First OS X trojan spotted – no need to panic just yet!

There is a great deal of chatter on TechMeme this morning because a trojan has emerged which infects Apple’s OS X!

The trojan is found in pornographic sites masquerading as a video codec.

It isn’t a huge threat because to become infected you need to go through several steps:

When the users arrive on one of the web sites, they see still photos from reputed porn videos, and if they click on the stills, thinking they can view the videos, they arrive on a web page that says the following:

Quicktime Player is unable to play movie file.
Please click here to download new version of codec.

After the page loads, a disk image (.dmg) file automatically downloads to the user’s Mac. If the user has checked Open “Safe” Files After Downloading in Safari’s General preferences (or similar settings in other browsers), the disk image will mount, and the installer package it contains will launch Installer. If not, and the user wishes to install this codec, they double-click the disk image to mount it, then double-click the package file, named install.pkg.

If the user then proceeds with installation, the Trojan horse installs; installation requires an administrator’s password, which grants the Trojan horse full root privileges. No video codec is installed, and if the user returns to the web site, they will simply come to the same page and receive a new download.

The trojan takes over the Mac’s DNS settings and from time-to-time re-directs the Mac to phishing or pornographic websites.

According to Intego, the security company reporting this trojan:

The best way to protect against this exploit is to run Intego VirusBarrier X4 with its virus definitions dated October 31,2007. Intego VirusBarrier X4 eradicates the malicious code and prevents the Trojan horse from being installed

Right – I can see why they are talking it up then! Stlll, if you do find you Mac bringing you to websites you didn’t ask for and you (or someone using your Mac – ahem!) have recently installed a video codec, maybe you should look into this further.

This is the first major malware reported which is specifically targeted at OS X since the operating system was released in 2001. I guess it is a sign of OS X’s increasing popularity.

4 thoughts on “First OS X trojan spotted – no need to panic just yet!”

  1. “The best way to protect against this exploit is to run Intego VirusBarrier”

    I’d suggest that the best way to protect against this exploit is not to download and install (as root) executable programs from porn sites.

    I’d imagine that the increased use of macs is a worry for anti-virus companies. Most Mac users don’t use anti-virus software so I bet all the AV companies want to convince mac users that they should be running their particular AV program.

  2. Looks like this was planned during development so the trojan was written by someone with development access or maybe even a sneaky competitor.
    🙂

    I have not installed virus software on any Mac for several years.

Comments are closed.