Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 01-11-2007, 08:14 PM   #1 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Phishing Trojan targets Mac OS X

Security vendor Intego claims to have uncovered a new Trojan attack that targets Apple's OS X operating system.

The OSX.RSPlug.A Trojan disguises itself as a video codec that offers access to a pornographic video.

Intego said that malware authors have spammed Mac forums with links for pornographic websites hosting the malware.

More info here http://www.vnunet.com/vnunet/news/22...trojan-targets
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP

Last edited by anandk; 01-11-2007 at 08:22 PM.
anandk is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 01-11-2007, 09:13 PM   #2 (permalink)
Human Spambot
 
aryayush's Avatar
 
Join Date: May 2005
Location: Noida
Posts: 5,593
Unhappy New Trojan Horse targets Mac users

New Trojan Horse targets Mac users
By Jim Dalrymple

Security research company Intego on Monday issued a security alert about a new Trojan Horse called OSX.RSPlug.A that specifically targets Mac users. The Trojan is a form of DNSChanger that changes the Mac’s Domain Name Server (DNS) address.

According to Intego, the Trojan has been found on several pornographic Web sites. When trying to view a movie, the user is told that “Quicktime Player is unable to play movie file. Please click here to download new version of codec.” Read more...

[Via Macworld]
__________________________________________________ _____________

Trojan Horse warning: What you need to know
How to detect—and remove—the OSX.RSPlug.A Trojan Horse

By Rob Griffiths

As you may have read, a new piece of OS X malware has been discovered. Intego has named this malware the OSX.RSPlug.A Trojan Horse. Note that this malware is not a virus—it can’t self-propagate from one machine to another. It is, however, definitely malicious, and it’s packaged in a well-designed trojan horse wrapper.

Your machine could be infected if you’ve recently gone looking for some, um, less-than-flattering pictures of Britney Spears. Thinking you’ve found what you’re looking for, you click a video to watch it, only to see a message stating that your machine lacks the necessary codec. A disk image will then start downloading, and (depending on the settings on your machine) may then mount and launch an installer which asks for your admin password.

Rule #1: Do not install software from untrusted sources, especially if that software comes as an installer package and requests your administrator’s password! However, if you do proceed to run the installer, here’s what will happen:
  • Sorry, but you won’t be able to watch those videos, as no codec was installed.
  • Your DNS will be changed to point to malicious DNS machines. What this means is that even if you type www.apple.com in your browser’s URL area, you may be taken there, to a phishing “clone” of that site, or to another site completely—such as a porn site. Where you wind up depends solely on how the malicious DNS machines are configured. If you consider ebay.com or paypal.com, for instance, the consequences may be dire.
  • A cron job (scheduled task) will run every minute to restore the malicious DNS info, in case you change it.
This is really bad. Really. And even though it’s targeted at porn surfers today, the malware could easily be associated with anything else, like a new viral video site, or a site that purports to show commercials from the upcoming Super Bowl. Because this thing may spread to other such sites, we spent some time investigating the trojan—no, not its source sites!—to determine the best way to tell if you’ve been infected, as well as how to remove the software if you do find it on your machine. Read more...

[Via Macworld]
__________________
Miss me already? See you on Penned Thoughts [http://aayush.me] then. Adios!
aryayush is offline  
Old 01-11-2007, 11:24 PM   #3 (permalink)
!! RecuZant By Birth !!
 
naveen_reloaded's Avatar
 
Join Date: May 2005
Location: In Everyone`s Heart
Posts: 2,985
Default Re: Phishing Trojan targets Mac OS X

It all starts like this.be ready to see more like this.fun begins from here.

Aaa scanning finished...2 trojan in my xp...move to quarantine:..
Sh.t i forgot to update my definition...

Downloading new def.
Scan again.
6 found..
Move again..

Cycle continues
__________________
Know My Thoughts..
Visit my Blog @ www.Urssiva.com
Visit My Tech Blog @ www.CloudTechnica.com
naveen_reloaded is offline  
Old 01-11-2007, 11:30 PM   #4 (permalink)
 Macboy
 
goobimama's Avatar
 
Join Date: Sep 2004
Location: Goa
Posts: 4,486
Default Re: Phishing Trojan targets Mac OS X

Quote:
launch an installer which asks for your admin password.
Yeah!
__________________
I'm like a bird...
goobimama is offline  
Old 01-11-2007, 11:39 PM   #5 (permalink)
Human Spambot
 
aryayush's Avatar
 
Join Date: May 2005
Location: Noida
Posts: 5,593
Default Re: Phishing Trojan targets Mac OS X

Quote:
Originally Posted by naveen_reloaded
It all starts like this.be ready to see more like this.fun begins from here.
Actually, if the whole Mac community goes up in arms within mere minutes of a single trojan being found, I think it is pretty darn difficult for them to spread.

I may be wrong though.
__________________
Miss me already? See you on Penned Thoughts [http://aayush.me] then. Adios!
aryayush is offline  
Old 01-11-2007, 11:54 PM   #6 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: Phishing Trojan targets Mac OS X

what he meant was.. 'this is just the starting'

but anyway this may be nothing just a rare case...

macs will not have much viruses bcos:

1) they are basically linux
2) most virus writers want to infect/promote stuff to massive number of systems and in the case of mac the massive number is not massive enough
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|
DigitalDude is offline  
Old 02-11-2007, 12:05 AM   #7 (permalink)
 Macboy
 
goobimama's Avatar
 
Join Date: Sep 2004
Location: Goa
Posts: 4,486
Default Re: Phishing Trojan targets Mac OS X

2) Would you like to be the creator of the 19842915th virus for Windows, or the first virus for a mac?
__________________
I'm like a bird...
goobimama is offline  
Old 02-11-2007, 12:22 AM   #8 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: Phishing Trojan targets Mac OS X

^^^^^

both the positions have been taken well before
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|
DigitalDude is offline  
Old 02-11-2007, 12:25 AM   #9 (permalink)
Human Spambot
 
aryayush's Avatar
 
Join Date: May 2005
Location: Noida
Posts: 5,593
Default Re: Phishing Trojan targets Mac OS X

The second one has been "taken" (a better word would be "conquered" or "achieved") today.
__________________
Miss me already? See you on Penned Thoughts [http://aayush.me] then. Adios!
aryayush is offline  
Old 02-11-2007, 12:42 AM   #10 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: Phishing Trojan targets Mac OS X

^^^^

not today

http://www.macrumors.com/2006/02/16/...w-os-x-trojan/
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|
DigitalDude is offline  
Old 02-11-2007, 12:46 AM   #11 (permalink)
 Macboy
 
goobimama's Avatar
 
Join Date: Sep 2004
Location: Goa
Posts: 4,486
Default Re: Phishing Trojan targets Mac OS X

I don't consider something that requires me to enter my admin/password as a threat.
__________________
I'm like a bird...
goobimama is offline  
Old 02-11-2007, 09:57 AM   #12 (permalink)
The G-Axe Effect
 
gxsaurav's Avatar
 
Join Date: Jan 2007
Location: New Delhi
Posts: 5,579
Default Re: Phishing Trojan targets Mac OS X

Quote:
Originally Posted by goobimama
I don't consider something that requires me to enter my admin/password as a threat.
We also don't consider it a threat which asks us for permission to install itself (UAC)
__________________
Graphics & Web Designer - SlideShare
Portfolio & Blog : http://gxsaurav.com
gxsaurav is offline  
Old 02-11-2007, 11:26 AM   #13 (permalink)
!! RecuZant By Birth !!
 
naveen_reloaded's Avatar
 
Join Date: May 2005
Location: In Everyone`s Heart
Posts: 2,985
Default Re: Phishing Trojan targets Mac OS X

Rightly said brother. But many dont realise UAC's potential to stop attacks like this.personally i haven disabled it.
__________________
Know My Thoughts..
Visit my Blog @ www.Urssiva.com
Visit My Tech Blog @ www.CloudTechnica.com
naveen_reloaded is offline  
Old 02-11-2007, 01:17 PM   #14 (permalink)
ax3
Cool as a CUCUMBAR ! ! !
 
ax3's Avatar
 
Join Date: Dec 2003
Posts: 5,002
Default Re: Phishing Trojan targets Mac OS X

so all OS`s r can b attacked & have security issues /........
__________________
... W H O T ...
ax3 is offline  
Old 02-11-2007, 07:03 PM   #15 (permalink)
Human Spambot
 
aryayush's Avatar
 
Join Date: May 2005
Location: Noida
Posts: 5,593
Default Re: Phishing Trojan targets Mac OS X

Quote:
Originally Posted by goobimama
I don't consider something that requires me to enter my admin/password as a threat.
Well, it is a codec and all codecs need the administrator username and password. This is a virus, man.
__________________
Miss me already? See you on Penned Thoughts [http://aayush.me] then. Adios!
aryayush is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
TROJAN VULNERABILITY - Keylogging Trojan Dodges Anti-virus Detection techtronic Technology News 1 26-05-2007 03:10 PM


All times are GMT +5.5. The time now is 06:22 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2