Tag Archive | "Mac"

Tags: ,

Mac OS X Hit By Trojan And Backdoor Tool

Posted on 23 November 2008 by Michael

Mac OS X Box

It isn’t a surprise that all of a sudden there is a Trojan and a backdoor tool causing havoc on people’s Mac computers in my opinion.  It was only a matter of time before these viruses sprung up.  Mac has always boasted how it had such a secure operating system and it took awhile but it looks like viruses are soon to spring up more on Mac operating systems.

Within the last week two new pieces of malicious software have been affecting Apple’s Mac OS X.  The Trojan horse has the ability to download and install malicious code of an attacker’s choice, and there is also a hacker tool for creating backdoors, according to security vendors.

“It is a downloader, and it contacts a remote server to download the files it installs,” Intego said in an advisory. “This means that, in the future, the downloader may be able to install payloads [other] than the one it currently installs.”

This Trojan is apparently very similar to one that first surfaced in October 2007, Intego said.  Basically what it does is it installs a piece of destructive code known as DNSChanger, which routes the user’s internet traffic through a malicious DNS server, and this leads the users to phishing websites or website pages that display advertisements.

This Trojan can be downloaded through porn websites as it is posed as a codec needed to play video files.  By having the user download and install the Trojan it gives the Trojan access to the computer to cause havoc on the computer.

OSX.RSPlug.D has been widely confused with a separate threat publicized this week by several security firms says Intego.  That threat is called OSX.TrojanKit.Malez by Intego and OSX.Lamzev.A by other vendors.

OSX.Lamzev.A is a hacker tool that is created to mainly allow attackers to install backdoors into user’s systems.  However this hasn’t been considered as a serious threat because the tool needs to have physical access to a system to install the backdoor.

“Unlike true malware and Trojan horses, OSX.TrojanKit.Malez requires that a hacker already have access to a Mac in order to install the code,” Intego stated.

Other antivirus vendors have noted that Lamzev could be disguised as other legitimate software besides codecs and that people should be careful not to download and install because some of this software could contain the code to create a backdoor for their computer

Security vendors for a long time have said that the Mac platform isn’t sure as it has said to be and this is proof of that.  Mac users should be aware that their computers can be at risk as well and its important to be careful what you download!

Comments (4)