Print 117 comment(s) - last by JKflipflop98.. on Nov 6 at 8:52 PM

Mac users are now at risky of getting a nasty virus.  (Source: Listmania)

If it you approve, you are a sad noob, and your Mac is infected.  (Source: Intego)
Mac: Hi PC, I'm not feeling so hot today... PC: Oh, I know ALL about that. I think you have a virus!

Security experts by and large agree that security via obscurity is not a wise model for protecting customers over the long term.  That's exactly the model Apple has employed successfully for some time now.  However, its luck finally appears to be running short.

Hot on the heels of a newly discovered iOS exploit that allows access to locked iPhones, new reports [1] [2] from security research firms 
SecureFirm and Intego reveals that a new trojan is targeting Mac users using a vulnerability in OS X's Java player.

According to the 
Intego report the new malware, trojan.osx.boonana.a, is really a reworked version of the Koobface malware, which has attacked Windows in the past.  The malware acts as a worm when it spreads and as a trojan when it is infecting your computer.

Users may encounter the worm via links posted on Facebook, MySpace, Twitter, and other websites.  When clicking the link, the applet attempts to run.  Users can stop the infection before it starts by denying the applet permission to run when OS X's Java player pops up a dialogue.

If they allow the applet to run, they may get another warning if they have a Mac antispyware program like VirusBarrier X6’s Anti-Spyware installed.  If they don't get the warning, or choose to disregard it, the applet will attempt to make a connection with a remote server and installs a rootkit, backdoor, command and control, and other elements.  These files are copied to an invisible folder -- .jnana -- in the user's home directory.

If the virus is allowed to carry out its infection process, the unsuspecting Mac user may find themselves part of a botnet.  When they log on social networks, the virus will post links to spread the infection.  It may also send spam e-mail via their logged-in accounts

Other variants of this virus target Windows and Linux, making it a rare true cross-platform virus.  All these viruses share the fact that they use the Java player as a route of attack.  According to 
Intego, other OS X-specific versions of the virus have shown up, but most are broken or try to connect to offline servers.

The malware could become potentially more dangerous in the future if it is able to eliminate the warnings from the Java player and/or change the name/location of the infection directory, making it hard for virus removal software to find it.

While it does not appear that this virus takes advantage of any unique flaws in Apple's version of Java, some security experts say that Apple's Java player may have more vulnerabilities than Window's.  That's because Apple makes its own Java player, which according to an e-mailreportedly attributed to Apple Chief Executive Steve Jobs, is always a version behind the official Linux/Windows builds from Sun and Oracle.

Apple is reportedly considering ditching its Java player in future versions of OS X, such as OS X 10.7 "Lion".  Similarly it's considering rejecting Flash, another multimedia web technology.  Ultimately these efforts may eliminate some routes of attack, but now that Apple is being targeted it must realize -- there is 
always a back door.


Comments     Threshold

This article is over a month old, voting and posting comments is disabled

RE: More pleasing fantasies for the truly insecure
By SkullOne on 10/28/2010 10:13:22 AM , Rating: 3
I love how the iSheep spin it already. Attack vector across all platforms or it's technology being dumped because it's crap.

My favorite right now is it's a worthless virus because it requires user interaction. If that's the case then most of the malware infecting Windows right now is worthless because most of it is moving towards some form of social engineering in order to get users to bypass security measures like UAC.

Honestly Tony you need to take a deep sniff of the shit your shoveling so that you pass out. This is only the beginning. Windows users don't want Macs exploited and trashed. We don't care if you want to use a Mac. We just want people like you to shut your damn mouth, drop the "holier then thou" attitude and stop trying to convince the world that your exploit free (when that's far from the truth) because Steve Jobs says so.

RE: More pleasing fantasies for the truly insecure
By Tony Swash on 10/28/10, Rating: -1
By inighthawki on 10/28/2010 10:24:48 AM , Rating: 3
Considering there are images showing of attempts at infection, you cannot honestly believe there is not a SINGLE PERSON dumb enough to hit OK, or even by accident? We don't need a specific example to assume something like this to have occurred already. Rule of thumb, if there is a virus/trojan/etc of any kind, at least one person is dumb enough to fall for its trap.This holds true on any platform, not just OSX.

By inighthawki on 10/28/2010 6:27:52 PM , Rating: 3
I take it you're not very skilled in logic then? No offense but when someone says "I have yet to see an infection, therefore there isn't one", a statement such as "absence of proof is not proof of absence" is a completely valid counter-argument, and is 100% true. I do not have to provide (or take the time/waste my time to find) a direct counter-example, when I can just show the flaw in his logic. I'll wait till he makes a single valid point before I have to give an actually counter-example.

By littlebitstrouds on 10/29/2010 2:53:45 PM , Rating: 1
What confuses me, is if you're so sure of your own arguments, why not take the short time to destroy the very premise and give the counter-example? Seems like an easy task isn't it?

"My sex life is pretty good" -- Steve Jobs' random musings during the 2010 D8 conference

Copyright 2016 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki