Possible Phishing Expedition?
Does anyone know why I might be getting constant requests to download a font on Safari and Textedit, alternately? Attached are the pop-ups.
MacBook
Does anyone know why I might be getting constant requests to download a font on Safari and Textedit, alternately? Attached are the pop-ups.
MacBook
PST-Art wrote:
The font is "Nanum Gothic"
That's a font for Korean script. Do you do any Korean reading or writing?
It's provided by Apple for downloading in Mojave. See this page
https://support.apple.com/en-us/HT208968
You are welcome. Try setting up another admin user account in System Preferences/Users & Groups to see if the same problem continues. Please post back on whether or not this worked. Also try the Safe Mode. Please post back on whether or not this worked.
Isolating an issue by using another user account
Safe Mode - About
If it works in the Safe Mode, try running this program when booted normally and then copy and paste the output in a reply. The program was created by Etresoft, a frequent contributor. Please use copy and paste as screen shots can be hard to read. Click “Share Report” button in the toolbar, select “Copy to Clipboard” and then paste into a reply. This will show what is running on your computer. No personal information is shown. If the log won’t post, try posting it in Pastebin and provide a link in a reply. After pasting the report in a PasteBin page, go to the top of the page, and copy the address in the URL bar. Paste that in a new reply. Pastebin
You didn't attach the screen shots. What font is it requesting you to download?
To attach screen shots, click the button shown below.
PST-Art wrote:
if the fonts download with the Mojave OS, wouldn't it simply upload automatically at the same time as my computer installed the new Mojave OS?
No, I think there are a bunch of fonts you have to download manually via Font Book if you want/need them.
Eric -
I have tried to attach the screenshots of the two pop-ups but somehow I cannot get them to register. The link just asks for a "valid URL." So I am describing: the images looks like pretty standard Apple pop-ups that might appear from any application. It says, "Safari needs to download the font 'Nanum Gothic'; then on the next line, "'Nanum Gothic' is 7.2 MB' and is accompanied by the small familiar corresponding "Safari" and "Textedit" icons to the left of the text.
Frankly, if the period came before the end quote at the end of the line instead of after it, perhaps I would not even have questioned it. But I find that one of the easiest clues that allow me to identify malware is incorrect English usage.
Can you tell from my description (or do you know) if this kind of thing is a malware issue or is it something that is not uncommon when one adds outside (from Apple) applications? I just added Photoshop and the Microsoft Word series the day before the pop-ups appeared. If it is coming from applications and it is not phishing or some other kind of hack, maybe all I need is to select the "Skip" choice. Any thoughts on this?
If it is the more serious issue, this series of checks will require a bit more time than I have tonight as I am not quickly familiar with the execution of most of them, but I will check in again as soon as I can try them all. Thank you so much, again, for your help and, as I said, I will employ your suggestions as soon as I can.
Tom Gewecke - Thank you for your help: I don't do any Korean reading or writing, but I did just upload a new Mojave OS. However, if the fonts download with the Mojave OS, wouldn't it simply upload automatically at the same time as my computer installed the new Mojave OS?
Thank you for your continual input on this. Attached, now, are the pop-ups. For some reason they appear quite large in these attachments. On my screen they appear much smaller - about 4-1/2" across and about a 1-1/2" inches high.
The font is "Nanum Gothic" and the request came first from Safari, then Textedit, then Safari again. Thank you for trying to help me!
PS Here is an example of how Apple provides Nanum for optional download:
Possible Phishing Expedition?