"BadGacha" warning on my Mac mini

XProtect has been giving me 3 warnings a day saying:


BadGacha ⚠️ FailedToRemediate time 0.0001501 {"caused_by":[],"status_message":"FailedToRemediate","status_code":24,"execution_duration":0.00015008449554443359}


This just began a little over 24 hours ago. Is this a serious issue or is it some result of the the Rapid Security Response that was recently installed? I'm using a Mac Mini M1, 8GB, with the latest Ventura and the Rapid Security Response installed as well.


[Re-titled by Moderator]

Mac mini, macOS 13.3

Posted on May 4, 2023 4:38 PM

Reply
Question marked as Top-ranking reply

Posted on Jan 31, 2024 8:26 AM

For clarification, XProtect does not display any messages like this. It has virtually no user interface. The user interface it does have is infuriating, and more disruptive to the user experience than any malware. I know this makes no sense, but that's the way the world works.


All of these reports about "BadGacha" are from people using a certain app written by a social media influencer. This app takes low-level log reports, that no one should ever, ever look at, and displays them.


If Apple had a reason to report any kind of "BadGacha" virus, then there would be a dialog pop-up telling you. You wouldn't be able to dismiss the dialog and you wouldn't be able to use your computer. Your only solution would be to erase the hard drive and install the latest version of macOS Sonoma. Because this isn't happening, these reports are, therefore, false.

32 replies
Question marked as Top-ranking reply

Jan 31, 2024 8:26 AM in response to Artiste212

For clarification, XProtect does not display any messages like this. It has virtually no user interface. The user interface it does have is infuriating, and more disruptive to the user experience than any malware. I know this makes no sense, but that's the way the world works.


All of these reports about "BadGacha" are from people using a certain app written by a social media influencer. This app takes low-level log reports, that no one should ever, ever look at, and displays them.


If Apple had a reason to report any kind of "BadGacha" virus, then there would be a dialog pop-up telling you. You wouldn't be able to dismiss the dialog and you wouldn't be able to use your computer. Your only solution would be to erase the hard drive and install the latest version of macOS Sonoma. Because this isn't happening, these reports are, therefore, false.

Apr 8, 2024 11:33 AM in response to luckman212

Take it up with the social media influencer who released your "XProCheck" app.


Those are all internal status messages. You aren't supposed to be looking at them at all.


For example, XProtect has several modules to look for several different types of infections. Each specific type of infection has specific characteristics. For any infection to be "found", it would have to trip some minimum threshold of events. There are always legitimate, but incompetent, developers who regularly do something wrong and trip one event or another. There needs to be multiple matches before doing something.


But when logging runtime behaviour, each module is going to report all events, under its own identifier. Unfortunately, Apple didn't obfuscate those identifiers as it should have. This leads social media influencers and "internet security researchers" to write apps and blog posts to scare people.


When I added antivirus detection to my own app, I made the exact same error that Apple did, with similar results. Years later, that one mistake is still used to libel and defame me. There's nothing to see here.

Jan 31, 2024 8:54 AM in response to rgev1973

AppleStar wrote:

If you are who I think you are then congratulations for EtreCheck which I am using regularly.

Thanks!

About my request: I am someone rather technical and I do spend some time analyzing what my devices are doing - as I do with some servers I run. So I am still curious why Apple is logging something as somehow relevant if it is not ;)

I can't explain Apple's Console.app or its new Unified Logging system. I find it completely unusable. It logs unbelievably massive amounts of nonsense. While at the same time, it redacts much of that information, making it even more useless.


I understand that what I'm saying makes no sense. Why would Apple be logging so massive quantities of repetitive gibberish, making a point to remove any information that might possibly be useful? It makes no sense. I don't know why.


I have never seen any instance where anyone has ever obtained any useful information from Console. Yes. It's that bad. I have seen many cases where people have stared at that never ending stream of techno-babble, lost touch with reality, and became convinced that hackers had taken control over their lives.


This is nothing but yet another piece of evidence. It's logging that it has found a "BadGacha" virus. This is false. It is reporting false information. That alone should be enough to do an immediate File > Quit.


My best guess is that this is the baby of some powerful, well-connected person high-up in Apple's software engineering team. They've been pushing it relentlessly and it is a Career Limiting Move for anyone to resist. The new version of Xcode now routes debugging messages through it, helpfully deleting them if your debug code logs too much data. (Note: when writing complex, asynchronous code like the kind Apple now demands, logging copious amounts of data is the only way to debug it. And Apple broke that.)

NB: You would consider Howard Oakley a social media influencer?

You wouldn't? By what criteria is he not?

May 5, 2023 7:43 AM in response to Artiste212

Then have a few suggestions ;


1 - Get Support Choose a product and we’ll find you the best solution.Start now and open an Apple Support Ticket as they are Apple Employees to deal will these types of issues . 


2 - Product Feedback - Apple and make it known to Apple regarding this ongoing issue 


Actually, is this is malware ir would only effect the User Account and Not the Operating System itself


In macOS 11 Big Sur, macOS 12 Monterey and macOS 13 Ventura. 


The Operating System resides in a Sealed and Read Only Volume that can not be opened by the User nor by Third Party Applications.


The only Entity that can open and modify or alter this Volume is Apple.


That would occur when a update or UpGrade is performed.


The Built in Security


Should “ Certain & Specific Software “ referenced from above be installed - it will negatively impact macOS. It is suggested, download directly from the Developer , the application Malwarebytes for Mac


It is free or paid for added features. 

Feb 27, 2024 6:46 AM in response to mauvedeity

Seems to me that XProtect mistakenly thing that Teams is infected with BadGacha, my log entry are:

2024-02-26 22:34:55.778 BadGacha 👉 no status_message report time 0.0000000 {"action":"report","process":{"pid":786,"name":"Microsoft Teams Launcher"},"status":null}

2024-02-26 22:34:55.781 BadGacha ⚠️ ThreatDetected time 0.0000319 {"execution_duration":3.1948089599609375e-05,"status_message":"ThreatDetected","status_code":21,"caused_by":[]}

Three times in the last day?

Apr 22, 2024 7:23 PM in response to Frederick Karayan

Frederick Karayan wrote:

Could you please provide evidence, data, a press release, a license agreement, or any other data in support of your remark that "no one should ever, ever look at" low-level log reports?

Apple doesn't publish that kind of information, let alone press releases, on low-level system topics. There is no harm in looking at the data, provided one is both honest and mentally stable. Tech support scammers often use Console log messages to convince people that they've been infected by malware. Here in the forums, the biggest problem is people looking at that never-ending list of scary-sounding messages on their own and losing all touch with reality.


We've all seen Apple's promotion and marketing materials. Those focus on more uplifting and empowering messages. They don't show people getting scammed or people struggling with a buggy computer caused by 3rd party antivirus.


The closest you are ever going to find to this kind of information is on the Developer forums. There, Apple engineers refer to these messages as "Log Noise". This all started when Apple introduced the new Unified Logging system that logs any and all messages from all Apple apps.


These messages only have meaning to the Apple developers who coded them. If Apple wants users to know something, they have the means and the capacity to tell them directly. They're happy to do that. Nobody other than that specific Apple developer who wrote XProtectRemediator has any knowledge of what any console log messages actually mean.

Jan 19, 2024 2:44 PM in response to Artiste212

I have the same warning, but mine includes references to 1Password. I have informed them. I can't recall what I was doing so it may not be much help.


I suspect it's a false alarm.


2024-01-18 18:01:33.285  BadGacha      👉 no status_message report     time 0.0000000 {"process":{"name":"1Password-Crash-Handler","pid":844},"status":null,"action":"report"}


2024-01-18 18:01:33.289  BadGacha      ⚠️ ThreatDetected time 0.0000380 {"caused_by":[],"execution_duration":3.802776336669922e-05,"status_code":21,"status_message":"ThreatDetected"}

May 5, 2023 7:37 AM in response to MrHoffman

Thanks. I actually found this by running Howard's Silent Knight, and seeing a warning about this. I then ran his XProCheck app to download the log info from XProtect.


The real issue is that as XProtect fails to remediate this issue, I'm not sure what this means. Apple hasn't revealed what this malware is or does, and I'm concerned about just ignoring the warnings. I suppose I need to find out how to reach Apple Support somehow, but I don't know exactly how to find them.

Jan 31, 2024 8:07 AM in response to Artiste212

any update on this?



See here:


2024-01-31 10:58:06.154 BadGacha 👉 no status_message report time 0.0000000 {"process":{"pid":2001,"name":"1Password-Crash-Handler"},"status":null,"action":"report"}

2024-01-31 10:58:08.464 BadGacha ⚠️ ThreatDetected time 0.0000371 {"status_message":"ThreatDetected","execution_duration":3.707408905029297e-05,"caused_by":[],"status_code":21}

Jan 31, 2024 8:36 AM in response to etresoft

If you are who I think you are then congratulations for EtreCheck which I am using regularly.


About my request: I am someone rather technical and I do spend some time analyzing what my devices are doing - as I do with some servers I run. So I am still curious why Apple is logging something as somehow relevant if it is not ;)


NB: You would consider Howard Oakley a social media influencer?

Jan 31, 2024 8:57 AM in response to tmg2010

tmg2010 wrote:

They are snippets from the system log captured by Howard Oakley's XProCheck app.

Yes. I know. 😄

Please explain "No one should ever look at"? Apple provides the Console app precisely to look at logs.

Please see my previous reply. I realize that Apple provides the app. But it's a horrible app. The entire system is just awful. In theory, it was designed exclusively for developers and should only be used by developers. No one else knows what the individual log messages mean, if anything. No one should ever look at the Apple logs because only Apple engineers know what they mean, and they never say anything. But, as a developer, I can tell you this system is totally useless. I would never, ever use it for my own apps. No way. Never.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

"BadGacha" warning on my Mac mini

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.