{"id":16017,"date":"2013-07-16T12:42:24","date_gmt":"2013-07-16T19:42:24","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=16017"},"modified":"2026-07-01T13:51:26","modified_gmt":"2026-07-01T20:51:26","slug":"new-mac-malware-janicab-uses-old-trick-to-hide","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/","title":{"rendered":"New Mac Malware Janicab Uses Old Trick To Hide"},"content":{"rendered":"<p style=\"text-align: center;\"><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/virus-free.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-12341\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/virus-free.jpg\" alt=\"Mac malware Janicab\" width=\"500\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/virus-free.jpg 500w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/virus-free-150x90.jpg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/virus-free-300x180.jpg 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<p>A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent <a href=\"https:\/\/www.intego.com\/mac-security-blog\/yet-another-filesteal-variant-found-today\/\" target=\"_blank\">FileSteal.B<\/a>, the file is signed with an Apple ID so that it can bypass the middle level of <a href=\"https:\/\/www.intego.com\/mac-security-blog\/do-os-xs-built-in-security-features-offer-good-enough-protection\/\" target=\"_blank\">Gatekeeper security<\/a>.<\/p>\n<p>The trick the malware uses to hide its true extension relies on a special character that\u2019s designed to assist with transmitting information, regardless of what language is being used. Specifically, whether the language is read from right-to-left or left-to-right. This feature does cause some very strange behavior in various programs, as it may not be handled properly in all cases.<\/p>\n<p>For instance, while the right-to-left override could trick a user in the Downloads folder, it won&#8217;t do so in the Desktop folder.\u00a0Amazingly, the right-to-left override also alters the Quarantine warning dialog, such that the text is reversed.<\/p>\n<p>If the user accepts this very strange-looking quarantine warning, it runs a Python script that performs the following actions:<\/p>\n<ul>\n<li>It opens the &#8220;dummy&#8221; PDF file to show a Russian PDF with news extracted from a website.<\/li>\n<li>It creates an invisible folder named &#8220;.t&#8221; in current user home folder<\/li>\n<li>It copies files from the application to this new folder<\/li>\n<li>It appends a job to the current user crontab to execute the copied files every minute.<\/li>\n<\/ul>\n<p>Usually, droppers would self-destruct, but this one does not. It remains after being executed.<\/p>\n<p>Intego will have a more thorough analysis of this malware soon. Until then, <a href=\"https:\/\/www.intego.com\/features\/virus-scanner\">Intego VirusBarrier<\/a>\u00a0with up-to-date virus definitions will protect Mac users against this threat, detecting it as OSX\/Janicab.A. This is considered to be a low-risk threat at this time as it&#8217;s not known to be affecting users, and its strange appearance would likely dissuade people from bypassing quarantine to let it run. This appears to be only one variant of many, so this may not be the last time we see this malware family.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[190,5],"tags":[529,174,86,168,531,125],"class_list":["post-16017","post","type-post","status-publish","format-standard","has-post-thumbnail","category-malware","category-security-news","tag-janicab","tag-mac","tag-mac-malware","tag-os-x","tag-osxjanicab-a","tag-spyware"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Lysa Myers\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"New Mac Malware Janicab Uses Old Trick To Hide\" \/>\n\t\t<meta property=\"og:description\" content=\"A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2013-07-16T19:42:24+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-01T20:51:26+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"New Mac Malware Janicab Uses Old Trick To Hide\" \/>\n\t\t<meta name=\"twitter:description\" content=\"A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#blogposting\",\"name\":\"New Mac Malware Janicab Uses Old Trick To Hide\",\"headline\":\"New Mac Malware Janicab Uses Old Trick To Hide\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert.png\",\"width\":400,\"height\":260},\"datePublished\":\"2013-07-16T12:42:24-07:00\",\"dateModified\":\"2026-07-01T13:51:26-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#webpage\"},\"articleSection\":\"Malware, Security News, Janicab, Mac, Malware, OS X, OSX\\\/Janicab.A, Spyware, lysam\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"position\":2,\"name\":\"Security News\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#listItem\",\"name\":\"New Mac Malware Janicab Uses Old Trick To Hide\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#listItem\",\"position\":3,\"name\":\"New Mac Malware Janicab Uses Old Trick To Hide\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a244278f35cc41c7ec676b36673dee0464ed8c7ceafb1ff484fdf13a916d126c?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Lysa Myers\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/\",\"name\":\"New Mac Malware Janicab Uses Old Trick To Hide\",\"description\":\"A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#mainImage\",\"width\":400,\"height\":260},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-malware-janicab-uses-old-trick-to-hide\\\/#mainImage\"},\"datePublished\":\"2013-07-16T12:42:24-07:00\",\"dateModified\":\"2026-07-01T13:51:26-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>New Mac Malware Janicab Uses Old Trick To Hide<\/title>\n\n","aioseo_head_json":{"title":"New Mac Malware Janicab Uses Old Trick To Hide","description":"A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#blogposting","name":"New Mac Malware Janicab Uses Old Trick To Hide","headline":"New Mac Malware Janicab Uses Old Trick To Hide","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","width":400,"height":260},"datePublished":"2013-07-16T12:42:24-07:00","dateModified":"2026-07-01T13:51:26-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#webpage"},"articleSection":"Malware, Security News, Janicab, Mac, Malware, OS X, OSX\/Janicab.A, Spyware, lysam"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","position":2,"name":"Security News","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#listItem","name":"New Mac Malware Janicab Uses Old Trick To Hide"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#listItem","position":3,"name":"New Mac Malware Janicab Uses Old Trick To Hide","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/a244278f35cc41c7ec676b36673dee0464ed8c7ceafb1ff484fdf13a916d126c?s=96&d=mm&r=g","width":96,"height":96,"caption":"Lysa Myers"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/","name":"New Mac Malware Janicab Uses Old Trick To Hide","description":"A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#mainImage","width":400,"height":260},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/#mainImage"},"datePublished":"2013-07-16T12:42:24-07:00","dateModified":"2026-07-01T13:51:26-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"New Mac Malware Janicab Uses Old Trick To Hide","og:description":"A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed","og:url":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/","article:published_time":"2013-07-16T19:42:24+00:00","article:modified_time":"2026-07-01T20:51:26+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"New Mac Malware Janicab Uses Old Trick To Hide","twitter:description":"A new threat has been discovered on VirusTotal which affects OS X, acting as spyware on affected systems. It uses an old trick that reverses the direction of text in order to hide its true file-extension and appear as a PDF file rather than an APP file. Like the recent FileSteal.B, the file is signed","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"16017","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-09-03 16:14:07","created":"2026-09-03 16:14:07","updated":"2026-09-04 13:08:52","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/\" title=\"Security News\">Security News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tNew Mac Malware Janicab Uses Old Trick To Hide\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Security News","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/"},{"label":"New Mac Malware Janicab Uses Old Trick To Hide","link":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-malware-janicab-uses-old-trick-to-hide\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/16017","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=16017"}],"version-history":[{"count":22,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/16017\/revisions"}],"predecessor-version":[{"id":105316,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/16017\/revisions\/105316"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8755"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=16017"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=16017"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=16017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}