From the archive. We first published this in May 2011. Apple added built-in protection against MacDefender shortly after, and macOS now checks downloaded software automatically. The fake security program is long gone, but the tricks it used are still the most common way Mac users get taken in.
Everyone has heard that Macs do not have the virus problems that plague many Windows PCs. Mac OS X is designed with layers of built-in security that protect against most malicious software right out of the box.
Even so, there are a few kinds of threats every Mac user should know about. A clever fake security program aimed squarely at Mac users makes this a good time to review them.
MacDefender (also called Mac Security and MacProtector)
Our most urgent advice: do not install a program called MacDefender. It is a polished piece of rogueware, explained below, that has been spreading mainly through poisoned Google Image search results.
Here is how it works. You are browsing and land on a page that starts warning you that your Mac has viruses. Click anywhere on the page and your Mac downloads an installer and tries to run it. It needs your password to install. Without your password it cannot do anything, so do not give it your password. Close the page, even if it warns that you will not be protected.
Safari is already blocking most known sources of MacDefender with a malware warning. Newer versions go by other names, including Mac Security and MacProtector, but they all work the same way.
Social engineering
MacDefender belongs to a broad category of threats that use social engineering: manipulating people into handing over confidential information or doing something that gives a program access it should not have. It is the modern version of the con game.
These tricks do not attack weaknesses in your computer. They target you, and ironically they work by playing on your fear of theft, viruses and intrusion. The best defense is simply knowing what they look like.
Phishing
Phishing is the name for emails that try to get your bank details, usernames, passwords and credit card numbers. Some are easy to spot, with bad grammar or promises of riches. Others look a lot like real email from your bank, PayPal or eBay.
They are easy to beat. If an email looks like it is from your bank, do not click its links. Open your browser and go to the bank's site the way you normally do, with a bookmark or by typing the address. If something really needs your attention, you will see it after you sign in.
Trojan horses
A trojan horse is malware that pretends to be legitimate software, so that you carry it through your own walls. One real Mac example, from 2004, posed as a free installer for a pirated copy of Microsoft Office on file-sharing networks. Anyone who ran it risked having their documents deleted.
Keeping trojans out is not hard. Get your software only from legitimate sources, and be especially wary of anything you did not set out to download.
Rogueware and scareware
Rogueware like MacDefender is fake security software, a kind of trojan that claims it will protect or clean your computer. It is also called scareware, because it works hard to frighten you into installing it by claiming your computer is already infected. If you ever have doubts about installing something, ask an expert first.
If you think you have installed it
Apple published instructions for removing MacDefender and announced an update with built-in protection. Removing it is easy. If you gave it your credit card number, though, contact your card company right away to protect your account.