Log in

View Full Version : New Apple Trojan(virus) Means Mac Hunting Season Is Open


iJack
June 1st, 2008, 11:01 AM
New Apple Trojan Means Mac Hunting Season Is Open
By Ryan Singel 11.01.07 | 8:30 PM

http://www.wired.com/images/article/full/2007/11/mac_trojan_500px.jpg
http://img520.imageshack.us/img520/6606/picture12qq6.png


The Mac has officially gone mainstream.

The proof? On Halloween, professional online criminals were found using Trojan-horse software to target, for the first time, computers running Apple's OS X operating system -- just as they have been doing for years on the more ubiquitous flavors of Windows.

"Apple's day has finally come, and Apple users are going to get hit hard," security researcher Gadi Evron said. "OS X is the new Windows 98."

The Trojan comes disguised as a video-decoding plug-in that users are told they must install to watch free porn clips. Instead, the software burrows into the operating system and diverts some of the victim's future web surfing to sites under the attacker's control. It's the professional attack on Macs that the security community has long predicted, according to Dave Marcus, security research manager at McAfee's Avert Lab, who said it was "written by people who know how to write malware."

The arrival of the Mac Trojan signals that cybercrooks have decided there are finally enough Apple systems on the internet to make attacking them profitable, according to security experts. Apple is the nation's No. 3 desktop and laptop seller in the United States, behind Dell and Hewlett Packard. And this year, the Cupertino company accounted for an impressive 8.1 percent of the personal-computer market for the third quarter, up nearly two percentage points from the same period a year ago. Evron and other observers predict that black hats will have a field day with Macs, as well as with Apple's new mobile platforms.

"With 2 million iPhones and iPod Touches, it makes sense they will think of them as an evolving market to exploit, and there are a lot of new Mac users who aren't as savvy as Mac's earlier users," said CEO Alex Eckelberry of Sunbelt Software, which sells security software for Windows machines.
But Carl Howe, an Apple analyst at Blackfriars Communications, disputes the security researchers' theories. He thinks that OS X's Linux heritage makes Apple systems less vulnerable to attack than Windows-based platforms. He argues that even if hacking Macs hasn't been profitable in the past, attackers would have done it anyway if they'd been able -- just for the attention.
"I think the market-share thing has always been a myth," Howe said. "It's a good story to talk about."

Announced Wednesday by Mac-focused security company Intego, the Mac Trojan was found on a set of pornography sites, where attackers dangled free movies that supposedly required users to install a special Quicktime codec to view.

The codec, however, is fake. Instead of unlocking a skin flick, it installs what Intego dubbed the OSX.RSPlug.A Trojan horse on the user's computer.
Black-hat hackers have been using fake codecs for more than a year to trick Windows users into installing software. In this case, when the site serving the malware determines that a user is on a Mac, it delivers a Mac-specific version.

Once installed, the Trojan hijacks the system's domain-name service. Internet-connected applications use DNS to translate the domain part of an URL, such as www.Wired.com, into the numeric IP address of a server. By hijacking the DNS, the attacker is able to replace search results with links to sites that he controls, in hopes of making money from online purchases, according to Eckelberry.

The software could also intercept intended visits to sites such as banks, eBay and PayPal and redirect them to fake websites that harvest users' logins and passwords. The scammers could then use that info to to get money out of the real sites, but neither Sunbelt nor McAfee researchers have seen the malware harvesting personal-finance info.

Unlike many Windows-based attacks, the Trojan doesn't exploit a hole in Apple's software, and it can't install itself. Instead, it relies on social engineering, tricking users into downloading the codec, and requiring that they type in the administrator password to install it.

But the fact that the hackers aren't attacking through software bugs doesn't change the portent of this week's attack, according to Eckelberry. "I don't care if you have to type in your admin password," Eckelberry said. "If you are asked to install a QuickTime plug-in, you will."

For the past year, fake codecs have been among the top problems encountered by Windows users, according to Eckelberry. The attacks have gotten so professional-looking that the fake codecs even have fake, annoying end-license-user agreements that users have to agree to.
The Mac Trojan is created by the same malware crew that has been infecting Windows machines with the Trojans known as Zlob and DNSChanger, according to Eckelberry and Marcus.

Marcus said McAfee researchers have already found the Mac Trojan on 65 websites. But he said the malware is not living up to its full potential: It only redirects users who attempt to visit one obscure adult website.

"Truthfully, this is kind of strange," said Marcus. "If you are going to mess with someone's DNS, I would have done far more fake DNS entries. I have a sneaking suspicion is that word got out before they wanted it to, but that's just an educated guess."

Evron sees more problems for Apple users than just new Trojans that try to trick users. Hackers will find it profitable and all too easy to find holes in Apple software, because the company hasn't paid sufficient attention to security, said Evron.

He predicts Apple will experience a full-range of attacks, just as Microsoft did a decade ago when Windows machines and the internet first met.

"It's Mac season. The next two years will be interesting."

http://www.wired.com/politics/security/news/2007/11/mac_trojan

Whisper
June 1st, 2008, 11:32 AM
so if you go to some random porn sites you might get a virus
DAM really?

Oblivion
June 1st, 2008, 12:17 PM
^^ Haha who would've known?

Anyway, from he title i thought you meant Apple and Trojan combined and they make like computer condoms or something O.o

iJack
June 1st, 2008, 12:23 PM
so if you go to some random porn sites you might get a virus
DAM really?
I know:(
^^ Haha who would've known?

Anyway, from he title i thought you meant Apple and Trojan combined and they make like computer condoms or something O.o
Ok...and you got 3 rep power how?

Antares
June 1st, 2008, 12:49 PM
Ok...and you got 3 rep power how?

Now what was that for? Totally not related to the topic at hand.

I actually thought that it was apple flavored Trojans but then I read "virus" so yeah. Anyways thats really scary and maybe I should tell my sister...but I don't think she looks at porn...I should have her install more security software...

Gavin
June 1st, 2008, 12:56 PM
Hmm, I shall have to tell my friends about that, since they probably wouldn't have known

iJack
June 1st, 2008, 01:24 PM
I actually thought that it was apple flavored Trojans but then I read "virus" so yeah. Anyways thats really scary and maybe I should tell my sister...but I don't think she looks at porn...I should have her install more security software...
Yea, you should, good luck bringing it up with her. If she has a mac, its a mac virus.

Hmm, I shall have to tell my friends about that, since they probably wouldn't have known

If they have macs, its a mac virus.

MoveAlong
June 1st, 2008, 01:31 PM
Ok...and you got 3 rep power how?

wtf? dude rep power has nothing to do with how smart or attentive a person is O_o

anyway, damn that really sucks. I knew it was going to happen, but it's sad to see that people have to jack people's computers and privacy.

Oblivion
June 1st, 2008, 06:26 PM
Oh and i'm not stupid either jack, i was just looking at it wrong. Anyway, why is this such a big deal? Can't you get viruses from porn sites any time? I mean its not like its new news... is it?

And the part about search... that happened to me once, every time i searched google i got porn no matter what. And that was before i had ever even seen porn in my life O.o

MoveAlong
June 1st, 2008, 06:29 PM
Oh and i'm not stupid either jack, i was just looking at it wrong. Anyway, why is this such a big deal? Can't you get viruses from porn sites any time? I mean its not like its new news... is it?

That's true, although most viruses are made to infect Windows, not Macintosh - they are completely impervious to all the viruses that infect the Windows system. But now, a new virus has been made specifically for Macs, so that's why it's news

Bound to happen sometime!

Sugaree
June 1st, 2008, 06:32 PM
Yea, you should, good luck bringing it up with her. If she has a mac, its a mac virus.
If they have macs, its a mac virus.

WOW REALLY?!?!?!?!?!

TBH I don't like Mac computers. I'm more used to Microsoft. And Jack, don't bash me and post about how great a Mac is.....

So let's hope you don't get a virus Jack.

Aηdy
June 1st, 2008, 06:33 PM
Macs are great aren't they :rolleyes:

Sugaree
June 1st, 2008, 06:43 PM
Not in my opinion...been raised around Microsoft all my life...I ain't changin'

MoveAlong
June 1st, 2008, 06:47 PM
Not in my opinion...been raised around Microsoft all my life...I ain't changin'

I'll go with whatever I can get that's fast! But that's besides the topic...
*hint hint* :P

so anyways, viruses and hackers are really stupid...can anyone tell me why someone would make a computer virus in the first place? Is it funny? And if they try to do this for a living, why don't they get a real job?

Sugaree
June 1st, 2008, 06:51 PM
so anyways, viruses and hackers are really stupid...can anyone tell me why someone would make a computer virus in the first place? Is it funny? And if they try to do this for a living, why don't they get a real job?


They do it to just piss people off probably. It may be funny if someone does it. I think I read somewhere that you can indeed get money for hacking a computer and installing a virus. I'm not sure where though :\

Maverick
June 1st, 2008, 08:04 PM
Good so I guess mac users can stop pretending they're invincible.

Sugaree
June 1st, 2008, 08:12 PM
Good so I guess mac users can stop pretending they're invincible.

I wouldn't say that they act like that...some do though but not Jack. But good point.

Maverick
June 1st, 2008, 08:21 PM
I wasn't implying anything about Jack so please don't take what I said out of context. :)

Sugaree
June 1st, 2008, 08:33 PM
I wasn't. I was simply saying that most Mac users are full of themselves. It's like Jack is a one-of-a-kind MAc user if you ask me :)

Maverick
June 1st, 2008, 08:56 PM
I was mainly talking about Apple's advertisers. :D

iJack
June 1st, 2008, 09:01 PM
BH I don't like Mac computers. I'm more used to Microsoft. And Jack, don't bash me and post about how great a Mac is.....

So let's hope you don't get a virus Jack.
I dont download porn, so i wont, yet...
Not in my opinion...been raised around Microsoft all my life...I ain't changin'
SO did i, but i did it
Good so I guess mac users can stop pretending they're invincible.
Your right, crap.

notsure101
June 4th, 2008, 05:24 PM
wow that sucks people just love screwin eachother over dont they

Ryandel
June 23rd, 2008, 09:40 PM
That bites. It's a bit obvious because the extension's ".dmg" . But ya it'll suck if mac gets hit. All my photo and other media works and project are on it. I guess I should have backed those files on my windows or some other place.

Underage_Thinker
June 25th, 2008, 10:19 PM
so anyways, viruses and hackers are really stupid...can anyone tell me why someone would make a computer virus in the first place? Is it funny? And if they try to do this for a living, why don't they get a real job?

Thats just like asking why do people rob banks instead of going to college to become a banker. Its much less work, and if your good at it, it can be very profitable.

japanman
June 25th, 2008, 10:42 PM
Pfft virus smirus i have yet to se a virus beat me the only one that got close was that trojan but it lasted a few days before i got pissed and fixed it.

but i feel sry for the ppl affected.

*Dissident*
June 26th, 2008, 02:56 PM
If you really read the whole post, hackers have yet to find a virus or trojan that penetrates OS X without the consent (In the form of a password) of the user. And now that that news is out, fewer people on macs will download programs from porn websites. And bashing Apple because of a SINGLE trojan that is very ineffective and comparing them to windows, which is essentially full of boulder-sized holes in its security, with thousands upon thousands of viruses and stuff, is really just you being mad at mac users for being pretentious, not you disliking macs themselves.

0=
June 26th, 2008, 06:11 PM
I genuinely dislike macs. I'm a system builder, but even if OS X were available I'd still go with Windows XP; it's more compatible and I like the interface. Slap some antivirus on and you're good to go. On a modern system there's no performance hit.

iJack
June 26th, 2008, 06:21 PM
That bites. It's a bit obvious because the extension's ".dmg" . But ya it'll suck if mac gets hit. All my photo and other media works and project are on it. I guess I should have backed those files on my windows or some other place.
Its a fake porn viewer. I think if you dont download porn, your ok.

Antares
June 27th, 2008, 10:44 PM
I don't think that Mac users are "full of themselves", I think that they are just stating facts. Like it was said earlier in this thread before viruses weren't a huge concern because virus makers mainly targeted Windowns. A virus for Windows can't affect Macs. So I think that it was okay for them to kinda gloat that there are no viruses because there kinda weren't...well many. So yeah that concludes my whole speil.

0=
June 30th, 2008, 02:50 PM
I know a lot of Mac users that worship anything Steve Jobs shits out. My sister's a very good example. If Apple really wanted to compete it would release OS X for every platform. Even then I wouldn't buy it because it doesn't do what I want.