Newsletter:

Skip Navigation LinksHome > News > Security > Phishing Trojan targets Mac OS X

Phishing Trojan targets Mac OS X

By Shaun Nichols
2 November 2007 06:59AM
Tags: phishing | trojan | targets | mac | os

Security vendor Intego claims to have uncovered a new Trojan attack that targets Apple's OS X operating system.

The OSX.RSPlug.A Trojan disguises itself as a video codec that offers access to a pornographic video.

Intego said that malware authors have spammed Mac forums with links for pornographic websites hosting the malware.

Users attempting to install the codec receive a piece of malware classified as a 'DNS Changer' which modifies the way OS X handles the DNS requests used to link numerical IP addresses to web URLs.

The tool allows the attackers to redirect web traffic. Users attempting to visit PayPal, eBay or certain banking sites, for instance, will be directed to a phishing website instead.

If confirmed, the Trojan would be the first piece of truly malicious software to be targeted at OS X.

Researchers have previously developed OS X attacks and exploits, but these were largely proof-of-concept attacks that lacked a malicious payload.

While security experts agree that such malware would pose a very serious threat to Mac users, it remains unclear just how far the reported Trojan has spread.

Early on Wednesday morning, representatives for McAfee, Symantec and Trend Micro said that their researchers had been unable to find the Trojan in the wild or obtain a sample from Intego.

A spokesperson for Symantec suggested that Intego "has a tendency to over-hype things".

UPDATE: McAfee has confirmed the existence of the OSX.RSPlug.A Trojan and reported that it is spreading through fake codec sites in addition to the porn website.

Copyright © 2008 vnunet.com

   


Ads by Google



Product Reviews

Star Rating
Paraben has been the market leader in hand-held forensics because the software is easy to use and covers a...
Star Rating
SpamTitan takes an interesting approach to managing spam.
Star Rating
Saint Scanner and Saint Exploit 6.7.11 are two great tools wrapped up to work together to provide an in-depth...
Star Rating
ManageEngine DeviceExpert 5.1 is a web-based configuration and change management solution for network...
Star Rating
The SPX3000 appliance from Array Networks combines many good features for making network resources easily...
TopTopics
(4859) -  google
(4568) -  internet
(4076) -  broadband
(3720) -  linux
(3673) -  iphone
(3476) -  security
(3351) -  mobile
(2137) -  government
(1596) -  telstra
(1595) -  china
(1158) -  ibm
(1079) -  microsoft
(991) -  apple
(942) -  network
(932) -  research