On BNET: 3 worst things about the iPhone 3G S
BNET Business Network:
BNET
TechRepublic
ZDNet

By Anne Broache
Posted on ZDNet News: Feb 16, 2006 10:53:00 PM

A malicious program that could be the first Trojan in the wild to target Apple Computer's Mac OS X operating system has been discovered, security experts confirmed Thursday.

Apple and outside analysts said the program, referred to as Leap-A, is not a "virus" per se. Rather, it "requires a user to download the application and execute the resulting file," Apple said in a statement to CNET News.com. The company provided no further comment on the nature of the program.

The malicious software, which has also been dubbed OSX/Oompa-A and the Ooompa Loompa Trojan Horse by other security experts, appears to have spread minimally so far and has achieved low-level threat classifications from McAfee and Symantec.

But security experts cautioned Macintosh users to view the incident as a wake-up call that all operating systems have vulnerabilities.

"It's not really news as far as threats go," said Ray Wagner, a senior vice president in Gartner's information security group. "It is news because it targets OS X, and as far as I know, it's certainly the first OS X malicious content in the wild that's been noted at this point."

Classified as both a worm and a Trojan, Leap-A appears to have begun its movement earlier this week after it was posted at a forum for Mac-related rumors. The file appeared as an external link promising pre-release screenshots of the upcoming Mac OS X 10.5, also known as Leopard.

Leap-A, which appears to affect only the OS X 10.4 platform, spreads primarily via the Apple iChat instant-messaging program. The program forwards itself as a compressed file called "latestpics.tgz" to all the contacts on the infected user's buddy list each time the program starts up.

But it's up to the person to download the file, which shows up as an attachment to a conversation thread. If downloaded, the self-executable file masquerades with an icon typically reserved for image files but does not activate itself unless opened.

"It exhibits the same behavior as a Trojan in that it requires user interaction and a mass mailer in that it's going through the contact list of that particular iChat client," said Dean Turner, senior manager of Symantec Security Response. "And it's a worm because it's replicating on its own once the system has become infected."

An analysis by U.K.-based security firm Sophos said it attempts to infect recently used applications by overwriting the original application with a copy of the worm. According to Symantec, "files infected by OSX.Leap.A may be corrupted and may not run correctly."

A number of security companies--including Symantec, McAfee, Sophos and Intego--have released updated definitions to guard against the threat. Apple directed customers to a safety guide at its site and said it "always advises Macintosh users to only accept files from vendors and Web sites that they know and trust."

Andy McCue of Silicon.com contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 97 Talkback(s)
wow
Hummm,
All I can say is that you must not see much in the way of file traffic?
I get them constantly.... (Read the rest)
Posted by: gtravis3 Posted on: 02/21/06 You are currently: a Guest | | Terms of Use
No no no! I was just kidding  Boot_Agnostic | 02/16/06
Many of the thirty-something viruses for OS9 were  MacGeek2121 | 02/17/06
Porting is the key  Boot_Agnostic | 02/17/06
It's not possible  Immanuel Tranz-Mischen | 02/19/06
i read articles all over about this...  doh123 | 02/16/06
Takes a lot of effort to catch this one...  tic swayback | 02/16/06
Something that could help  Jeremy Chappell | 02/16/06
what could help users...  rafe01 | 02/17/06
I remember a Windows program...  s_gamgee | 02/17/06
for screenshots????  MacGeek2121 | 02/17/06
Sure does  I'm Ye, the MS SHILL . | 02/18/06
This is no big deal !!!  I'm Ye, the MS SHILL . | 02/18/06
err, does this show vulnerabilities?  Jeremy Chappell | 02/16/06
I'm confused  NonZealot | 02/16/06
Re: I'm confused  leguirerj | 02/16/06
This solely is a user hit not any OS hit  RicD_ | 02/16/06
RE: This solely is a user hit not any OS hit  Jeremy Chappell | 02/16/06
RE: RE: This solely is a user hit  999ad@... | 02/17/06
Can't patch stupidity  Jeremy Chappell | 02/16/06
no you're not..  rafe01 | 02/17/06
Amen, brother, amen  EJHonda | 02/17/06
Yes, however, this is nothing like Microsoft.  olePigeon | 02/17/06
You obviously know nothing about Windows  NonZealot | 02/17/06
I didn't say Windows didn't have those features.  olePigeon | 02/17/06
I agree, never said this was a virus  NonZealot | 02/17/06
Zealot  b.d.hi | 02/17/06
Typical Mac zealot response! (NT)  NonZealot | 02/17/06
You've got to be kidding  I'm Ye, the MS SHILL . | 02/18/06
Neither do you.  Immanuel Tranz-Mischen | 02/19/06
You just proved your ignorance  NonZealot | 02/20/06
No, I just proved YOUR ignorance.  Immanuel Tranz-Mischen | 02/20/06
Immanuel: If ignorance is bliss...  NonZealot | 02/20/06
Cute  tic swayback | 02/17/06
I'm a Mac user. There's no way OSX is completely invulnerable.  MacGeek2121 | 02/17/06
I hope you're not stupid enough...  Immanuel Tranz-Mischen | 02/19/06
Yikes, I'm embarrassed for you  NonZealot | 02/20/06
Unlike you, I know better than to use Windows  Immanuel Tranz-Mischen | 02/20/06
A Fundamental Problem  ITTech001 | 02/16/06
A Fundamental Problem  Jeremy Chappell | 02/16/06
true...  rafe01 | 02/17/06
Process Audit and Rollback  ITTech001 | 02/17/06
Hindsight  gtravis3 | 02/20/06
Over and over again?  Laff | 02/20/06
wow  gtravis3 | 02/21/06
Can't patch stupidity  Jeremy Chappell | 02/16/06
Dancing bunnies  PB_z | 02/16/06
re: Dancing bunnies  Jeremy Chappell | 02/16/06
you can tell if you look first... but look closer...  doh123 | 02/17/06
But then ...  ShadeTree | 02/17/06
Watch and see  tic swayback | 02/17/06
If the implication of your statement ...  ShadeTree | 02/17/06
depends on the metrics  woot! | 02/17/06
Actually  j.m.galvin | 02/17/06
Let's look at the numbers  tic swayback | 02/17/06
Go to the Mac tech support sites  s_gamgee | 02/17/06
Can I guess?  NonZealot | 02/17/06
Actually there's two cults  woot! | 02/17/06
Very unlikely  Rick_K | 02/17/06
Impossible!  John Zern | 02/16/06
Message has been deleted.  Narg | 02/17/06
At the risk of feeding the Troll...  woot! | 02/17/06
Ah, Narg, did you read the post?  John Zern | 02/19/06
Hmmmmm...I don't use iChat.  Laff | 02/16/06
so...  rafe01 | 02/17/06
Theres a big different between doing something where  Laff | 02/17/06
So if I understand you correctly...  NonZealot | 02/17/06
Disadvantages? What disadvantages?  Laff | 02/17/06
The disadvantages of OSX  Rick_K | 02/17/06
Disadvantages??  djc1309@... | 02/17/06
Clearly, the problem is...  tic swayback | 02/17/06
I'll kill him  djc1309@... | 02/17/06
malware vs os's  jguyp725@... | 02/17/06
Who does it really affect?  Kid Icarus | 02/17/06
Stoopid users...  Narg | 02/17/06
Ummm, yeah,  Kid Icarus | 02/17/06
iChat is available only for Mac OS X  I'm Ye, the MS SHILL . | 02/18/06
I think  j.m.galvin | 02/17/06
Stoopid users are everywhere  zmud | 02/17/06
I agree 100%  NonZealot | 02/17/06
Fear of files  tic swayback | 02/17/06
Fear of file?  NonZealot | 02/17/06
Advantage  tic swayback | 02/17/06
A few more  tic swayback | 02/17/06
Advantages?  NonZealot | 02/17/06
Out of the box, baby!  tic swayback | 02/17/06
Fatal flaws?  NonZealot | 02/17/06
Windows advantage  Rick_K | 02/20/06
Poor poor Rick  NonZealot | 02/20/06
Not Even a Trojan  Techscan | 02/17/06
Easy test to pass  tic swayback | 02/17/06
Caveat Emptor  h2opolo | 02/17/06
Everybody's overlooking something  cavenewt | 02/17/06
Plus one more warning  tic swayback | 02/17/06
AT LAST!  s_gamgee | 02/17/06
WHERE IS MIKE???  s_gamgee | 02/17/06
no big deal  beafeater | 02/17/06
Just install Linux and be down with the commerical dweebs  Boot_Agnostic | 02/20/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Smartphones

  • Last year, many businesses deferred the purchase of new laptops in favor of smartphones, and why not? Offering phone, calendar, email, IM and Web access, they're arguably the most practical business tools. Check out the latest CNET Reviews of Blackberry devices for all the knowledge you need to make an intelligent choice.
  • Sleek. Thin. Light.
  • With its full keyboard and high-res screen, the BlackBerry® Curve™ 8900 is the perfect fit for your work and your life. Learn more
advertisement
Click Here