Giveaway: Bracketron Case If outdoor adventures are in your future this summer, enter to win a Bracketron Sport Case with Mount Strap from MacNN and keep that iPhone, iPod or other electronic device safe from the elements.      
toggle

AAPL Stock: 454.74 ( + 1.77 )

http://www.macnn.com/articles/11/09/23/malware.currently.just.minor.threat/

Mac Trojan may funnel files, screenshots to distant servers

updated 01:15 pm EDT, Fri September 23, 2011

 

Malware currently just minor threat


A newly-detailed Trojan attack is being directed at Macs, say security firms F-Secure and Sophos. Originally spotted in late July, the Trojan relies on two pieces of malware. The first is a downloader identified as "Trojan-Dropper:OSX/Revir.A," which not only retrieves the second piece of software but repeatedly opens a Chinese PDF document -- trojan.pdf -- said to contain offensive political statements. The real purpose of the document is thought to be distracting a person while the second app is downloaded.

Nicknamed "BackDoor:OSX/Imuler.A," the second half of the Trojan configures a launch agent which keeps the malware active, and then connects to a remote server, feeding it a victim's computer username and MAC address. The server can reportedly instruct a besieged system to archive files and upload them, or else capture screenshots for upload. F-Secure comments that Imuler.A currently seems to be working badly or not at all, since it isn't receiving instructions; the company warns, though, that server may simply be in a testing phase, and could later become fully functional.

Both Sophos and F-Secure have produced updated definitions for their antivirus scanners that should cope with the Trojan. Apple has yet to push out new definitions for Lion and Snow Leopard, but the malware is said to be relatively easy to stop manually. People must first stop a process called "checkvir" in the Activity Monitor, and then delete "checkvir" and "checkfir.plist" files from their /username/Library/LaunchAgents/ directory.


by MacNN Staff

Post tools:

TAGS :

 security, Mac OS X
toggle

Comments

  1. dliup

    Fresh-Faced Recruit

    Joined: Jan 2006

    -5

    non-issue

    Apple will provide a security definition within 24 hours to lock out the trojan.

  1. lysolman

    Fresh-Faced Recruit

    Joined: May 2005

    0

    What in the world

    is an offensive political statement?

  1. testudo

    Forum Regular

    Joined: Aug 2001

    -14

    Re: non-issue

    Of course it's a non-issue. Every mac 'security hole' is a non-issue. Because a patch will be issued. Or a definition. Or it requires physical access. Or requires the user to do something they shouldn't do.

  1. Grendelmon

    Forum Regular

    Joined: Dec 2007

    -10

    Non-issue?

    AYFKM? Your responses just keep getting better. Denial.

    SAVE US APPLE!!! OH, THE MESSIAH... SAVE US!!!

  1. dliup

    Fresh-Faced Recruit

    Joined: Jan 2006

    +5

    @testudo

    Software cannot correct user stupidity. You are a prime example.

  1. rbodgers

    Fresh-Faced Recruit

    Joined: Feb 2010

    +8

    @testudo

    "Because a patch will be issued. Or a definition. Or it requires physical access. Or requires the user to do something they shouldn't do."

    That same statement is just as valid for Windows. But:

    - not everyone runs their updates timely
    - definitions are not always timely
    - smart people do dumb things ALL THE TIME (especially those of us who should know better)

  1. Evolution_tech

    Fresh-Faced Recruit

    Joined: Sep 2011

    0

    @testudo

    Another pinhead comment by an ignorant troll.

  1. facebook_William

    Via Facebook

    Joined: Sep 2011

    +1

    Apple XProtect v24 is out

    Adds OSX.Revir.A definition.
    Run sudo /usr/libexec/XProtectUpdater or just reboot if you want to be protected now. XProtectUpdater runs every 24 hours from boot time.

  1. byRyan

    Fresh-Faced Recruit

    Joined: Jun 2007

    +6

    stealthy naming

    wow - so two of the files involved in this Trojan are named "Trojan"

    Note to self, don't open files labeled TROJAN

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

HTC One

It is hard to understate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming declin ...

Samsung Galaxy S 4

Samsung's new flagship Android smartphone, the Galaxy S 4, faces even stiffer competition than its popular predecessor. With a five-in ...

HighPoint RocketU 1144CM USB 3.0 PCI-E card

Apple was one of the first -- if not the first -- major computer manufacturers to provide then-fledgling USB support at the expense of ...

toggle

Most Commented