Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

cosmichobo

macrumors 65816
Original poster
May 4, 2006
1,002
637
G'day,

Long story short
Are there any viruses that can make Apple's Mail app send out emails to people randomly, with attachments?
(iMac 2009 running Mavericks; yes I know it needs updating...)

Short story long
About a month ago a handful of people received an email "from" my father, containing an attachment that may or may not have been "bad". (No one opened it as far as we know to verify.)

The text within the email itself had originally legitimately been sent by my father from his iMac about 3-4 years earlier to a list of people. (And would almost certainly have since been deleted from his iMac, as my father doesn't believe in keeping emails more than about a month.)

The email was then re-sent as noted above (I suspect to the list of original recipients from what my father can tell), BUT, whilst the email says it is from him, the actual email address shown was "guaitajavier@speedy.com.ar" (which appears to be some kind of mild celebrity somewhere).

I personally don't believe it came from his iMac at all - I suspect it was one of the recipient's computers that has been attacked, and my father's email used on that machine.

As I'm 4 hrs away, and due to COVID, he ended up getting a former cop friend to come and check it out, and he convinced my dad that he definitely had had a virus.

Now, he's just received another email from someone telling him they received another of these emails. Again, it says my father's name, but the email address is same as above. Instead of an attachment this time it has a link to some "entertainment" website.

I've heard of "zombie" email viruses that use your computer to send out heaps of emails to people in your directory, but - is that only a PC thing, or Mac too?

Cheers

cosmic
 
Last edited:
Instead of an attachment this time it has a link to some "entertainment" website.
Looks as if he has been hacked. Have you changed the password on his mail account? Is it a very strong one?

I personally don't believe it came from his iMac at all - I suspect it was one of the recipient's computers that has been attacked, and my father's email used on that machine.

Can the other party send you the raw headers? (View/Message/Raw Source on Mohave Mac). That should tell you where the message originated.
 
Yes - changed his email password to something strong back when first became aware.

I've tried to get him to contact some of the people and get the long/raw headers, but I think he's thinking no one is going to know how to actually do that... (He's an old fart, emailing lots of other old farts...) I have asked him again to do this though, as it would certainly give some answers.

This is the short header from the forwarded email:

From: Mydads Name <guaitajavier@speedy.com.ar>
Date: Sat, Dec 12, 2020 at 3:10 AM
Subject: FWD: for Mydads Name
To: [person who notified myDad]

That's why I don't think it's necessarily anything to do with his computer.

To me, that header isn't saying it originated from my father's email. I realise that it doesn't mean it didn't either...
 
Last edited:
The way the Email protocol works is that everyone can send an email with the sender name they want. Someone doesn't need a virus to send an email with your name.
 
Yes - I tried to show that to my dad by sending him an email from my own computer, with his name on it.
 
Now, he's just received another email from someone telling him they received another of these emails. Again, it says my father's name, but the email address is same as above. Instead of an attachment this time it has a link to some "entertainment" website.

I've had plenty of those, usually the link is to some bit.ly type eaddress and the sender "appears" to be somebody you know but with a different address than their own.

It means that their machine, most likely a PC running Windows, has been infected with a Trojan that harvests all their contacts.

I report all such crap to https://www.spamcop.net/

Sign up for free, if you can be bothered.
 
Completely to the side of the above... Spotlight just showed me an email when I was looking for something, and I noticed my amazing signature circa 2009:

--
This is an email virus for Mac OS X.
It works on the honor system.
Please start deleting random files on your system and forward this message to everyone in your address book.


--
I doubt I was clever enough to think of it myself... but I love it all the same. :)
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.