Trojan horse
Experts claim that the Mac Trojan has been modified to produce more than 32 variants

Mutant Trojans threaten Mac users

Malware authors tweaking payload, say researchers

Written by Shaun Nichols

The malware authors behind last week's MacOS X Trojan attack are continuing development on the malicious downloads, security experts warn.

Mikko Hyppönen, chief research officer at F-Secure, said in a company blog that the Trojan had already been modified to produce more than 32 variants.

"The gang behind it seems serious about targeting Mac users as well as Windows users," wrote Hyppönen. "This is not likely to end any time soon."

The Mac Trojan was discovered last week by researchers at internet security firm Intego. The malware disguises itself as a codec file which is needed to view movies.

The code was thought to be hosted only on adult movie pages, but was soon discovered on a number of fake codec sites and in some cases was being delivered alongside Windows malware.

However, while F-Secure has warned users about the Trojan, another security executive is attempting to allay fears about the threat.

Alex Eckelberry, president of Sunbelt Software, said in a blog posting that the malicious payload in the Trojan may not be as serious as some believe.

The malware, known as DNSchanger, alters the victim's DNS server to allow the attacker to reroute website requests.

Intego reported that the Trojan could allow an attacker to hijack and redirect web requests for sites such as PayPal and eBay to phishing sites.

But Eckelberry maintains that the Trojan is not likely to redirect URL requests for major sites, and will affect users in a much more subtle way by redirecting such things as search queries to pages controlled by attackers.

"This Trojan is all about generating affiliate commissions by redirecting search results," he wrote. "So if you Google 'spyware', you will get search results that they want you to see."

See also:

reader comments

related articles

Trojan horse

Mac Trojan attack gathers steam

OS X attack being served up with PC malware 01 Nov 2007

 

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware 01 Nov 2007

Leopard roars to two million sales

Opening weekend best ever for MacOS 31 Oct 2007

Leopard users unable to run Java 1.6

Developers claim Java 6 absent from new Apple OS 30 Oct 2007

Expert warns of new Mac malware

Fake security app may be on the way 17 Oct 2008

Storm botnet connected to phishing ring

Experts fear hackers selling time on botnet 10 Jan 2008

Experts sound alarm on Silentbanker Trojan

More than 400 banks on malware hitlist 15 Jan 2008

latest news

Novell to shuffle EMEA executive pack

Linux vendor shifts partner programme responsibilities to marketing organisation 09 Jan 2009

Ballmer highlights aims for New Year

Ballmer announces Windows 7 beta and future alliances designed to improve information sharing 08 Jan 2009

Active Storage completes UK Jigsaw

Jigsaw unveiled as Raid vendor's first non-US Platinum partner as it launches in Europe 08 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation