Apple
Malware authors have spammed Mac forums with links for pornographic websites

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware

Written by Shaun Nichols in California

Security vendor Intego claims to have uncovered a new Trojan attack that targets Apple's OS X operating system.

The OSX.RSPlug.A Trojan disguises itself as a video codec that offers access to a pornographic video.

Intego said that malware authors have spammed Mac forums with links for pornographic websites hosting the malware.

Users attempting to install the codec receive a piece of malware classified as a 'DNS Changer' which modifies the way OS X handles the DNS requests used to link numerical IP addresses to web URLs.

The tool allows the attackers to redirect web traffic. Users attempting to visit PayPal, eBay or certain banking sites, for instance, will be directed to a phishing website instead.

If confirmed, the Trojan would be the first piece of truly malicious software to be targeted at OS X.

Researchers have previously developed OS X attacks and exploits, but these were largely proof-of-concept attacks that lacked a malicious payload.

While security experts agree that such malware would pose a very serious threat to Mac users, it remains unclear just how far the reported Trojan has spread.

Early on Wednesday morning, representatives for McAfee, Symantec and Trend Micro told vnunet .com that their researchers had been unable to find the Trojan in the wild or obtain a sample from Intego.

A spokesperson for Symantec suggested that Intego "has a tendency to over-hype things".

UPDATE: McAfee has confirmed the existence of the OSX.RSPlug.A Trojan and reported that it is spreading through fake codec sites in addition to the porn website.

See also:

reader comments

related articles

Trojan horse

Mac Trojan attack gathers steam

OS X attack being served up with PC malware 01 Nov 2007

 

Leopard roars to two million sales

Opening weekend best ever for MacOS 31 Oct 2007

Special Report: Apple iPhone

All the latest news on Apple's iPhone 18 Dec 2007

Leopard users unable to run Java 1.6

Developers claim Java 6 absent from new Apple OS 30 Oct 2007

Mutant Trojans threaten Mac users

Malware authors tweaking payload, say researchers 08 Nov 2007

Mac Trojan attack gathers steam

OS X attack being served up with PC malware 01 Nov 2007

Twin Trojans attack Macs

Malware spotted in the wild 21 Jun 2008

latest news

Channel M&A set to soar

Research house forecasts surge in bolt-on acquisitions as impact of credit crunch hits home 14 Oct 2008

HDS accelerates SME push

Storage vendor tasks Bell and Zycko with taking new midrange storage proposition to resellers 14 Oct 2008

Comms-care mourns loss of managing director

Staff vow to continue business as usual in memory of Scott Yates who passed away at the weekend 13 Oct 2008

poll

Education gap?

Education gap?

Is there still business up for grabs in the education space?

Previous poll results

Vendor Q&A Session: Rick Wallis, NEC Computers

Vendor Q&A Session: Rick Wallis, NEC Computers

During this Q&A session Rick Wallis, UK Sales Director at NEC Computers, talks about the firm’s reasons for committing to a 100 per cent channel strategy

In The Studio with CRN: Dave Poskett, HP

CRN TV catches up with Dave Poskett, director of Solutions Partner Organisation for the UK & Ireland at HP

events

Channel Awards logo

CRN Channel Awards 2008

The Channel Awards recognise excellence and exceptional performance from businesses and individuals in the UK technology channel

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation