Ubuntu Forums Archive Viewer

Macs hit with BitTorrent-embedded malware attack

Archived thread 1051201 from Mac OSX. Markdown source: Mac_OSX/thread_1051201_Macs_hit_with_BitTorrent-embedded_malware_attack.md

Original URL About this archive
#1

http://tech.yahoo.com/blogs/null/117188

Macs hit with BitTorrent-embedded malware attack

Sun Jan 25, 2009 5:47PM EST

For years, Mac users have long been rightfully smug about their platform's relative immunity to virus and malware attacks, but it's inevitable that those days will eventually come to an end. (As the Mac gains in popularity, it also earns more attention from malware developers, and it's this lack of malware being actively developed, not some special, inherent security, that have really kept the Mac a "safe" platform for the time being.)

Now we're seeing one of the first moderately-sized exploits to take advantage of Mac users. The iServices.A Trojan horse is an attack being distributed via BitTorrent, where it's disguised as a bootleg copy of the new iWork 09. Once installed, the malware takes administrator access and connects to remote servers over the Internet, where it can be given additional instructions as the author commands, from installing additional malware to stealing information off the Mac in question. The malware creator can also take complete remote control of any compromised machine.

Security firm Intego said that just 20,000 machines had been infected as of January 21 but that the risk of ongoing infection was "serious, and users may face extremely serious consequences" if they are stricken with the malware.

Mac users are suggested to use common sense -- that is, don't try to download and installed pirated software -- and to update any antivirus definitions immediately. If you're a Mac user and aren't using security software, well, this might be a good time to start.

As well, if you've been hit by this piece of malware, a removal tool is available here. (Please note: I have not tested it.)

#2

Damn... That's what happens when you run as a root user...

#3

I don't agree with the article.

This kind of thing can happen on any OS in the world, including GNU/Linux.

You give full root access to software when you install it, so you better be sure that it's legit.

DrMega said it perfectly on nomgpp:

My car is secure. It has central locking, deadlocks, a steering wheel lock and an imobiliser. However if I don't look after the keys then all this means nothing.

If someone says to me: "I will give you 1 million GBP for nothing, I just need your car keys so I can put the case of money in your boot", would it be bad design on Vauxhall's part if they then took off with my car? Or would it be grand naivity and stupidity on my part?

#4

Um, don't steal software from dodgy sites and install it with full root access.

"it's this lack of malware being actively developed, not some special, inherent security, that have really kept the Mac a "safe" platform for the time being."

...or maybe a lack of stupid people using the platform. The more people use a particular OS the more likely that a percentage of them will be morons that install any code they come across with root access.

#5

billgoldberg said: I don't agree with the article.

This kind of thing can happen on any OS in the world, including GNU/Linux.

You give full root access to software when you install it, so you better be sure that it's legit.

DrMega said it perfectly on nomgpp:

Very good point.

A trojan is possible (and very easy) to create on any platform as they rely primarily on user's stupidity, not technical aspects of the host OS like viruses do.

#6

Wow.

Just wait, GNU/Linux or BSD is next.

#7

kaldor said: Wow.

Just wait, GNU/Linux or BSD is next. That would be easy to do. Just encrypt a shell script that has "sudo rm -rf /" in it. Then send it out, people run it with root access. That's basically what this is (although I doubt this just rms /)

#8

Tom Mann said: Damn... That's what happens when you run as a root user...

No, that's what happens when you run at any user level but choose to install a program which typically prompts for privilege escalation.

#9

marco123 said: Um, don't steal software from dodgy sites and install it with full root access.

+1!!! ;)

This story already made the rounds thru here BTW.....

#10

There hasn't been any *independent* verification of this attack either.

#11

You reap what you sew.

So it still takes (albeit indirect) physical access to the system for this bit of malware to have its way. Nice.

#12

I doubt it has hit 20,000 Macintosh users, but even if it had that's still a piddly little infection. That latest Windows malware whose name I keep forgetting, has hit 10 million computers. I think Storm hit 30 million or something like that before fading away.

#13

3rdalbum said: I doubt it has hit 20,000 Macintosh users, but even if it had that's still a piddly little infection. That latest Windows malware whose name I keep forgetting, has hit 10 million computers. I think Storm hit 30 million or something like that before fading away.

Remember, that is just what that company, who sells a mac antivirus says. No independent verification of it actually infecting anyones computer yet.

#14

Glad I just bought iWork 09 XD