Technology no image

Published on April 17th, 2012 | by Ramon Trotman

0

Two new Mac Trojans discovered: Wait, what?

Two new Mac Trojans discovered Wait, what

Fresh off the cleanup effort of a previous malware attack a few weeks ago, Apple’s beloved Mac OS seems to be under attack again.

The new Trojans come in two flavors, the first is a Java exploit. The Mac soldiers will be quick to point out apple has since shut down Java’s presence in the mac (unless enabled again by power users.) The second will come via some sort of word document. Again, the pundits will frown on you for opening random word documents.

None the less, watch yourselves out there Mac’ers, its getting crazy out there!

Both cases are variants on the same Trojan, called SabPub, Kaspersky Lab Expert Costin Raiu wrote on Securelist.

(See Related: Flashback Malware Puts Apple in Security Spotlight: Experts Weigh In)

The first variant is known as Backdoor.OSX.SabPub.a. Like Flashback, this new threat was likely spread through Java exploits on Websites, and allows for remote control of affected systems. It was created roughly one month ago.

Fortunately, this malware isn’t a threat to most users for a few reasons: It may have only been used in targeted attacks, Raiu wrote, with links to malicious Websites sent via e-mail, and the domain used to fetch instructions for infected Macs has since been shut down.

Credit: Sophos’ NakeSecurityFurthermore, Apple’s security update for Flashback helps render future Java-based attacks harmless. In addition to removing the Flashback malware, the update automatically deactivates the Java browser plug-in and Java Web Start if they remain unused for 35 days. Users must then manually re-enable Java when they encounter applets on a Web page or a Web Start application.

The second SabPub variant is old-school compared to its sibling. Instead of attacking through malicious Websites, it uses infected Microsoft Word documents as vector, distributed by e-mail.

Like the other SabPub variant, this one was used only in targeted attacks, possibly against Tibetan activists. So unless you’re working with a pro-Tibet organization–and you have a habit of opening suspicious Word documents–there’s little reason for alarm. At most, SabPub is more evidence that Macs aren’t immune to attacks—a point that Flashback already made perfectly clear.

Just for added effect, please refer to the video below.

 

 

source pcworld

Share this article


About the Author

Editor in Chief, self proclaimed technologist, hardcore gamer and all things in between!



0 comments
Sort: Newest | Oldest
Back to Top ↑
  • Latest Posts

    TTL Episode 33

    Top Posts + Pages


  • Check the archives




UA-22735936-1