Text Size

First Mac-based botnet becomes active

updated 09:40 am EDT, Fri April 17, 2009

Mac-based botnet active

The first known botnet to exploit Mac OS X has been activated, security researchers claim. The network is believed to have been put in place by iServices, a Trojan infection accompanying some pirated versions of iWork '09 and Photoshop CS4. Although downloaded at least 20,000 times by the end of January, the Trojan's payload has remained dormant for some time, in the same manner as many Windows botnets.

Symptoms of the active iServices botnet may begin with excessive CPU usage on a Mac, the result of a PHP script instigating denial-of-service attacks on websites. Many anti-virus programs have been updated to block iServices however, and it may also be possible to halt the Trojan's operations by deleting "System/Library/StartupItems/DivX" and/or "System/Library/StartupItems/iWorkServices" folders. Some security companies, such as SecureMac, are offering removal tools specifically targeted at iServices.

In spite of the potential number of infected computers, the danger from the current botnet is expected to be minimal, both as a result of security measures and the limited vectors of infection. Symantec researchers warn, though, that the code in iServices is designed to be extremely flexible, and as such modified versions may appear in upcoming months.

 
Previous Comments

Image that

04/17, 10:18am reply

You spent the $ for the hardware but were too cheap to drop the $ for the software so you got a nasty.

ibugv4

Fresh-Faced Recruit

Joined: Jun 2003

+1

FUD Time Again

04/17, 10:28am reply

Stolen software which will require physical access and admin rights to install...BFD.

We're still waiting for an infection through no physical access, no admin rights, no PEBCAK.

Mr. Strat

Fresh-Faced Recruit

Joined: Jan 2002

+6

Comment buried. Show

Re: image that

04/17, 11:19am (2 replies) reply

Maybe its because they spent all their money on the computer and AppleCare, they had nothing left.

Oh, right, I think only the affluent are supposed to be buying macs...

testudo

Fresh-Faced Recruit

Joined: Aug 2001

-40

Comment buried. Show

Re: FUD

04/17, 11:22am (1 reply) reply

And so you believe that there is no security threat unless it meets your criteria? Nice to know.

And I love how people discount physical access to a computer. I guess Mac users believe all macs are Personal computers and are never used by more than one person...

testudo

Fresh-Faced Recruit

Joined: Aug 2001

-28

Not Mac OS

04/17, 11:25am reply

This botnet (if it exist) isn't exploiting Mac OS X, it is exploiting users. There couldn't be any protection against users, that will gladly install and provide admin password to an app called Botnet Client for Mac, if those users are naive enough.

The worst thing to do is to buy antivirus app, which will be happily clogging your Mac while having no idea that this brand new app you've just installed (and which can be created in an hour) is a botnet client.

ViktorCode

Fresh-Faced Recruit

Joined: Jan 2006

+8

Comment buried. Show

Same as Windoze

04/17, 01:25pm reply

Mac users will call it FUD as usual, without realizing that this malware threat is the same as Windows. Almost NO Windows malware spreads by itself, and almost ALL Windows malware requires the user to actually download it manually and install it before it does anything.

And yet Mac users will say "if it doesn't spready by itself" or "if it requires admin rights" it's not a real malware threat. Get over it people, it is real.

fubar_this

Fresh-Faced Recruit

Joined: Jul 2006

-12

Comment buried. Show

Re: not mac os

04/17, 01:30pm (1 reply) reply

Don't know how to break it to you, but most all botnets end up because users install c*** onto their computers. There's just a lot more PC users, which means there's a larger selection of gullible ones who'll install an 'update to flash' or 'missing codec' to get themselves infected.

BTW, an app does not need an admin password to be installed. It just would install to the current user, not as a system daemon or the like. But it certainly isn't hard to have a background program added as a login item...

testudo

Fresh-Faced Recruit

Joined: Aug 2001

-12

Re: Not Mac OS

04/18, 02:05am reply

I don't get ViktorCode's statement. Did you not read the part about most antivirus programs on the Mac catching this since January? Antivirus on Windows and Mac have always detected trojans. Norton AntiVirus on Windows updates its definitions every 5 minutes, but still detects most trojans heuristically.
Maybe you don't need antivirus but to make a blanket statement like that is pretty irresponsible.

fubar_this

Fresh-Faced Recruit

Joined: Jul 2006

+2

my gawd

04/18, 06:46am reply

"Maybe its because they spent all their money on the computer and AppleCare, they had nothing left."

you're like right wing nutjobs who regurgitate what hannity and limbaugh tell them.

nat

Junior Member

Joined: Mar 2002

-2

Funny...

04/18, 10:27am reply

Rush uses all Macs, big supporter of Apple. And it is apparent that you have never listened to him, as you are just regurgitating the left wing spin. The same left wing that doesn't listen to him either but can spend much of their day trying to discredit him.

localnet

Fresh-Faced Recruit

Joined: Feb 2005

-8

Popular News