{"id":7617,"date":"2012-11-30T10:00:49","date_gmt":"2012-11-30T18:00:49","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=7617"},"modified":"2026-07-04T02:20:05","modified_gmt":"2026-07-04T09:20:05","slug":"new-mac-spyware-discovered-osxdockster-a","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/","title":{"rendered":"New Mac Spyware Discovered &#8211; OSX\/Dockster.A"},"content":{"rendered":"<p><strong>Update: December 3, 2012<\/strong><\/p>\n<p>This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The <a href=\"https:\/\/www.intego.com\/mac-security-blog\/osxdockster-found-on-tibetan-website\/\">exploit code used to drop the backdoor<\/a> is the same as that used by SabPab. This is still considered to be low-risk as this is not known to be widespread and the vulnerability targeted by the exploit code is corrected by the latest version of Java.<\/p>\n<hr \/>\n<p>A sample of a new Mac spyware called OSX\/Dockster.A\u00a0was found today on VirusTotal. This trojan is currently considered low risk as it is not known to have infected users. It has backdoor functionality, including a keylogger component that records an affected user&#8217;s typing.<\/p>\n<p>If it&#8217;s executed, the trojan deletes itself from the location where it was run and installs itself in the user&#8217;s home directory with the filename <strong>.Dockset<\/strong>. The file is not visible through Finder; however, if it&#8217;s running, it can be seen within OS X&#8217;s Activity Monitor.\u00a0 It creates a launch agent called <strong>mac.Dockset.deman<\/strong> so that the trojan will restart each time an affected user logs in. Once the trojan is active, it tries to contact the remote address <strong>itsec.eicp.net<\/strong> to await instructions. At the time of writing, this address is not registered, which indicates the sample may be intended simply as a test rather than an active threat.<\/p>\n<p align=\"center\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-7635\" title=\"Dockset\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/11\/Dockset.png\" alt=\"\" width=\"624\" height=\"120\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/11\/Dockset.png 780w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/11\/Dockset-150x28.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/11\/Dockset-300x57.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/11\/Dockset-100x19.png 100w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/p>\n<p>The backdoor functionality of this trojan is quite basic &#8211; it provides a simple remote shell which allows the trojan&#8217;s controller remote access, it allows the controller to download additional files, and it logs keystrokes.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/products\">Intego VirusBarrier<\/a> users with up-to-date virus definitions are protected from this threat, which is detected as OSX\/Dockster.A.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8763,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[190],"tags":[174,86,168,2776,125,2773],"class_list":["post-7617","post","type-post","status-publish","format-standard","has-post-thumbnail","category-malware","tag-mac","tag-mac-malware","tag-os-x","tag-osxdockster-a","tag-spyware","tag-tibetan"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Lysa Myers\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"New Mac Spyware Discovered \u2013 OSX\/Dockster.A\" \/>\n\t\t<meta property=\"og:description\" content=\"Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2012-11-30T18:00:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-04T09:20:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"New Mac Spyware Discovered \u2013 OSX\/Dockster.A\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#blogposting\",\"name\":\"New Mac Spyware Discovered \\u2013 OSX\\\/Dockster.A\",\"headline\":\"New Mac Spyware Discovered &#8211; OSX\\\/Dockster.A\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert-intego.jpg\",\"width\":400,\"height\":260,\"caption\":\"Malware Alert from Intego\"},\"datePublished\":\"2012-11-30T10:00:49-08:00\",\"dateModified\":\"2026-07-04T02:20:05-07:00\",\"inLanguage\":\"en-US\",\"commentCount\":1,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#webpage\"},\"articleSection\":\"Malware, Mac, Malware, OS X, OSX\\\/Dockster.A, Spyware, Tibetan, lysam\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"name\":\"Malware\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"position\":2,\"name\":\"Malware\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#listItem\",\"name\":\"New Mac Spyware Discovered &#8211; OSX\\\/Dockster.A\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#listItem\",\"position\":3,\"name\":\"New Mac Spyware Discovered &#8211; OSX\\\/Dockster.A\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"name\":\"Malware\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a244278f35cc41c7ec676b36673dee0464ed8c7ceafb1ff484fdf13a916d126c?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Lysa Myers\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/\",\"name\":\"New Mac Spyware Discovered \\u2013 OSX\\\/Dockster.A\",\"description\":\"Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/lysam\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert-intego.jpg\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#mainImage\",\"width\":400,\"height\":260,\"caption\":\"Malware Alert from Intego\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/new-mac-spyware-discovered-osxdockster-a\\\/#mainImage\"},\"datePublished\":\"2012-11-30T10:00:49-08:00\",\"dateModified\":\"2026-07-04T02:20:05-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>New Mac Spyware Discovered \u2013 OSX\/Dockster.A<\/title>\n\n","aioseo_head_json":{"title":"New Mac Spyware Discovered \u2013 OSX\/Dockster.A","description":"Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#blogposting","name":"New Mac Spyware Discovered \u2013 OSX\/Dockster.A","headline":"New Mac Spyware Discovered &#8211; OSX\/Dockster.A","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","width":400,"height":260,"caption":"Malware Alert from Intego"},"datePublished":"2012-11-30T10:00:49-08:00","dateModified":"2026-07-04T02:20:05-07:00","inLanguage":"en-US","commentCount":1,"mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#webpage"},"articleSection":"Malware, Mac, Malware, OS X, OSX\/Dockster.A, Spyware, Tibetan, lysam"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","name":"Malware"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","position":2,"name":"Malware","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#listItem","name":"New Mac Spyware Discovered &#8211; OSX\/Dockster.A"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#listItem","position":3,"name":"New Mac Spyware Discovered &#8211; OSX\/Dockster.A","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","name":"Malware"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/a244278f35cc41c7ec676b36673dee0464ed8c7ceafb1ff484fdf13a916d126c?s=96&d=mm&r=g","width":96,"height":96,"caption":"Lysa Myers"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/","name":"New Mac Spyware Discovered \u2013 OSX\/Dockster.A","description":"Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#mainImage","width":400,"height":260,"caption":"Malware Alert from Intego"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/#mainImage"},"datePublished":"2012-11-30T10:00:49-08:00","dateModified":"2026-07-04T02:20:05-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"New Mac Spyware Discovered \u2013 OSX\/Dockster.A","og:description":"Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be","og:url":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/","article:published_time":"2012-11-30T18:00:49+00:00","article:modified_time":"2026-07-04T09:20:05+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"New Mac Spyware Discovered \u2013 OSX\/Dockster.A","twitter:description":"Update: December 3, 2012 This malware is now known to be in the wild, on a website dedicated to the Dalai Lama, and the remote address contacted by the backdoor is now active. The exploit code used to drop the backdoor is the same as that used by SabPab. This is still considered to be","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":[],"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\" title=\"Malware\">Malware<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tNew Mac Spyware Discovered \u2013 OSX\/Dockster.A\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Malware","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/"},{"label":"New Mac Spyware Discovered &#8211; OSX\/Dockster.A","link":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-spyware-discovered-osxdockster-a\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/7617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=7617"}],"version-history":[{"count":18,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/7617\/revisions"}],"predecessor-version":[{"id":105858,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/7617\/revisions\/105858"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8763"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=7617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=7617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=7617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}