News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Apple/Macintosh
Average Rating:
Rate this article:  
New Mac Trojan Disables Security, Steals Passwords New Mac Trojan Disables Security, Steals Passwords
By Jennifer LeClaire
June 23, 2008 9:28AM

    Bookmark and Share
A Mac Trojan horse compiled as either an AppleScript called ASthtv05 or as an application bundle called AStht_v06 exploits a vulnerability in the Apple Remote Desktop agent. Sophos has labeled the Mac Trojan "OSX/Hovdy-A," and it's evidence that cybercriminals are increasingly interested in hacking into Apple, Inc.'s Mac computer.
 



The Macintosh platform is again under attack by malicious code writers. This time, it's a Trojan horse that could compromise machines running Mac OS X 10.4 or 10.5.

Antivirus firm SecureMac claims to have discovered multiple variants of a Trojan horse being distributed from a hacker Web site. The site hosts a discussion on distributing the Trojan horse through iChat and Limewire.

The Trojan, distributed as either a compiled AppleScript called ASthtv05 or as an application bundle called AStht_v06, exploits a recently discovered vulnerability with the Apple Remote Desktop agent. The ARD allows the Trojan to run as root.

According to SecureMac, the Trojan runs hidden on a Mac and allows a malicious user complete remote access. The Trojan can transmit system Relevant Products/Services and user passwords, and avoid detection by opening ports in the firewall and turning off system logging. The AppleScript version, SecureMac reported, can also log keystrokes, take pictures with the built-in Apple iSight camera, take screenshots, and turn on file sharing.

Fortifying a Mac

While it's true that hackers and malware authors target Macs far less frequently than Microsoft Relevant Products/Services Windows Relevant Products/Services PCs, that doesn't mean Mac users can disregard common sense in securing their computers, according to Carole Theriault, senior security consultant at Sophos.

"In the last 12 months we have seen growing evidence that cybercriminals -- although still focusing in the main on the Microsoft platform -- have shown an increase in interest in seeing if there is an opportunity to hack into Mac computers for financial gain," Theriault noted.

Although the problem is much smaller than on Windows, she added, Mac users would be wise to run an antivirus program, keep up with security patches, and exercise care about which programs they install.

The Threat Behind the Threat

Sophos has labeled the new Trojan "OSX/Hovdy-A." According to its monitoring service Relevant Products/Services, the prevalence is low but the danger is critical. In addition to opening ports in firewalls and starting the ARD, the Trojan will also attempt to install itself in the Library/Caches folder and perform several tasks, including deleting system log files, starting PHPShell and Web server Relevant Products/Services, disabling system updates, and disabling third-party security software.

Like many Windows attacks, this Mac Trojan relies on the user giving it permission to install. Using social-engineering techniques, the Trojan could be given disguises as varied as a game, a video, or a handy new utility.

"Sadly, many Mac users are just as willing as their Windows-based cousins to install a program without careful thought as to safety," Theriault said. "We are not witnessing a large-scale attack by this Trojan, but it is worrying to see yet more hackers turning their malevolent gaze to the Mac platform."
 

Tell Us What You Think
Your Comment:



Advertisement


 Apple/Macintosh
1.   Macworld Focuses on Mobile Apps
2.   Analysts Expect iPad Price To Drop
3.   iPad Blitz Yields Low Buying Plans
4.   With No Killer App, iPad Is a Hard Sell
5.   iPhone Location-Based Ads Banned


advertisement
With No Killer App, iPad Is a Hard SellWith No Killer App, iPad Is a Hard Sell
The iPad still needs to prove its worth.
Average Rating:
Reporters Invited To Apple EventReporters Invited To Apple Event
New tablet could be low-end MacBook.
Average Rating:
French Exec Confirms Apple TabletFrench Exec Confirms Apple Tablet
With a webcam and 3G connectivity.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.