Trojan horse
A Trojan is infecting Mac users with a DNS Changer which redirects web traffic

Mac Trojan attack gathers steam

OS X attack being served up with PC malware

Written by Shaun Nichols in California

The OSX.RSPlug.A phishing Trojan that targets users of Apple's OS X operating system is much more widespread than originally believed, say experts.

David Marcus, security research and communications director at McAfee, told vnunet.com that the Trojan has spread to several sites that offer fake codecs.

Initial reports about the worm indicated that it was distributed as a codec on a porn website that was advertised in spam messages posted on Mac bulletin boards.

The attackers behind the sites crafted the malware to detect the visitor's operating system, allowing them to serve a tailor-made exploit and guarantee a higher rate of infections.

McAfee confirmed that, as reported earlier by Intego, the Trojan infects Mac users with a DNS Changer which redirects web traffic from legitimate sites to either phishing pages or sites that serve ads.

Although the Trojan is being distributed by more sites than originally believed, Marcus noted that there are still few actual infections being reported.

The Trojan is believed to be the first functional piece of malware to be released for OS X.

How it fares could determine whether other malware authors follow suit, according to Marcus. If the Trojan is successful at infecting machines, malware writers are bound to repeat the attack method.

"Ultimately, if the malware is successful and it can make the malware writer money on the Mac platform, it could catch on," he warned.

See also:

reader comments

related articles

Apple

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware 01 Nov 2007

 

Leopard roars to two million sales

Opening weekend best ever for MacOS 31 Oct 2007

Special Report: Apple iPhone

All the latest news on Apple's iPhone 18 Dec 2007

Leopard users unable to run Java 1.6

Developers claim Java 6 absent from new Apple OS 30 Oct 2007

Mozilla fixes Firefox flaws and welcomes Leopard

But still some issues running browser on latest Apple Mac OS 22 Oct 2007

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware 01 Nov 2007

vnunet.com analysis: Browser wars changing security game

Variety and competition bring new protections and new threats 18 Jun 2008

Mac security goes rogue

Spy Sheriff gang jumps platforms to OS X 16 Jan 2008

latest news

Red Hat a good fit for Qumranet

Open source behemoth opens up Windows opportunities with acquisition of virtualisation specialist 05 Sep 2008

Infor praises partners

Software vendor outlines its channel vision at second annual EMEA partner summit in Marbella 05 Sep 2008

Version One and Accurate launch university push

Software vendors link arms to create integrated document and financial management offering for universities 05 Sep 2008

Most commented stories

poll

Stormy times ahead for PBX?

Stormy times ahead for PBX?

Will the credit crunch affect PBX takeup?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories