This article has been created in order to help explain what is the OSX.Calisto Trojan and how you can effectively remove this malware from your Mac.
SIDENOTE: This post was originally published in August 2018. But we gave it an update in August 2019.
A new Trojan for OSX was recently detected by Symantec researchers. The malware reportedly uses it’s permissions to obtain live information from the victim’s Mac and relay it to the cyber-criminals who are behind the virus. The Trojan is also reported to have other functions that are primarily related to taking screenshots as well as stealing passwords and also files from the victim computers. If your Mac has been infected by the OSX.Calisto Trojan, we strongly suggest that you read this article as it may help you learn more about this virus plus help you to remove it from your computer effectively.
|Type||Trojan for OSX|
|Short Description||Used to steal files, take screenshots, steal keychains and also obtain other information from the infected Mac|
|Symptoms||A Calisto App that might exist in your list of installed apps.|
|Distribution Method||Likely via a fake app that pretends to be of a helpful type or via a malicious web link.|
|Detection Tool|| See If Your System Has Been Affected by OSX.Calisto |
|User Experience||Join Our Forum to Discuss OSX.Calisto.|
OSX.Calisto – How Did I Get It
The main method by which Trojan horses, like Calisto are slithered into Mac Books are via fake apps that are offered by what only seems reputable websites. The bad news here is that most of those applications may be uploaded by someone with a more sinister goals, like to hack your Mac, for example. In order to get you to download and install the app, the publisher may make it seem as the app is something you are looking for, like a converter app, video editor, Snapchat filter app or any other often downloaded applications. While the app may work properly, it may also contain malicious code, whose primary purpose is to activate the OSX.Calisto Trojan on your Mac.
But this may not be the only method of infection that this malware may use on you. The OSX.Calisto Trojan may also be spread as a result of malicious e-mails being sent to victims. These e-mails often contain malicious e-mail attachments embedded within them, for example:
The end goal is to convince victims that the attachment uploaded is some kind of important invoice, receipt or other document and it is urgent that the user reads it’s content. But often to enable the content on such fake documents, users are asked to enable Macros on their Mac, which may result in the triggering of the OSX.Calisto infection.
OSX.Calisto – More Information
Once OSX.Calisto has already infected your mac, the malware drops the following files in your User directory:
Once the OSX.Calisto threat drops it’s malicious files, the virus deletes a crucial DMG file within the infected Mac machine. This effectively allows for the Trojan to establish remote access to the compromised Mac. Once the Calisto malware has taken over your Mac, the virus may connect to several http hosts and load the following .php files:
These files are likely used to relay information from the infected machine and successfully establish remote access. Calisto can perform the following remote operations on your Mac if it has infected it:
- Enable the remote login and control to the hackers.
- Enable the sharing of your Mac screen live.
- Enable control over the permissions enabling of apps.
- Allow hackers to login remotely to all the users on the Mac.
- Allow hackers to create their own accounts.
In addition to thiose activities, the OSX.Calisto can become an even meaner threat, since it can use it’s permissions to perform the following activities:
- Upload files from your Mac.
- Download files.
- Run files..
- Steal files.
- Steal keychains.
- Obtain your cookies.
- Steal your saved passwords.
If you see a folder, named %calisto% or any app of such similarity, it is strongly recommended that you immediately remove it from your computer.
Remove OSX.Calisto Trojan from Your Mac
If you believe that your Mac has been infected by this Trojanized app, you should immediately take actions towards securing it. One of those actions is to manually delete Calisto if it is added as an app, or to use the information in this article to eliminate the malicious files. However, this may not solve your problem, since infections of this Type often have backed up files on standby and may restart the infection afte removal. This is why, for maximum effectiveness, it is strongly recommended that you remove OSX.Calisto Trojan automatically from your Mac with the aid of a powerful anti-malware program. Such specific software aims to automatically remove all traces and objects of OSX.Calisto malware and ensures that your Mac remains protected against malware in the future too.