How a Well-Regarded Mac App Became a Trojan Horse
Short Summary
The macOS app called NightOwl, originally designed to provide a night mode feature for Macs, has turned into a malicious tool that collects users' data and operates as part of a botnet. Originally well-regarded for its utility, NightOwl was bought by another company, and a recent update introduced hidden functionalities that redirected users' data through a network of affected computers. Web developer Taylor Robinson discovered that the app was running a local HTTP proxy without users' knowledge or consent, collecting users' IP addresses and sending the data to third parties. The app's certificate has been revoked, and it is no longer accessible. The incident highlights the risks associated with third-party apps that may have malicious intentions after updates or ownership changes.
Longer Summary
The NightOwl app was developed by Keeping Tempo, an LLC that went inactive earlier this year. The app was recently found to have been turned into a botnet by the new owners, TPE-FYI, LLC. The original developer, Michael Kramser, claims that he was unaware of the changes to the app and that he sold the company last year due to time constraints.
Gizmodo was unable to reach TPE-FYI, LLC for comment. However, the internet sleuth who discovered the botnet, Will Robinson, said that it is not uncommon for shady companies to buy apps and then monetize them by integrating third-party SDKs that harvest user data.
Robinson also said that it is understandable why developers might sell their apps, even if it means sacrificing their morals. App development is both hard and expensive, and for individual creators, it can be tempting to take the money and run.
This is not the first time that a popular app has been turned into a botnet. In 2013, the Brightest Flashlight app was sued by the Federal Trade Commission after allegedly transmitting users' location data and device info to third parties. The developer eventually settled with the FTC for an undisclosed amount.
In 2017, software developers discovered that the Stylish browser extension started recording all of its users' website visits after the app was bought by SimilarWeb. Another extension, The Great Suspender, was flagged as malware after it was sold to an unknown group back in 2020.
All of these apps had millions of users before anyone recognized the signs of intrusion. In these cases, the new app owners' shady efforts were all to support a more-intrusive version of harvesting data, which can be sold to third parties for an effort-free, morals-free payday.
Possible Takeaways
-
Minimize the software you use
-
Keep track of ownership changes
-
Use software from only the most reputable sources
-
Regularly review installed apps
-
Be suspicious about app's unexpected behaviors and permissions
Agreed. But FOSS apps for Lemmy exist, use one of those!
I do, but I have no computer science knowledge. I have no way of checking anything and have to rely on others to make sure the developer is trustworthy. I know there are people doing this, but it’s on their own time, they’re volunteering their effort. They may not be monitoring the specific app I’m using, or maybe they’ll be tired from work and won’t check the most recent update until it’s too late and a lot of people installed malware.
Maybe I’m completely wrong about this, like I said this is not my field.
Well, yes, but the reality is that the crowd-sourced aspect of it is what protects you. But you're right, there's always an element of risk!