Researchers dissect world's first Mac botnet

Status
Not open for further replies.

Osiris

Golden Master
Messages
36,817
Location
Kentucky
Fresh research has shed new light on the world's first Mac OS X botnet, which causes infected machines to mount denial of service attacks.
Symantec researchers Mario Ballano Barcena and Alfredo Pesoli said the infections are the same ones described in this blog post from January.


In it, the blogger - a self-described designer and developer from Australia - said he awoke one morning to discover 100 per cent of his Mac laptop's resources were being consumed by a bunch of unfamiliar resources. After digging further, he found a foreign PHP script with root privileges was flooding an undisclosed website with data packets.

The botnet employs a peer-to-peer engine, encryption and a structure that allows it to dynamically adapt.
"The code indicates that, wherever possible, the author tried to use the most flexible and extendible approach when creating it - and therefore we would not be surprised to see a new, modified variant in the near future," the researchers write, according to ZDNet's Zero Day blog.
The botnet comes courtesy of two trojans dubbed OSX.Trojan.iServices.A and OSX.Trojan.iServices.B by Mac anti-virus provider Intego, which first documented them in January. The malware is surreptitiously included in copies of Apple's iWork 09 productivity suite and Adobe's Photoshop CS4 that are distributed on warez sites. Intego said three months ago more than 20,000 people had downloaded the rogue installers.
The Symantec research comes amid reports of a series of unpatched, actively-exploited holes in OS X and word that a researcher has figured out how to run shellcode on Apple's iPhone.
They are the latest reminder that Apple's growing market share - estimated to have reached about seven per cent in the fourth quarter of last year - hasn't been lost on malware authors. OS X users who have felt cavalier about installing unfamiliar titles on their machines have always done so at their peril, but that's especially true going forward.
According to the CBC, the Symantec researches add: "With malware authors showing an increasing interest in the Mac platform, we believe that more advanced [user interface] spoofing tricks may be seen in the future."

Researchers dissect world's first Mac botnet ? The Register
 
Eh, a lot of pc's are part of botnet's and people don't realize it. I do agree though, Mac will need to start doing some work on a good antvirus and such.
 
An you know what, this just goes to show security through obscurity is only good with you have a 7% total market shair.
 
Did you really think any OS could be virus proof?



Remember that while there are "professional" OS makers out there, Microsoft, Linux, MaxOSX, etc, there are also "Professional *******" out there, with the Hacking skills required to make anyone's life a living nightmare.

No matter how "secure" a Program, OS, or whatever is - there is always a way AROUND the security- mostly because security always has 'back doors' in case of emergencies. These back doors, if found by hackers, or leaked into the public by the team that created it - will be the downfall of the security, after all - if a building's front door is locked - you look to find another way in. Having the back door unlocked by a hacker or a leak in the program makes it really easy for anyone and anything to get inside and do whatever it wants to.


As posted in the other thread.. Mac's best hope is to quickly adapt to the circumstances and realize they cannot be so "worry free" with what they do. make backups, dont trust odd sites and stop looking at random pron sites or downloading illegal programs.

PC users have built up our resistance to these attacks, but for Macs.. it's going to be like War of the Worlds to them...
 
Status
Not open for further replies.
Back
Top Bottom