On CBS Sports: British Open tournament highlights
BNET Business Network:
BNET
TechRepublic
ZDNet

By Anne Broache, News.com
Posted on ZDNet News: Feb 16, 2006 10:53:00 PM

A malicious program that could be the first Trojan in the wild to target Apple Computer's Mac OS X operating system has been discovered, security experts confirmed Thursday.

Apple and outside analysts said the program, referred to as Leap-A, is not a "virus" per se. Rather, it "requires a user to download the application and execute the resulting file," Apple said in a statement to CNET News.com. The company provided no further comment on the nature of the program.

The malicious software, which has also been dubbed OSX/Oompa-A and the Ooompa Loompa Trojan Horse by other security experts, appears to have spread minimally so far and has achieved low-level threat classifications from McAfee and Symantec.

But security experts cautioned Macintosh users to view the incident as a wake-up call that all operating systems have vulnerabilities.

"It's not really news as far as threats go," said Ray Wagner, a senior vice president in Gartner's information security group. "It is news because it targets OS X, and as far as I know, it's certainly the first OS X malicious content in the wild that's been noted at this point."

Classified as both a worm and a Trojan, Leap-A appears to have begun its movement earlier this week after it was posted at a forum for Mac-related rumors. The file appeared as an external link promising pre-release screenshots of the upcoming Mac OS X 10.5, also known as Leopard.

Leap-A, which appears to affect only the OS X 10.4 platform, spreads primarily via the Apple iChat instant-messaging program. The program forwards itself as a compressed file called "latestpics.tgz" to all the contacts on the infected user's buddy list each time the program starts up.

But it's up to the person to download the file, which shows up as an attachment to a conversation thread. If downloaded, the self-executable file masquerades with an icon typically reserved for image files but does not activate itself unless opened.

"It exhibits the same behavior as a Trojan in that it requires user interaction and a mass mailer in that it's going through the contact list of that particular iChat client," said Dean Turner, senior manager of Symantec Security Response. "And it's a worm because it's replicating on its own once the system has become infected."

An analysis by U.K.-based security firm Sophos said it attempts to infect recently used applications by overwriting the original application with a copy of the worm. According to Symantec, "files infected by OSX.Leap.A may be corrupted and may not run correctly."

A number of security companies--including Symantec, McAfee, Sophos and Intego--have released updated definitions to guard against the threat. Apple directed customers to a safety guide at its site and said it "always advises Macintosh users to only accept files from vendors and Web sites that they know and trust."

Andy McCue of Silicon.com contributed to this report.

  • Talkback
  • Most Recent of 97 Talkback(s)
wow
Hummm,
All I can say is that you must not see much in the way of file traffic?
I get them constantly.... (Read the rest)
Posted by: gtravis3 Posted on: 02/21/06 You are currently: Logged In | Log out
No no no! I was just kidding Boot_Agnostic   | 02/16/06
Many of the thirty-something viruses for OS9 were MacGeek2121   | 02/17/06
Porting is the key Boot_Agnostic   | 02/17/06
It's not possible Immanuel Tranz-Mischen   | 02/19/06
i read articles all over about this... doh123   | 02/16/06
Takes a lot of effort to catch this one... tic swayback   | 02/16/06
Something that could help Jeremy Chappell   | 02/16/06
what could help users... rafe01   | 02/17/06
I remember a Windows program... s_gamgee   | 02/17/06
for screenshots???? MacGeek2121   | 02/17/06
Sure does I'm Ye, the MS SHILL .   | 02/18/06
This is no big deal !!! I'm Ye, the MS SHILL .   | 02/18/06
err, does this show vulnerabilities? Jeremy Chappell   | 02/16/06
I'm confused NonZealot   | 02/16/06
Re: I'm confused leguirerj   | 02/16/06
This solely is a user hit not any OS hit RicD_   | 02/16/06
RE: This solely is a user hit not any OS hit Jeremy Chappell   | 02/16/06
RE: RE: This solely is a user hit 999ad@...   | 02/17/06
Can't patch stupidity Jeremy Chappell   | 02/16/06
no you're not.. rafe01   | 02/17/06
Amen, brother, amen EJHonda   | 02/17/06
Yes, however, this is nothing like Microsoft. olePigeon   | 02/17/06
You obviously know nothing about Windows NonZealot   | 02/17/06
I didn't say Windows didn't have those features. olePigeon   | 02/17/06
I agree, never said this was a virus NonZealot   | 02/17/06
Zealot b.d.hi   | 02/17/06
Typical Mac zealot response! (NT) NonZealot   | 02/17/06
You've got to be kidding I'm Ye, the MS SHILL .   | 02/18/06
Neither do you. Immanuel Tranz-Mischen   | 02/19/06
You just proved your ignorance NonZealot   | 02/20/06
No, I just proved YOUR ignorance. Immanuel Tranz-Mischen   | 02/20/06
Immanuel: If ignorance is bliss... NonZealot   | 02/20/06
Cute tic swayback   | 02/17/06
I'm a Mac user. There's no way OSX is completely invulnerable. MacGeek2121   | 02/17/06
I hope you're not stupid enough... Immanuel Tranz-Mischen   | 02/19/06
Yikes, I'm embarrassed for you NonZealot   | 02/20/06
Unlike you, I know better than to use Windows Immanuel Tranz-Mischen   | 02/20/06
A Fundamental Problem ITTech001   | 02/16/06
A Fundamental Problem Jeremy Chappell   | 02/16/06
true... rafe01   | 02/17/06
Process Audit and Rollback ITTech001   | 02/17/06
Hindsight gtravis3   | 02/20/06
Over and over again? Laff   | 02/20/06
wow gtravis3   | 02/21/06
Can't patch stupidity Jeremy Chappell   | 02/16/06
Dancing bunnies PB_z   | 02/16/06
re: Dancing bunnies Jeremy Chappell   | 02/16/06
you can tell if you look first... but look closer... doh123   | 02/17/06
But then ... ShadeTree   | 02/17/06
Watch and see tic swayback   | 02/17/06
If the implication of your statement ... ShadeTree   | 02/17/06
depends on the metrics woot!   | 02/17/06
Actually j.m.galvin   | 02/17/06
Let's look at the numbers tic swayback   | 02/17/06
Go to the Mac tech support sites s_gamgee   | 02/17/06
Can I guess? NonZealot   | 02/17/06
Actually there's two cults woot!   | 02/17/06
Very unlikely Rick_K   | 02/17/06
Impossible! John Zern   | 02/16/06
Message has been deleted. scottwilkins@...   | 02/17/06
At the risk of feeding the Troll... woot!   | 02/17/06
Ah, Narg, did you read the post? John Zern   | 02/19/06
Hmmmmm...I don't use iChat. Laff   | 02/16/06
so... rafe01   | 02/17/06
Theres a big different between doing something where Laff   | 02/17/06
So if I understand you correctly... NonZealot   | 02/17/06
Disadvantages? What disadvantages? Laff   | 02/17/06
The disadvantages of OSX Rick_K   | 02/17/06
Disadvantages?? djc1309@...   | 02/17/06
Clearly, the problem is... tic swayback   | 02/17/06
I'll kill him djc1309@...   | 02/17/06
malware vs os's jguyp725@...   | 02/17/06
Who does it really affect? Kid Icarus   | 02/17/06
Stoopid users... scottwilkins@...   | 02/17/06
Ummm, yeah, Kid Icarus   | 02/17/06
iChat is available only for Mac OS X I'm Ye, the MS SHILL .   | 02/18/06
I think j.m.galvin   | 02/17/06
Stoopid users are everywhere zmud   | 02/17/06
I agree 100% NonZealot   | 02/17/06
Fear of files tic swayback   | 02/17/06
Fear of file? NonZealot   | 02/17/06
Advantage tic swayback   | 02/17/06
A few more tic swayback   | 02/17/06
Advantages? NonZealot   | 02/17/06
Out of the box, baby! tic swayback   | 02/17/06
Fatal flaws? NonZealot   | 02/17/06
Windows advantage Rick_K   | 02/20/06
Poor poor Rick NonZealot   | 02/20/06
Not Even a Trojan Techscan   | 02/17/06
Easy test to pass tic swayback   | 02/17/06
Caveat Emptor h2opolo   | 02/17/06
Everybody's overlooking something cavenewt   | 02/17/06
Plus one more warning tic swayback   | 02/17/06
AT LAST! s_gamgee   | 02/17/06
WHERE IS MIKE??? s_gamgee   | 02/17/06
no big deal beafeater   | 02/17/06
Just install Linux and be down with the commerical dweebs Boot_Agnostic   | 02/20/06

What do you think?

advertisement
advertisement