toggle

AAPL Stock: 509.46 ( + 6.86 )

New spyware tracks Mac files, opens up backdoors [u]

updated 01:20 pm EDT, Tue June 1, 2010

Code attaches to files at legitimate websites


(Updated with list of affected apps) A new piece of spyware is targeting Mac users through downloaded apps, warns security firm Intego. Dubbed "OSX/OpinionSpy," the code is said to be attached to programs like screensavers, found at otherwise legitimate download sites like MacUpdate, VersionTracker and Softpedia. Only when a person tries to install an affected app is the separate spyware actually downloaded, in some cases under the guise of being a "market research" tool.

The code attempts to run as root, asking for an administrator's password. If granted access, the spyware will then open an HTTP backdoor, and perform a long scan of any and all files, including those on network volumes. It also tracks incoming and outgoing network packets, and steals information from Safari, Firefox and iChat. The collected data is sent to remote servers, potentially exposing all of a person's private details, such as passwords and credit card numbers.

On top of this the code will occasionally prompt people to enter data voluntarily, for instance by filling out a survey. OpinionSpy can ultimately break a Mac, forcing a user to reboot his computer while still suffering from the infection. Deleting the program the spyware is associated with does not remove the latter.

Intego remarks that a Windows version of OpinionSpy has existed since 2008, but that the Mac version appears to be a more serious threat. People are urged to update their antivirus software as soon as possible, and turn on real-time scanning, which should be able to detect the spyware's download. Tools that can successfully spot OpinionSpy should be able to eliminate it.

Update: Intego has supplied what it calls a "preliminary" list of contaminated apps. All but one, MishInc FLV To Mp3, are made by a company called 7art-screensavers. A list of titles can be found below.

• Secret Land ScreenSaver v.2.8
• Color Therapy Clock ScreenSaver v.2.8
• 7art Foliage Clock ScreenSaver v.2.8
• Nature Harmony Clock ScreenSaver v.2.8
• Fiesta Clock ScreenSaver v.2.8
• Fractal Sun Clock ScreenSaver v.2.8
• Full Moon Clock ScreenSaver v.2.8
• Sky Flight Clock ScreenSaver v.2.8
• Sunny Bubbles Clock ScreenSaver v.2.9
• Everlasting Flowering Clock ScreenSaver v.2.8
• Magic Forest Clock ScreenSaver v.2.8
• Freezelight Clock ScreenSaver v.2.9
• Precious Stone Clock ScreenSaver v.2.8
• Silver Snow Clock ScreenSaver v.2.8
• Water Color Clock ScreenSaver v.2.8
• Love Dance Clock ScreenSaver v.2.8
• Galaxy Rhythm Clock ScreenSaver v.2.8
• 7art Eternal Love Clock ScreenSaver v.2.8
• Fire Element Clock ScreenSaver v.2.8
• Water Element Clock ScreenSaver v.2.8
• Emerald Clock ScreenSaver v.2.8
• Radiating Clock ScreenSaver v.2.8
• Rocket Clock ScreenSaver v.2.8
• Serenity Clock ScreenSaver v.2.8
• Gravity Free Clock ScreenSaver v.2.8
• Crystal Clock ScreenSaver v.2.6
• One World Clock ScreenSaver v.2.8
• Sky Watch ScreenSaver v.2.8
• Lighthouse Clock ScreenSaver v.2.8




by MacNN Staff

toggle

Comments

  1. QualleyIV

    Fresh-Faced Recruit

    Joined: Aug 2001

    +6

    It's not like any of this c*** is good, but...

    Even the Intego description seems to concede that this software ASKS YOU TO INSTALL IT. So, wouldn't the best solution just be to not install it rather than buying a processor-sucking antivirus software to remove it for you once you've installed it?

  1. Flying Meat

    Fresh-Faced Recruit

    Joined: Jan 2007

    +6

    So helpful... Not.

    If you know that software downloaded from X site/s have this software added during installs, wouldn't it be in everyone's best interests to share the names of those software titles so folks can investigate for themselves whether they are at risk?

    Doesn't mean those titles did have it when it was downloaded, or will always have it, but those that downloaded those titles might have reason to investigate.

    No-no! Buy this software to protect against that software that you got with some other software... :P

  1. panjandrum

    Fresh-Faced Recruit

    Joined: Dec 2004

    +9

    Trojan horse

    I think the point is that this is a form of trojan horse. You think you've got one thing, but there is something else hidden in it. When you install the legitimate product, you also unwittingly install the malware. I expect that almost any computer user would fall for that, since until now there has been no reason until now to expect that the "insert name here" download from MacUpdate has been compromised. I'm interested in how this is happening. Have the servers as MacUpdate, VersionTracker, etc. been compromised? How is this malware getting attached like this? This article needs to be expanded with more detailed information.

  1. MizuInOz

    Fresh-Faced Recruit

    Joined: Feb 2010

    +1

    Name the software or this is more FUD

    Site real world apps that are installed and list the package content and I will believe it.
    I am really tired of the BS and FUD that security software companies spread. It is like plastering Vegemite on toast - unless you want to live with the bad taste for a long time, you make sure you like the smell. And this doesn't smell right.

    VT and MacUpdate are supposed to check every app for this kind of c***. I am with panjandrum - I would like to know if the servers have been compromised.

    Thanks for the snippet of almost information. Need more data.

    Cheers.

  1. drbroom

    Fresh-Faced Recruit

    Joined: Dec 2006

    +12

    The question is...

    What is the name of process?! (we should be able to see it in our "Activity Monitor")

    I have a lot of problems with companies that's sole purpose is releasing this kind of warning and selling us the solution.

    I am a security professional (a CISSP in fact for what ever that is worth) and I KNOW that there is no such thing as a truly secure machine; no matter how many of us would like to believe Mac are (except for one that has NO access to the world), but when I read that Intego tells us that there is a new vulnerability out there, all I can say is. Where is CERT's advisory?

    If Intego finds these things their first action should be to send it to CERT. Let them test to see if it is real and have them send out the warning. They have nothing to sell. Nothing to prove and most importantly not tainted reputation!!!

    I'm sorry Intego your "ego" is writing checks your company can't cash!!!

  1. Mr. Strat

    Fresh-Faced Recruit

    Joined: Jan 2002

    +1

    Hmmm...

    A company that sells anti-virus software reports malware in the wild. We've never trusted these guys before. I'd see if MacUpdate's and others' servers have been compromised.

  1. MizuInOz

    Fresh-Faced Recruit

    Joined: Feb 2010

    +4

    Thanks for the list

    Thanks MacNN for the list.

    Clean and clear...

    Cheers

  1. jwdsail

    Fresh-Faced Recruit

    Joined: Jun 2000

    +2

    Check for the open ports..

    Until someone posts the process name(s), maybe go to Shields Up! at http://www.grc.com/ and do a full scan of "All Service Ports", as well as checking port 8254.

    sigh...

    https://www.grc.com/x/ne.dll?bh0bkyd2

    http://www.grc.com/port_8254.htm (click on "probe this port")



  1. testudo

    Fresh-Faced Recruit

    Joined: Aug 2001

    +5

    Re Hmmmmm

    I'd see if MacUpdate's and others' servers have been compromised.

    This isn't about compromised servers (for most of these sites don't host the software themselves, they just point to it from the provider). It's about an app developer inserting a trojan into their software. Or a developer who's site has been hacked and someone has uploaded infected versions of the software (or, better yet, just wrapped the software around an installer with an additional payload).

    BTW, the screensavers are a nice touch, as most people installing a screen saver and getting asked for their password wouldn't think twice about providing it. Assuming people think about such things at all.

    Although I must ask. Do people still use screen savers?

  1. Flying Meat

    Fresh-Faced Recruit

    Joined: Jan 2007

    -6

    Yay! Someone was on the ball.

    Thanks for the list. It is helpful info. This also goes a long way toward showing Intego's desire to help, and not just to sell a product.

    If I were currently in the market, I might well check out their AV, just for this! :)

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

10 Most Read

Recent Reviews

Logitech Cube

The world of mice could often be described charitably as stagnant: it's an endless sea of ergonomic shapes that assume you're sitting ...

NewerTech and Targus USB Hubs For Gifts

A useful holiday present to resolve an ongoing frustration is a multi-port hub. Whether as a stocking stuffer, Chanukah present, or an ...

X-Rite ColorMunki Photo

Color calibration is the art of tweaking your monitor so that the colors represented on screen better match real life and your printer ...

toggle

Most Commented

10 Most Discussed