

One way to find out whether you’ve downloaded the Trojan is to look for an “activity_agent” process in the macOS by accessing the Activity Monitor application.

This malicious file managed to trick Apple’s security approval system into deeming it as safe and legitimate. Infected downloads came from the mirror site,, where the installer file (HandBrake-1.0.7.dmg) was swapped with a Trojan file, OSX.PROTON. HandBrake can be downloaded from its official website and via mirror sites, or sites that provide the same content as the primary site. If you’re not sure whether your device has been infected, read on. From May 2-6, a Trojan was attached to downloads of the macOS version of HandBreak, a free, cross-platform video transcoding software that processes multimedia files and other digital sources such as DVD and BluRay into.
