Apple Updates OS X Anti-Malware Definitions to Block 'Yontoo' Adware - MacRumors
Skip to Content

Apple Updates OS X Anti-Malware Definitions to Block 'Yontoo' Adware

Yesterday, word surfaced of new malware targeting major browsers on the Mac platform with adware capable of injecting advertising into users' browsing experiences. The malware, known as "Yontoo", masquerades as a video plug-in or download accelerator in order to trick users into installing the package.

yontoo_xprotect
As noted by security firm Intego, Apple has already updated its "Xprotect" anti-malware system to recognize Yontoo and warn users who attempt to install it on their machines.

Apple has decided the Yontoo Adware has fallen too far on the side of undesirable behavior, as they have released an update to the XProtect.plist definitions file to provide Mac OS X with basic detection for the Yontoo adware as OSX.AdPlugin.i. In testing, it appears this detection is very specific and potentially location-dependent. This extra specificity is likely there so as to catch only the surreptitious installations of this file.

Apple routinely uses its Xprotect anti-malware tools introduced in OS X Snow Leopard to provide rudimentary protection against threats, and has expanded its efforts in OS X Mountain Lion with the introduction of Gatekeeper to allow users to restrict app installation to software from identified developers registered with Apple, or even to only apps installed through the Mac App Store.

Apple has also been using Xprotect to enforce minimum version requirements for plug-ins such as Java and Flash Player, forcing users to upgrade from earlier versions known to have significant security issues.

Popular Stories

iOS 26

iOS 26.5 Features: Everything New in iOS 26.5

Monday May 11, 2026 5:09 pm PDT by
Apple released iOS 26.5 after a few months of beta testing, and while it doesn't have the Siri features we were hoping for since those are being held until iOS 27, there are a handful of useful changes worth knowing about. Subscribe to the MacRumors YouTube channel for more videos. End-to-End Encryption for RCS Support for end-to-end encryption (E2EE) for RCS messages between iPhone and...
Dynamic Island iPhone 18 Pro Feature

11 Reasons to Wait for the iPhone 18 Pro

Monday May 11, 2026 9:01 am PDT by
We're only four months out from the launch of Apple's premium next-generation smartphone lineup, and while we're not expecting a sea change in terms of functionality, there are still several enhancements rumored to be coming to the iPhone 18 Pro and iPhone 18 Pro Max. One thing worth noting is that Apple is reportedly planning a major change to its iPhone release cycle this year, adopting a...
Four iPhone 18 Pro Colors Mock Feature

iPhone 18 Pro May Have 'Aggressive' Starting Price Despite RAM Crisis

Tuesday May 12, 2026 6:53 am PDT by
While the ongoing RAM chip shortage is leading some Android smartphone makers to increase prices, one analyst believes that Apple will take advantage of the situation with the upcoming iPhone 18 Pro and iPhone 18 Pro Max. In a research note with GF Securities today, analyst Jeff Pu said he expects Apple to outperform in the smartphone market by having an "aggressive pricing strategy" for the ...

Top Rated Comments

172 months ago
Great news. Though I've said it before, all software must pass through my built-in antivirus called "common sense." It's updated frequently.

So I'm not too worried.
Score: 18 Votes (Like | Disagree)
172 months ago
But what about my freedom to install adware!
Score: 10 Votes (Like | Disagree)
172 months ago
But what about my freedom to install adware!

Said no one ever.
Score: 7 Votes (Like | Disagree)
tevion5 Avatar
172 months ago
But what about my freedom to install adware!

Such freedoms should come with free laxative overdoses.
Score: 6 Votes (Like | Disagree)
Mr Fusion Avatar
172 months ago
But what about my freedom to install adware!
You joke now...

... Just wait till OS XI debuts and you'll have to wait for the jailbreak to install third-party apps. ;)
Score: 5 Votes (Like | Disagree)
172 months ago
This is a very good thing, not trying to be critical.

But isn't this a slippery slope towards 'microsoft security essentials'? For now xprotect surely uses less system resources, but I'd wager that eventually the day will come for antivirus/antimalware on osx.

Shouldn't matter much to you since you're running Windows 7...
Score: 4 Votes (Like | Disagree)