Apple has pushed two updates today, to the data files used by XProtect, bringing its version number to 2111, dated 7 January 2020, and to its malware removal tool MRT, bringing it to version 1.52, also dated 7 January 2020.
Apple doesn’t release information about what these updates add or change, and now obscures the identities of malware detected by XProtect using internal code names. Comparing the previous version of XProtect’s data files with these, three rules have been added to detect “MACOS_5af1486”, “MACOS_03b5cbe” and “MACOS_ce3281e”. Changes have also been made to the signatures of “MACOS_9bdf6ec” and “MACOS_e79dc35”. I’m sure we’ll all sleep easier in our beds tonight in the light of those.
You can check whether this update has been installed by opening System Information via About This Mac, and selecting the Installations item under Software.
A full listing of security data file versions is given by SilentKnight, LockRattler and SystHist for El Capitan, Sierra, High Sierra, Mojave and Catalina, available from their product page. If your Mac has not yet installed this update, you can force an update using SilentKnight, LockRattler, or at the command line.
I have updated the reference pages here which are accessed directly from LockRattler 4.2 and later using its Check blog button.