On CBSSports.com: Mike Tyson's daughter dies in accident
BNET Business Network:
BNET
TechRepublic
ZDNet

By Matthew Broersma ZDNet.co.uk
Posted on ZDNet News: Nov 21, 2008 4:38:55 AM

Two pieces of malicious software affecting Apple's Mac OS X appeared this week: a Trojan horse with the ability to download and install malicious code of an attacker's choice, and a hacker tool for creating backdoors, according to security vendors.

The Trojan — called 'OSX.RSPlug.D' by Intego, the Mac security specialist that discovered the threat — is a variant on an older piece of malicious code but with a new installer, Intego said.

"It is a downloader, and it contacts a remote server to download the files it installs," Intego said in an advisory. "This means that, in the future, the downloader may be able to install payloads [other] than the one it currently installs."

In other respects the Trojan is similar to previous versions of RSPlug, which first surfaced in October 2007, Intego said. It installs a piece of malicious code known as DNSChanger, which routes the user's internet traffic through a malicious DNS server, leading users to phishing websites or pages displaying advertisements.

The Trojan is found on porn websites posing as a codec needed to play video files, a technique used to trick the user into downloading and installing it.

Intego said OSX.RSPlug.D has been widely confused with a separate threat publicized this week by several security firms. That threat is called OSX.TrojanKit.Malez by Intego and OSX.Lamzev.A by other vendors, including Symantec and Trend Micro.

OSX.Lamzev.A is a hacker tool designed primarily to allow attackers to install backdoors in a user's system, according to Intego. However, the company dismissed the tool as a serious threat because a potential hacker has to have physical access to a system to install the backdoor.

"Unlike true malware and Trojan horses, OSX.TrojanKit.Malez requires that a hacker already have access to a Mac in order to install the code," Intego stated.

Other antivirus vendors noted that Lamzev could be disguised as a piece of legitimate software and used to trick users into creating the backdoor themselves.

Lamzev is not related to RSPlug, despite several high-profile reports confounding the two, Intego emphasized. "This hacker tool has nothing to do with the RSPlug Trojan horse," Intego stated.

Security vendors have long warned that the Mac platform is not as secure as some users might like to believe. Apple had not responded to a request for comment at the time of publication.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 346 Talkback(s)
Are you actually trying to deny
That you're a troll? When you can't even talk maturely
instead of just randomly trying to insult people? Good
one.... (Read the rest)
Posted by: AzuMao Posted on: 12/07/08 You are currently: a Guest | | Terms of Use
Stupid Users  Pascal117 | 11/21/08
Sounds familiar...  daMan25 | 11/21/08
Actually  AzuMao | 11/24/08
Do you lack knowledge or are you just a troll? n/t  notsofast | 11/24/08
No, but you're clearly a troll.  AzuMao | 11/25/08
Right...  tikigawd | 11/25/08
Okay  AzuMao | 11/25/08
Funny...  tikigawd | 11/26/08
Not Funny....!  Rasheedalh | 11/26/08
Enjoy your delusional reality.  AzuMao | 11/26/08
@Rasheedalh  tikigawd | 12/04/08
@AzuMao: Oh, I see...  tikigawd | 12/04/08
That is funny  mdemuth | 11/21/08
Yep.  kozmcrae | 11/23/08
Yes  ghost_ghost | 11/25/08
You would have to discount...  DevJonny | 11/28/08
Yes, Microsoft have earned their reputation  AzuMao | 11/28/08
Hmmmm  JHPArizona@... | 12/04/08
No  AzuMao | 11/24/08
Wrong!!!!  mrlinux | 11/25/08
Didn't know I had to explicitly mention that  AzuMao | 11/26/08
And here  ShadowGIATL | 11/21/08
VLC for Mac is great for porn!  Dan the Digital Dog | 11/22/08
VLC is the best for porn!  Kiamors | 11/24/08
And the best part is, it also lets you get your pr0n in HD! 8-}  nix_hed | 11/24/08
not always stupid users - backdoors are sometimes used  Clewin | 11/24/08
I think it's funny...  nix_hed | 11/24/08
And the backdoor got installed to begin with because..  AzuMao | 11/25/08
Stop the FUD, read the comment properly (nt)  nDuDut | 11/25/08
You read it properly.  AzuMao | 11/26/08
Gullable Users  chromeronin | 11/24/08
Well Duh!  notsofast | 11/24/08
Yes they are......  JHPArizona@... | 12/04/08
OMG!!!! A big Mac attack!  ddmattison | 11/21/08
Old news  U53r | 11/21/08
Wrong fruit  ddmattison | 11/21/08
Maybe...  ShadowGIATL | 11/21/08
Of course...  FanaticGeek | 11/22/08
Yeah, I regularly let complete strangers...  914four | 11/24/08
I really hope...  Leans_To_Center | 11/24/08
...ugh  Metronome49 | 11/21/08
So we keep hearing. Yet no prove is ever offered.  ye | 11/21/08
True, and here's the proof  FanaticGeek | 11/22/08
Add on Programs  brendan@... | 11/24/08
Think you missed something here...  scpredmage | 11/24/08
Let's think about this, though...  nix_hed | 11/24/08
re: Let's think about this, though...  rtk | 11/25/08
Or it was...  AzuMao | 11/25/08
You've actually done a pretty good  alaniane@... | 12/04/08
You sure about that?  AzuMao | 12/05/08
Not quite ...  de-void | 11/21/08
More to the point...  ShadowGIATL | 11/21/08
Wasn't a bug in the latest ubuntu Kernel announced a week or 2 ago?  notsofast | 11/24/08
Nope.  AzuMao | 11/25/08
WiFi hacks will afect any OS...  DevJonny | 11/28/08
The aim  AzuMao | 11/28/08
A famous MIT buffer overrun  alaniane@... | 12/04/08
Okay?  AzuMao | 12/05/08
Right on!  FanaticGeek | 11/22/08
Yes, I agree, but...  FanaticGeek | 11/22/08
The first step to getting better...  ShadowGIATL | 11/23/08
The thing with Mac VS PC...  nix_hed | 11/24/08
But this isn't an imperfection.  AzuMao | 11/25/08
Some mistruths here  jimfrost | 11/24/08
Amen!  914four | 11/24/08
Amen, Again.  PMC-CON | 11/24/08
Perfect  mars3132@... | 11/25/08
At last someone seeing sense...  DevJonny | 11/28/08
Fanboys?  UncleVic | 11/24/08
Not running...  arminw | 11/24/08
you must of course be speaking about  rtk | 11/25/08
I agree, and I am a Mac User....  akaralia | 11/24/08
Except  AzuMao | 11/24/08
no matter how many times you make the claim  rtk | 11/25/08
If 10 days = 10 years  AzuMao | 11/25/08
lol  rtk | 11/26/08
Nope  AzuMao | 11/26/08
Please can you still answer the question...  DevJonny | 11/28/08
Do you actually want a list? Or just trying to be annoying?  AzuMao | 11/28/08
no list required  rtk | 11/28/08
Actually  AzuMao | 11/29/08
re: actually  rtk | 12/01/08
You're the one going off topic.  AzuMao | 12/03/08
I looked all over  rtk | 12/03/08
If you say so.  AzuMao | 12/04/08
I love flame postings grin  nix_hed | 11/24/08
Adrian will blame Bill Gates.  Feldwebel Wolfenstool | 11/21/08
No, he'll blame Ballmer and the MBU wink  nix_hed | 11/24/08
Trojan  BreadintheBone | 11/21/08
MyDoom  rpmyers1 | 11/21/08
Morons are on all platforms  rag@... | 11/21/08
Exactly  rpmyers1 | 11/21/08
The first widespread viruses were for Macs  PMC-CON | 11/24/08
And the very first computer virus was on the Apple II platform.  nix_hed | 11/24/08
So far so good.....  James Quinn | 11/21/08
You are very confused here Jimbo.  xuniL_z | 11/21/08
You obviously know nothing about Mac OS X  GoPower | 11/21/08
Unfortunately, I have to support one.  xuniL_z | 11/21/08
Woah! woah! Hold on a sec  hurler1348@... | 11/24/08
We'll wait until you learn more...  tem.digital | 11/25/08
about accusations of stupidity.  rtk | 11/25/08
Amazing !  Jkirk3279 | 11/30/08
He banged his thick skull on it to often.  AzuMao | 12/01/08
Read and learn  GoPower | 11/21/08
*Pop*  Sleeper Service | 11/22/08
Misconception time again...  rag@... | 11/21/08
lol  Badgered | 11/21/08
Better a Wintard than an iTard  mikefarinha | 11/21/08
Oh, come on!  rtk | 11/21/08
So the Mac OS cannot run applications?  logicearth@... | 11/21/08
The long and the short of it...  Wolfie2K3 | 11/22/08
You mean harmless ones? OK.  James Quinn | 11/24/08
It's probably best......  xuniL_z | 11/24/08
K..... but seriously what harm has been done?  James Quinn | 11/25/08
Sorry, but that argument is ridiculous  eMJayy | 11/21/08
Quicktime Will Ultimately Be The Major Mac Compromise Vector  PMC-CON | 11/24/08
That's why Apple's overhauling the entire QT platform in time for 10.6.  nix_hed | 11/24/08
I feel so... enlightened!  tem.digital | 11/25/08
It has everything to do with how the OS is designed.  tracy anne | 11/25/08
neither are you a windows user  rtk | 11/25/08
[winking]  brian ansorge | 11/28/08
yup  rtk | 12/01/08
Looks like YOU'RE the one with no first-hand Vista experience.  AzuMao | 11/29/08
Oh! Hold your horses....  akaralia | 11/24/08
Jimmy, Jimmy...  nix_hed | 11/24/08
Doesn't malware have to do something mal?  James Quinn | 11/25/08
Only on Tuesdays  tracy anne | 11/25/08
If everything you can download and run (on purpose) is malware  AzuMao | 11/25/08
There is a difference in a program  alaniane@... | 12/04/08
That would be true if..  AzuMao | 12/05/08
RE: Mac OS X targeted by Trojan and backdoor tool  jeremychappell | 11/21/08
Nice Spin!(nt)  ShadeTree | 11/21/08
Say That Again?  mikefarinha | 11/21/08
Oh! well Hilda scratch this one of the list..  akaralia | 11/24/08
And how is this different from Windows?  ye | 11/21/08
I see... that's why Vista is still junk  Dan the Digital Dog | 11/22/08
Or...  mikefarinha | 11/22/08
This functionality has been present from day one.  ye | 11/23/08
Your post is junk.  tem.digital | 11/25/08
WOW  rjohn05 | 11/21/08
RE: Mac OS X targeted by Trojan and backdoor tool  jeremychappell | 11/21/08
How does Mac OS X protect users?  jeremychappell | 11/21/08
Not enough  rpmyers1 | 11/21/08
That would be true for Windows as well, but unlike Windows...  olePigeon | 11/21/08
Easy to clean  rpmyers1 | 11/21/08
Administrative users can modify other users files in OS X.  ye | 11/21/08
You're Right There  DannyO_0x98 | 11/21/08
No privileged elevation required.  ye | 11/22/08
Yes and no.  nix_hed | 11/24/08
The problem is  AzuMao | 11/25/08
except  rtk | 11/26/08
Actually  AzuMao | 11/26/08
Actually,  rtk | 11/28/08
Weird  AzuMao | 11/29/08
North America  rtk | 12/01/08
Looks like you gave up.  AzuMao | 12/03/08
Oh, don't count on it.  rtk | 12/03/08
Do you actually  AzuMao | 12/04/08
88%, up from 84% of user sessions have UAC enabled  rtk | 12/04/08
Uh-huh  AzuMao | 12/05/08
Yup  rtk | 12/05/08