blogger recently claimed that NightOwl, a popular app, enlists Macs in a botnet. Apple seemed to agree that something was off, revoking the NightOwl code-signing certificate. But is the app really malware? Here is the full story.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/","og_site_name":"The Mac Security Blog","article_published_time":"2023-08-15T03:28:05+00:00","article_modified_time":"2024-05-21T08:49:48+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jay Vrijenhoek","Est. reading time":"24 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg","width":400,"height":260,"caption":"NightOwl becomes a PUA, adds undesirable background behavior"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/","name":"Did the NightOwl app really join Macs to a botnet army? - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#primaryimage"},"datePublished":"2023-08-15T03:28:05+00:00","dateModified":"2024-05-21T08:49:48+00:00","description":"A blogger recently claimed that NightOwl, a popular app, enlists Macs in a botnet. Apple seemed to agree that something was off, revoking the NightOwl code-signing certificate. But is the app really malware? Here is the full story.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Did the NightOwl app really join Macs to a botnet army?"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0"},"headline":"Did the NightOwl app really join Macs to a botnet army?","datePublished":"2023-08-15T03:28:05+00:00","dateModified":"2024-05-21T08:49:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#webpage"},"wordCount":5069,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg","keywords":["Bot\/Zombie","Botnet","Malware","PUA\/PUP","Rogue Software"],"articleSection":["Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/did-the-nightowl-app-really-join-macs-to-a-botnet-army\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0","name":"Jay Vrijenhoek","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g","caption":"Jay Vrijenhoek"},"description":"Jay Vrijenhoek is an IT consultant with a passion for Mac security research.","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/jay-vrijenhoek\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/08\/NightOwl-undesirable-behavior-400x260-1.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-pEB","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/98617"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/79"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=98617"}],"version-history":[{"count":12,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/98617\/revisions"}],"predecessor-version":[{"id":100711,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/98617\/revisions\/100711"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/98627"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=98617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=98617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=98617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}