Welcome | Sign In
TechNewsWorld.com
Hacks & Malware

The Quiet Little Pop of the Mac Security Bubble

Print Version
E-Mail Article
Reprints
The Quiet Little Pop of the Mac Security Bubble

Mac users don't necessarily have to break out in a cold sweat now that another Trojan has been found circulating in the wild, but if anyone's still relying on the OS X platform's mythic invulnerability to malware attacks, this is a wake-up call.


Learn How You Can Protect Your Virtual Datacenter
With Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™ infrastructure, you can mitigate risk and maximize the benefits of virtualization. Get the free eBook to learn how.

A Trojan targeting Mac computers in the wild used to be a rarity, but this type of malware is now turning up with alarming frequency. The latest Trojan is rudimentary, at best, although when coupled with a Mac platform vulnerability that came to light earlier this week, it could deliver an extra wallop.

The Trojan is masquerading as a program for Mac OS X called "PokerGame." A shell script encapsulated in an application, it is distributed in a 65 KB Zip archive; unzipped, it is 180 KB, according to Intego, one of the security firms that flagged it.

After it is downloaded, PokerGame activates an SSH tunnel and sends the user's name, along with the Internet protocol address of the Mac, to a server. It then asks for an administrator's password after displaying this dialog: "A corrupt preference file has been detected and must be repaired." When the user enters the password, the hacker gets remote access to the computer.

Hacking 101

All in all, this Trojan is a straightforward program -- both in the way it installs itself and in how it's executed.

"Years ago, we were seeing the same malware but designed for the PC," Wolfgang Kandek, CTO of Qualys, told MacNewsWorld.

It is a social engineering-designed hack attack at its most basic, in other words.

For that reason, Kandek is not too worried about the malware proliferating among Mac users, who tend to be a savvy IT user group anyway.

Doubling Up

It does have the potential to deliver an additional sting, though, if coupled with a vulnerability in Mac OS X that security firms identified earlier this week, Kandek noted. Specifically, "ARDAgent" within Mac OS X 10.4 and 10.5 can be invoked to execute arbitrary commands with root privileges via AppleScript.

"Then the virus becomes more dangerous, because it won't require the user to type in the password," explained Kandek.

It's likely that malware writers are already exploring this angle.

Root access gives full control, even to other user accounts on the same system, said Mary Landesman, senior security researcher at ScanSafe.

"However, to work, the attacker must be able to either establish a remote connection to the target machine or have local physical access," she told MacNewsWorld.

"In such cases, that means the attacker already effectively owns the machine, which has cast some doubt on the seriousness of this particular disclosure. However, an exploit for the vulnerability in conjunction with a socially engineered Trojan such as PokerGame would satisfy that restriction and could have serious consequences for the victim," Landesman concluded.

Waiting for the Day

Security researchers have been forecasting the day the Mac would become a major target for malware writers for several years now. Despite recent events and louder projections of doom, that day is not yet here.

"This was an immature piece of malware -- we saw this kind of thing many moons ago with Windows," Tyler Reguly, a security research engineer for nCircle told MacNewsWorld. "But going forward, as more people use Macs, we are going to see more and more malware for the Mac that is sophisticated and dangerous."

Some even say that the day of reckoning is at hand. "Malware has finally made Macs a destination of choice, since so many people are now using Macs -- and especially with the onset of the iPhone smartphone device," Christoph Alme, team leader with Secure Computing's antimalware team, told MacNewsWorld.

"It was only a matter of time," he remarked, "and I think we'll see many more attacks aimed at the Mac community the rest of this year and beyond."

With Mac's growing popularity, it is inevitable that scammers will seek to exploit the growing base of systems operated by users who have never had to worry before, said Andrew Klein, senior product marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales manager for SonicWall. But that is no longer the point.

The choice of the platform -- Mac versus PC -- is not the basis of a sound security policy, he told MacNewsWorld.

"The real answer for the home user is the same one adopted by most businesses: to think about security -- and, in this case, virus protection -- in layers. Most only think about protection on the system itself."


Print Version E-Mail Article Reprints More by Erika Morphy


Talkback: Join the Discussion.
What exactly is the *alarming* frequency?
pkrug
Posted 2008-06-27
I know no platform is invulnerable, but I am trying to remember when the last Mac Trojan came ...
Chicken Little
drpalmer
Posted 2008-06-26
The virus software folks need the business, windoze is currently implementing their own virus ...
A Trojan is NOT a Virus
ViewRoyal
Posted 2008-06-26
Geez, when are people going to realize that a Trojan horse is not a virus. ...
spoken like a true believer
bunGfrog
Posted 2008-06-26
While I would agree that the definitions of virus and trojan are dissimilar, the idea that ...
Ugh...
jeffsters
Posted 2008-06-26
Not since George Ou have I see the words Trojan and virus used so loosely and interchangeably to ...
Mythic.
jimstead
Posted 2008-06-26
Who said the Mac was "invulnerable"? Got any names?
The Quiet Little Pop of the Mac Security Bubble
machelp
Posted 2008-06-26
'Quiet Pop', indeed! Try 'non existent!' ...

Related News Alerts

Hacker Activate Alert | Search Archives

More by Erika Morphy

Report: iPad Will Propel Tablets Into Mainstream Use
February 08, 2010
Will Apple's iPad do for tablets what its iPod did for MP3 players? Quite possibly. The tablet market will grow quickly on the heels of the iPad's release, according to In-Stat, which forecasts 50 million of the devices will ship in 2014. Others are less optimistic, though. Notably, consumer interest in buying an iPad did not increase as a result of the product's unveiling, according to a Retrevo survey.
DoJ Re-Nixes Google's Settlement With Authors
February 05, 2010
The latest revision of the digital book settlement between Google and the Authors Guild is an improvement, but still not good enough, according to the DoJ. It may be that Google and the Authors Guild will decide to take their case to the judge, suggested CEI analyst Ryan Radia. "I don't think the [Justice] Department has fully appreciated that this project could benefit consumers."
Amazon's Touchco Buy Could Lead to Niftier Kindle
February 04, 2010
Amazon seems to be squirming now that Apple's iPad is official and being hailed as a "Kindle killer." Though the iPad is not yet available to purchase, the Kindle suddenly looks old school, with its black-and-white display and its button-pushing page turning functionality. Amazon's reported purchase of Touchco could help freshen up the Kindle, bringing touchscreen capabilities and perhaps more.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Free eBook: Secure Your Datacenter
Click here to download today.
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network