backtop


Print 88 comment(s) - last by overzealot.. on Mar 6 at 1:06 AM


The new Apple Trojan "BlackHoleRat" sneaks itself in through OS X users' open back doors. It is currently in "beta" and its capabilities are being expanded.  (Source: Sophos Labs)

One of its capabilities is to pop up fake administrator password request windows as a phishing attempt  (Source: Sophos Labs)

The trojan even delivers humorous messages to users in current form.  (Source: Sophos Labs)

  (Source: Chris Moncus)
Malicious program still appears to be in "beta" form, unlike its Windows counterpart

Security researchers at Sophos Labs have discovered a naughty new trojan that's in the process of beta testing attack capabilities against the growing population of Mac users.

The trojan exploits open back doors in OS X to gain a good deal of access to the system.  It can be transmitted through a variety of vectors, including torrent files or seemingly legitimate download programs.  It could also be, in the future, delivered via the exploitation of browser flaws to perform "drive by downloads".

Once inside, the Trojan gets down to business, allowing the attacker to have their way with their Apple victim.  The attacker can plant text files on the desktop, force URLs to open, run shell commands, and pop up fake password windows in a phishing attempt.

They can also force the users machine shutdown or reboot. When a reboot is forced an amusing message pops up, informing:

I am a Trojan Horse, so i have infected your Mac Computer. I know, most people think Macs can't be infected, but look, you ARE Infected! I have full controll over your Computer and i can do everything I want, and you can do nothing to prevent it.

So, Im a very new Virus, under Development, so there will be much more functions when im finished.

The virus is a port of darkComent, a remote access trojan for Windows.  The new OS X versions has been dubbed "OSX/MusMinim-A", or "MusMinim" for short, by Sophos.  Its creators, however, call it BlackHoleRat.

Sophos believes its creators will likely expand its functionality now that the concept has been proven.  It will likely be loaded with far nastier tricks in the future.

Despite its obscurity, Apple's poor security track record virtually ensures that Apple OS X users back doors will be open in years to come.  And increasingly they may find malicious individuals looking to poke and prod their way inside.

Still Apple has been quite quiet in its direction to users to get an anti-virus program.  To this day it still tries to portray Windows as "virus-laden" and OS X as virus-free.  As a result of this ostrich-in-the-sand attitude, some users may fall victim of unwanted backdoor intrusion.

Apple has yet to comment on its users' latest infection or hint at how widespread it might be.


Comments     Threshold


This article is over a month old, voting and posting comments is disabled

Awaken the Blissfully Ignorant
By morphologia on 2/28/2011 2:41:05 PM , Rating: 4
Seriously, it gets to the point where Macolytes are religiously opposed to antivirus, because using antivirus is like publicly admitting that the Mac propaganda is wrong. And like religious groups, it'll probably take Apple a couple of centuries to admit their mistakes. Meanwhile, people will continue to ignore the problem even if they themselves fall victim to the vicious problem that they've steadfastly pretended didn't exist.




RE: Awaken the Blissfully Ignorant
By Tony Swash on 2/28/11, Rating: -1
RE: Awaken the Blissfully Ignorant
By sprockkets on 2/28/2011 7:58:57 PM , Rating: 5
http://discussions.apple.com/thread.jspa?threadID=...

soooooooooooooooo,

where is that wide scale infection of vista or win7 devices?


RE: Awaken the Blissfully Ignorant
By themaster08 on 3/1/2011 3:51:41 AM , Rating: 4
Expect no response from Mr. Swash as he completely disregards the link you have posted, as he turns away stroking the back of his Mac, assuring it won't get any viruses.

I'm actually surprised that Apple have kept it on their support forums.


By struzzin20 on 3/1/2011 4:06:33 AM , Rating: 2
Nice

I just wish they would open up and tell us how much Apple is paying them to post on here!

Well Tony ?

*This message sent from a secure Windows 7 PC*


RE: Awaken the Blissfully Ignorant
By Tony Swash on 3/1/11, Rating: -1
RE: Awaken the Blissfully Ignorant
By chick0n on 3/1/11, Rating: -1
RE: Awaken the Blissfully Ignorant
By Tony Swash on 3/1/11, Rating: -1
RE: Awaken the Blissfully Ignorant
By ClownPuncher on 3/1/2011 3:33:22 PM , Rating: 2
Do you have some form of retardation or something?


RE: Awaken the Blissfully Ignorant
By Tony Swash on 3/1/11, Rating: -1
RE: Awaken the Blissfully Ignorant
By ClownPuncher on 3/1/2011 7:23:48 PM , Rating: 2
Because most malware was created for Windows. I think that is pretty clear.

If the amount of malware is what you hinge your OS purchase on, then go for it. People who run windows can just use MSE and not open links in spam email. It's pretty simple to keep your computer clean, and you no longer need to be a "guru".


RE: Awaken the Blissfully Ignorant
By Alexstarfire on 3/1/2011 7:51:27 PM , Rating: 2
I'd agree, but people in general seem to be stupid when it comes to the unfamiliar. That might seem odd to say considering computers have been around for so long, but to the vast majority of people they are still very unfamiliar with most things on a computer.

I've literally told people to their face to NOT do something just to watch them do it like 30 seconds later. I can't get more clear/direct than that. When most people use a computer it's like them having unprotected sex with a stranger even when a condom is sitting on the night stand. Sure, some of the time you might be ok, but just that one bad sex partner and it's all over.


By ClownPuncher on 3/2/2011 7:53:55 PM , Rating: 2
That is actually a good thing. People will either learn from their mistakes, or be doomed to fail. Life.


RE: Awaken the Blissfully Ignorant
By sprockkets on 3/1/2011 8:06:24 PM , Rating: 2
You asked:

quote:
Show-me-a-real-world-example-of-a-Mac-actually-gett ing-infected.


And I provided. So instead of changing the goal posts or some other bull sh it, admit you were wrong then shut the fu ck up.


RE: Awaken the Blissfully Ignorant
By Tony Swash on 3/2/11, Rating: -1
By sprockkets on 3/2/2011 4:47:47 PM , Rating: 2
quote:
You offer up a two year old forum thread containing exactly six comments. The only comment of substance in the thread is the opening one that says 'I clicked on a Goggle link and it didn't go where I expected'. There then follows five comments offering advice and some speculation about whether this might be Trojan related. And that's it!!!


Reading comprehension fail. And no, I won't tell you why you are wrong; you can figure that out for yourself.


RE: Awaken the Blissfully Ignorant
By leuNam on 3/3/2011 12:17:30 PM , Rating: 1
mark you in time, when OS X will be full of viruses it be named Tony...


RE: Awaken the Blissfully Ignorant
By Argon18 on 2/28/11, Rating: -1
RE: Awaken the Blissfully Ignorant
By bplewis24 on 3/1/2011 12:04:25 PM , Rating: 2
*facepalm*


RE: Awaken the Blissfully Ignorant
By KoolAidMan1 on 3/1/11, Rating: 0
By Alexstarfire on 3/1/2011 7:55:40 PM , Rating: 2
He certainly is correct, but I'm failing to see how this is less harmful to users. Any type of malware is bad, period. A virus and trojan are usually used for two separate purposes. They are both quite harmful in the end. Actually, a trojan could be far worse since usually all a virus can/is meant to do is make your computer useless and spread itself. A trojan could very well get your login and password to any account you use on that computer. That seems far worse to me.


By testerguy on 3/3/2011 4:11:03 AM , Rating: 2
Firstly - a Trojan CAN be a virus. It is possible to engineer a legitimate appearing malicious file which is also able to propagate (replicate and distribute) itself, thus satisfying both requirements.

Secondly - anti virus programs CAN and DO detect Trojan horses as well.

Thirdly - a Windows batch file is NOT a Trojan because it's clearly an executable, whereas a Trojan horse would masquerade as something else less dangerous.

Finally, a virus by definition does NOT have to be able to reproduce with no user intervention. For example, a user can intervene by removing a USB from one PC to another, thereby allowing the Virus to replicate. User intervention, and still a virus.

All of the above being said, and despite thinking that what you're arguing is a distinction without a difference in the real world (since whether it's a virus or a Trojan doesn't really matter much once your computer dies), what you write is largely correct.


By HomerTNachoCheese on 3/1/2011 8:57:29 AM , Rating: 1
Like Catholics and condoms, antivirus for a Mac is just wrong. (no offense to Catholics).


"Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town." -- Charlie Miller














botimage
Copyright 2014 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki