Announcement

Collapse
No announcement yet.

The impossible has happened: MacOS X worm/malware spreads via iChat

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • The impossible has happened: MacOS X worm/malware spreads via iChat



    New malware targets OS X chat users
    By Anne Broache
    Staff Writer, CNET News.com
    Published: February 16, 2006, 2:53 PM PST
    Tell us what you think about this storyTalkBack E-mail this story to a friendE-mail View this story formatted for printingPrint

    A malicious program that could be the first Trojan in the wild to target Apple Computer's Mac OS X operating system has been discovered, security experts confirmed Thursday.

    Apple and outside analysts said the program, referred to as Leap-A, is not a "virus," per se. Rather, it "requires a user to download the application and execute the resulting file," Apple said in a statement to CNET News.com. The company provided no further comment on the nature of the program.

    The malicious software, which has also been dubbed OSX/Oompa-A and the Ooompa Loompa Trojan Horse by other security experts, appears to have spread minimally so far and has achieved low-level threat classifications from McAfee and Symantec.

    But security experts cautioned Macintosh users to view the incident as a wake-up call that all operating systems have vulnerabilities.

    "It's not really news as far as threats go," said Ray Wagner, a senior vice president in Gartner's information security group. "It is news because it targets OS X, and as far as I know, it's certainly the first OS X malicious content in the wild that's been noted at this point."

    Classified as both a worm and a Trojan, Leap-A appears to have begun its movement earlier this week after it was posted at a forum for Mac-related rumors. The file appeared as an external link promising pre-release screenshots of the upcoming Mac OS X 10.5, also known as Leopard.

    Leap-A, which appears to affect only the OS X 10.4 platform, spreads primarily via the Apple iChat instant-messaging program. The program forwards itself as a compressed file called "latestpics.tgz" to all the contacts on the infected user's buddy list each time the program starts up.

    But it's up to the person to download the file, which shows up as an attachment to a conversation thread. If downloaded, the self-executable file masquerades with an icon typically reserved for image files but does not activate itself unless opened.
    In other news:

    * Newsmaker: Ending Redmond's identity crisis
    * Reporter's notebook: High tech's trip to toyland
    * RSA: Consumer trust and the government's thrust
    * Images: A flying car in every garage?
    * Roundup: Capitol Hill's fury on China

    "It exhibits the same behavior as a Trojan in that it requires user interaction and a mass mailer in that it's going through the contact list of that particular iChat client," said Dean Turner, senior manager of Symantec Security Response. "And it's a worm because it's replicating on its own once the system has become infected."

    An analysis by U.K.-based security firm Sophos said it attempts to infect recently used applications by overwriting the original application with a copy of the worm. According to Symantec, "files infected by OSX.Leap.A may be corrupted and may not run correctly."

    A number of security companies--including Symantec, McAfee, Sophos and Intego--have released updated definitions to guard against the threat. Apple directed customers to a safety guide at its site and said it "always advises Macintosh users to only accept files from vendors and Web sites that they know and trust."
    How is this possible? MacOS X is invulnerable to malware, spyware, trojans, adware, worms, and viruses. Clearly this must be a mistake in reporting!
    "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
    Ben Kenobi: "That means I'm doing something right. "

  • #2
    “I give you a new commandment, that you love one another. Just as I have loved you, you also should love one another. By this everyone will know that you are my disciples, if you have love for one another.”
    - John 13:34-35 (NRSV)

    Comment


    • #3
      Meanwhile, Microsoft is too busy patching its patches to come up with an OS secure enough so it makes the news when an insignificant trojan tries to infect its users.

      I frequent the forums and read the thread used to try to spread this, and like the article says, this is a minor event with minimal chance of doing any harm.

      Comment


      • #4
        Originally posted by Verto
        Meanwhile, Microsoft is too busy patching its patches to come up with an OS secure enough so it makes the news when an insignificant trojan tries to infect its users.

        I frequent the forums and read the thread used to try to spread this, and like the article says, this is a minor event with minimal chance of doing any harm.
        And as I've said repeatedly, the #1 factor preventing mass OS X viruses/worms/trojans is the small marketshare, not because of the design of the OS. The more popular the product is, the more people you have trying to break it and exploit the weaknesses.

        MacOS X has had dozens of security vulnerablities last year as well (comparable to Microsoft). the problem is, most Windows users have antivirus/antispyware utilities now, while MacOS X users are as good as naked. Coupled with overconfidence in their security, it's a recipe for disaster. This particular worm is rather harmless, but look at what it does -- it successfully tricks users into running a program.

        This means it can do anything a user can, including deleting all files a users' permissions permits (including most of their documents I'd assume). If paired with another exploit for raising the privledge (there were several last year for MacOS X), it can cause havoc across the entire computer.

        The fact that it doesn't tells me that the author is mostly someone who wants to let MacOS X users know they aren't safe by design. It could have been a lot worse. In fact, I think there will be some copycats using the same iChat vulnerability to release some truly malicious software soon.
        "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
        Ben Kenobi: "That means I'm doing something right. "

        Comment


        • #5
          Similarly, iTunes released version 6.0.3 last night addressing bugs and security issues. Apple doesn't even know how to make a patch, apparently -- to upgrade you have to download the 30MB+ iTunes/Quicktime combo pack and reinstall both over again.
          "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
          Ben Kenobi: "That means I'm doing something right. "

          Comment


          • #6
            I didn't have to

            Of course, it's hard to compare how Microsoft would handle that kind of situation, since they just decided to stop WMP for Mac, and didn't even bother to update to WMP10 before doing so.

            Comment


            • #7
              Originally posted by Verto
              I didn't have to

              Of course, it's hard to compare how Microsoft would handle that kind of situation, since they just decided to stop WMP for Mac, and didn't even bother to update to WMP10 before doing so.
              Because the usage of WMP on the Mac was abysmal once iTunes came out. Same with IE for Mac after Safari came out. Apple users flock to first-party programs.

              Apple is scaring off third parties. They did the same to Adobe with Premiere, didn't they?
              "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
              Ben Kenobi: "That means I'm doing something right. "

              Comment


              • #8
                so what were you doing last weekend

                JM
                Jon Miller-
                I AM.CANADIAN
                GENERATION 35: The first time you see this, copy it into your sig on any forum and add 1 to the generation. Social experiment.

                Comment


                • #9
                  Thank you Asher - yet another ROFLMAO

                  You compare a deliberate download and execution of a program with visiting a web page with IE and having your PC destroyed - are you for real ?
                  With or without religion, you would have good people doing good things and evil people doing evil things. But for good people to do evil things, that takes religion.

                  Steven Weinberg

                  Comment


                  • #10
                    "I have been reading up on the universe and have come to the conclusion that the universe is a good thing." -- Dissident
                    "I never had the need to have a boner." -- Dissident
                    "I have never cut off my penis when I was upset over a girl." -- Dis

                    Comment


                    • #11
                      Originally posted by BlackCat
                      Thank you Asher - yet another ROFLMAO

                      You compare a deliberate download and execution of a program with visiting a web page with IE and having your PC destroyed - are you for real ?


                      What do you think most viruses on the PC are?!
                      “I give you a new commandment, that you love one another. Just as I have loved you, you also should love one another. By this everyone will know that you are my disciples, if you have love for one another.”
                      - John 13:34-35 (NRSV)

                      Comment


                      • #12
                        Originally posted by Imran Siddiqui




                        What do you think most viruses on the PC are?!
                        Windows
                        With or without religion, you would have good people doing good things and evil people doing evil things. But for good people to do evil things, that takes religion.

                        Steven Weinberg

                        Comment


                        • #13
                          Originally posted by Imran Siddiqui


                          What do you think most viruses on the PC are?!
                          No kidding.

                          BlackCat continues to amaze me.
                          "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                          Ben Kenobi: "That means I'm doing something right. "

                          Comment


                          • #14
                            @Imran : there are of course no difference between downloading and executing a program wether it's mac or windows (or any other OS). Problem is that exploder have been able to introduce viruses by just visiting a website wich is a totally different thing.
                            With or without religion, you would have good people doing good things and evil people doing evil things. But for good people to do evil things, that takes religion.

                            Steven Weinberg

                            Comment


                            • #15
                              Originally posted by Asher

                              No kidding.

                              BlackCat continues to amaze me.
                              That is because you still has a lot to learn
                              With or without religion, you would have good people doing good things and evil people doing evil things. But for good people to do evil things, that takes religion.

                              Steven Weinberg

                              Comment

                              Working...
                              X