toggle

AAPL Stock: 97.97 ( + 0.3 )

Printed from http://www.macnn.com

'Beta' backdoor Trojan for Mac enters circulation

updated 10:30 am EST, Mon February 28, 2011

Allows for phishing, shell commands

A new backdoor Trojan is targeting Mac users, says security firm Sophos. The attack is delivered via a client called BlackHole RAT, which in turn is based on Windows software known as darkComet. RAT is described by as "very basic," and effectively a beta, as even its creator admits that it's unfinished. It can nevertheless do some serious damage, as it allows an attacker to run shell commands or pop up a fake "Administrator Password" window to phish a person's account data.

Other options include dropping text files on a desktop, or sending URLs that open a website. A targeted Mac can be made to sleep, shut down or reboot; in that regard, a fullscreen window can be triggered which only offers the option of rebooting. "I am a Trojan Horse, so i have infected your Mac Computer," the window reads by default. "I know, most people think Macs can't be infected, but look, you ARE Infected! I have full controll over your Computer and i can do everything I want, and you can do nothing to prevent it. So, Im a very new Virus, under Development, so there will be much more functions when im finished."

The Trojan can end up on a Mac in several ways. While downloading pirated software is one, it can also be delivered via vulnerabilities in browsers, plugins and other programs. Some existing antivirus utilities, such as Sophos', should be able to scrub the malware.








by MacNN Staff

POST TOOLS:

TAGS :

toggle

Comments

  1. gskibum3

    Joined: Dec 1969

    +22

    Terrifying

    I'm so scared now I think I'll run out and buy Sophos Anti-Virus.

    /sarcasm

  1. Teq

    Joined: Dec 1969

    +4

    it's actually free

    afaik, not that I'll be installing it anytime soon

  1. ggirton

    Joined: Dec 1969

    0

    jeeze don't these blackhats know?

    The unboxing ninjas are real? Sure, you may create a successful Mac virus but watch your gajongas ... because soon you will be removed from the gene pool and will no longer be able to reproduce.

    SRSLY

  1. testudo

    Joined: Dec 1969

    +2

    Re: jeeze don't these blackhats know?

    Sure, you may create a successful Mac virus

    Well, at least the blackhats know that this isn't a virus. It's a trojan horse.

  1. Mr. Strat

    Joined: Dec 1969

    +1

    It's FUD time again

    And yet another company that coincidentally sells anti-virus software warns us about a Mac virus...

  1. facebook_Michael

    Via Facebook

    Joined: Feb 2011

    -2

    Ho-hum.

    your comment

  1. facebook_Justin

    Via Facebook

    Joined: Feb 2011

    +2

    comment title

    Anyone else think its the anti-virus software makers that are actually making the viruses?

  1. testudo

    Joined: Dec 1969

    +2

    Re: Its FUD time again

    At least they get their information correct. As opposed to a second person here who's mentioned a Mac virus when it is no such thing.

  1. facebook_Bufus

    Via Facebook

    Joined: Feb 2011

    +1

    Hrm...

    I've seen something like this back in the late 90's from Jason Toffaletti (who used to have a "company" called black hole media). I wonder if this is his doing....

  1. donmontalvo

    Joined: Dec 1969

    +1

    No admin rights, no problem.

    :)

Login Here

Not a member of the MacNN forums? Register now for free.

toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

JBL Synchros E40BT headphones

For all the different configurations of headphones on the market, it's always a tough choice for buyers to get something that is just ...

Razer Taipan mouse

The list of gaming devices is growing larger with each passing day. A large number of companies have entered the gaming input arena, a ...

Cambridge Audio DacMagic XS

Every computer with a microphone or headphone port has one -- a digital to analog converter (DAC). There are nearly as many chipsets a ...

toggle

Most Commented