"Dodgy" FabFilter Mac installer from team GMATIC left "CoreAudio.app" on system

Discussion in 'Mac / Hackintosh' started by Vaultnaemsae, Feb 28, 2025 at 6:01 PM.

  1. Vaultnaemsae

    Vaultnaemsae Newbie

    Joined:
    Jun 28, 2017
    Messages:
    6
    Likes Received:
    0
    I was running on not much steam after a very long day and installed plugins using a re-uploaded FabFilter installer from team GMATIC It installed an unusual "CoreAudio.app" application on the system. I removed it using an app removal utility for macOS.

    The original link has since been removed from the site -- within hours.

    The release team was unfamiliar, but I didn't notice until the installer had completed.

    What kind of nastiness have I potentially exposed myself to?
     
  2.  
  3. ArticStorm

    ArticStorm Moderator Staff Member

    Joined:
    Jun 7, 2011
    Messages:
    8,040
    Likes Received:
    4,157
    Location:
    AudioSexPro
    inst coreaudio the audio engine on macOS?
     
  4. Vaultnaemsae

    Vaultnaemsae Newbie

    Joined:
    Jun 28, 2017
    Messages:
    6
    Likes Received:
    0
    No, not the audio engine. As I posted originally, it installed an iconless application called "CoreAudio.app" to my applications folder.
     
    • Interesting Interesting x 1
    • List
  5. sisyphus

    sisyphus Audiosexual

    Joined:
    Apr 29, 2014
    Messages:
    1,596
    Likes Received:
    679
    Yeah, I'm a little confused as to this myself... There is a core audio driver and whatnot... but I'm not sure what this CoreAudio.app is... or what happened... apparently there was some release deleted or removed by the moderation staff? I missed it, would love to hear more.. :)
     
  6. sisyphus

    sisyphus Audiosexual

    Joined:
    Apr 29, 2014
    Messages:
    1,596
    Likes Received:
    679
    Ah ok, I haven't seen that..., WHO released it? I would love to peak at that package if there is something sketch going on....
     
  7. Vaultnaemsae

    Vaultnaemsae Newbie

    Joined:
    Jun 28, 2017
    Messages:
    6
    Likes Received:
    0
    I archived the following .rar after the installation: "FabFilter Total Bundle 2025 MacOS U2B GMATIC"

    I do not recall seeing a GMATIC release on the site before.
     
  8. sisyphus

    sisyphus Audiosexual

    Joined:
    Apr 29, 2014
    Messages:
    1,596
    Likes Received:
    679
    Yeah, I'm not familiar with that either, and I wouldn't touch it.

    Absolutely vet the releases and teams a little before putting things on your system as you probably have already learned.. ! :)
     
  9. loveriuz

    loveriuz Producer

    Joined:
    Jan 1, 2022
    Messages:
    218
    Likes Received:
    97
    Location:
    East of Jupiter
    TCGMATIC i think their name was

    The last 2 "new" fake "teams", Oneclick and C0ndom uploaded bitcoin miners and some malware, rehashing some old V.R license as their own. Banned ASAP. As this new team...


    so conclusion:
    don't download from a "team" with 1 upload or zero comments and that was registered 1 month ago before first release, if you care about your stuff.
    Stay with the teams that are known. Or...do what you want.:dunno:
    Why it's even possible or allowed to be uploader like that before getting vetted...who knows.
     
  10. Vaultnaemsae

    Vaultnaemsae Newbie

    Joined:
    Jun 28, 2017
    Messages:
    6
    Likes Received:
    0
    Already touched! Waiting for something terrible to happen now...
     
  11. Vaultnaemsae

    Vaultnaemsae Newbie

    Joined:
    Jun 28, 2017
    Messages:
    6
    Likes Received:
    0
    Thanks for the reply but I wasn't seeking advice on how to approach the site, though it is a good reminder to all. I obviously made an error of judgment and it certainly wasn't intentional.

    What I was wondering was is if anybody had any further information on what threats I may have been exposed to and what the "CoreAudio.app" actually is...I doubt it's a good thing. And since it was removed, somebody knows something about it.
     
  12. HoMeCracKeR

    HoMeCracKeR Noisemaker

    Joined:
    Jun 6, 2013
    Messages:
    1
    Likes Received:
    3
    I took a quick look at the CoreAudio app from GMATIC that is included in our stolen release and it looks like it is a keylogger / monitoring app so I recommend anyone who has it installed to remove it immediately.

    For anyone who wants to investigate a little more closely, PM me.
     
    • Like Like x 3
    • Love it! Love it! x 1
    • List
  13. shinyzen

    shinyzen Audiosexual

    Joined:
    Sep 28, 2023
    Messages:
    883
    Likes Received:
    567
    wow! wtf. this, paired with dox-gate that happened earlier in the week is highly susupect. Is somebody attacking the community? Thanks HCiSO for the warning!
     
    Last edited: Feb 28, 2025 at 10:25 PM
  14. omiac

    omiac Moderator Staff Member

    Joined:
    May 3, 2024
    Messages:
    224
    Likes Received:
    221
    For obvious reasons I wont go into, this isn't the place to publicly distribute warez / malware, so for you guys offering any related content, whatever it may be, please only do so via PM and only with longtime trusted members of the scene and this community. TY!
     
  15. shinyzen

    shinyzen Audiosexual

    Joined:
    Sep 28, 2023
    Messages:
    883
    Likes Received:
    567
    my bad! i edited my comment to have less detail
     
  16. bigpapa23

    bigpapa23 Newbie

    Joined:
    Today
    Messages:
    1
    Likes Received:
    0
    The "virus" acts as a sort of snippet manager. If you copied & pasted crypto address that matches regex of some mainstream crypto it get's replaced instantly with the "attacker" address. If you haven't sent any crypto with the app running in the background you're safe. Just remove it from computer and login items.

    TLDR: App monitors your clipboard and if it finds crypto address it replaces it with attacker address.
     
    Last edited: Feb 28, 2025 at 11:03 PM
  17. shinyzen

    shinyzen Audiosexual

    Joined:
    Sep 28, 2023
    Messages:
    883
    Likes Received:
    567
    thats crazy. crypto is already robbing me blind in the last couple weeks, and now bad actors are trying to steal whats left of my sad portfolio :rofl:
    I didnt install it, but seesh! may the forever have bad luck!
     
Loading...
Loading...