{"id":14485,"date":"2013-05-21T12:54:29","date_gmt":"2013-05-21T19:54:29","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=14485"},"modified":"2026-07-02T01:41:28","modified_gmt":"2026-07-02T08:41:28","slug":"yet-another-filesteal-variant-found-today","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/","title":{"rendered":"Yet Another FileSteal Variant Found Today"},"content":{"rendered":"<p>As we predicted in our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/two-new-variants-of-backdoor-trojan-found-targeting-activists\/\">previous post on OSX\/Filesteal<\/a>, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A.<\/p>\n<p>The server used by this variant is at:<\/p>\n<ul>\n<li>liveapple.eu\/MEny\/upload.php<\/li>\n<\/ul>\n<p>At the time of writing, the site was not responding.<\/p>\n<p>It comes in a ZIP archive with the following file name:<\/p>\n<ul>\n<li>Christmas_Card.app.zip (SHA256 &#8211; 07062d9ecb16bd3a4ea00d434f469fe63d5c1c95d1b4903705de31353e9c92ce)<\/li>\n<\/ul>\n<p style=\"text-align: center;\"><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/ChristmasCard.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-14487\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/ChristmasCard.png\" alt=\"Christmas_Card.app\" width=\"156\" height=\"121\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/ChristmasCard.png 156w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/05\/ChristmasCard-150x116.png 150w\" sizes=\"auto, (max-width: 156px) 100vw, 156px\" \/><\/a><\/p>\n<p>Inside the ZIP is an application with the following name:<\/p>\n<ul>\n<li>FileBackup (SHA256 &#8211; e25bc53c1255507d17d7fa5cf79721d413f97250f6bf10df93f222f6a3073cf3)<\/li>\n<\/ul>\n<p>This executable is signed with the same revoked developer certificate as the FileSteal.B variant, attributed to &#8220;Rajinder Kumar.&#8221;<\/p>\n<p>It&#8217;s good to remember, this information is useful for what&#8217;s called &#8220;indications of compromise.&#8221; If you see a file that matches these descriptions, there is a good chance that it&#8217;s not a beneficial file. However, this does not mean that any file that doesn&#8217;t match these descriptions will be safe. It&#8217;s not possible to list the places you should not go on the Internet, in order to be safe. There could be malvertisements or compromises that happen at any time, and you should always exercise caution, particularly when you&#8217;re surfing the web or when you receive unexpected files via email.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/features\/virus-scanner\">Intego VirusBarrier<\/a> users with up-to-date virus definitions will detect this trojan as OSX\/FileSteal.A.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we predicted in our previous post on OSX\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A. The server used by this variant is at: liveapple.eu\/MEny\/upload.php At [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[190,5],"tags":[405,86,399],"class_list":["post-14485","post","type-post","status-publish","format-standard","has-post-thumbnail","category-malware","category-security-news","tag-christmas_card-app","tag-mac-malware","tag-osxfilesteal"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"As we predicted in our previous post on OSX\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A. The server used by this variant is at: liveapple.eu\/MEny\/upload.php At\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Lysa Myers\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Yet Another FileSteal Variant Found Today\" \/>\n\t\t<meta property=\"og:description\" content=\"As we predicted in our previous post on OSX\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A. The server used by this variant is at: liveapple.eu\/MEny\/upload.php At\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2013-05-21T19:54:29+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-02T08:41:28+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Yet Another FileSteal Variant Found Today\" \/>\n\t\t<meta name=\"twitter:description\" content=\"As we predicted in our previous post on OSX\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A. The server used by this variant is at: liveapple.eu\/MEny\/upload.php At\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#blogposting\",\"name\":\"Yet Another FileSteal Variant Found Today\",\"headline\":\"Yet Another FileSteal Variant Found Today\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert.png\",\"width\":400,\"height\":260},\"datePublished\":\"2013-05-21T12:54:29-07:00\",\"dateModified\":\"2026-07-02T01:41:28-07:00\",\"inLanguage\":\"en-US\",\"commentCount\":2,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#webpage\"},\"articleSection\":\"Malware, Security News, Christmas_Card.app, Malware, OSX\\\/FileSteal, lysam\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"position\":2,\"name\":\"Security News\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#listItem\",\"name\":\"Yet Another FileSteal Variant Found Today\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#listItem\",\"position\":3,\"name\":\"Yet Another FileSteal Variant Found Today\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a244278f35cc41c7ec676b36673dee0464ed8c7ceafb1ff484fdf13a916d126c?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Lysa Myers\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/\",\"name\":\"Yet Another FileSteal Variant Found Today\",\"description\":\"As we predicted in our previous post on OSX\\\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\\\/FileSteal.A. The server used by this variant is at: liveapple.eu\\\/MEny\\\/upload.php At\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#mainImage\",\"width\":400,\"height\":260},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yet-another-filesteal-variant-found-today\\\/#mainImage\"},\"datePublished\":\"2013-05-21T12:54:29-07:00\",\"dateModified\":\"2026-07-02T01:41:28-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Yet Another FileSteal Variant Found Today<\/title>\n\n","aioseo_head_json":{"title":"Yet Another FileSteal Variant Found Today","description":"As we predicted in our previous post on OSX\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A. The server used by this variant is at: liveapple.eu\/MEny\/upload.php At","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#blogposting","name":"Yet Another FileSteal Variant Found Today","headline":"Yet Another FileSteal Variant Found Today","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","width":400,"height":260},"datePublished":"2013-05-21T12:54:29-07:00","dateModified":"2026-07-02T01:41:28-07:00","inLanguage":"en-US","commentCount":2,"mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#webpage"},"articleSection":"Malware, Security News, Christmas_Card.app, Malware, OSX\/FileSteal, lysam"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","position":2,"name":"Security News","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#listItem","name":"Yet Another FileSteal Variant Found Today"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#listItem","position":3,"name":"Yet Another FileSteal Variant Found Today","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/a244278f35cc41c7ec676b36673dee0464ed8c7ceafb1ff484fdf13a916d126c?s=96&d=mm&r=g","width":96,"height":96,"caption":"Lysa Myers"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/","name":"Yet Another FileSteal Variant Found Today","description":"As we predicted in our previous post on OSX\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A. The server used by this variant is at: liveapple.eu\/MEny\/upload.php At","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#mainImage","width":400,"height":260},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/#mainImage"},"datePublished":"2013-05-21T12:54:29-07:00","dateModified":"2026-07-02T01:41:28-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"Yet Another FileSteal Variant Found Today","og:description":"As we predicted in our previous post on OSX\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A. The server used by this variant is at: liveapple.eu\/MEny\/upload.php At","og:url":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/","article:published_time":"2013-05-21T19:54:29+00:00","article:modified_time":"2026-07-02T08:41:28+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"Yet Another FileSteal Variant Found Today","twitter:description":"As we predicted in our previous post on OSX\/Filesteal, a new sample of FileSteal has been found. It was found on VirusTotal earlier today, though the sample seems to have been created in December of 2012. It is already detected by VirusBarrier as a OSX\/FileSteal.A. The server used by this variant is at: liveapple.eu\/MEny\/upload.php At","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"14485","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-08-31 04:29:19","created":"2026-08-31 04:29:19","updated":"2026-09-04 13:02:49","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/\" title=\"Security News\">Security News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tYet Another FileSteal Variant Found Today\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Security News","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/"},{"label":"Yet Another FileSteal Variant Found Today","link":"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/14485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=14485"}],"version-history":[{"count":9,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/14485\/revisions"}],"predecessor-version":[{"id":105421,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/14485\/revisions\/105421"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8755"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=14485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=14485"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=14485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}