Skip to comments.New Mac OS X Trojan unearthed. Call it SabPub
Posted on 04/16/2012 9:00:32 PM PDT by iowamark
Here we go again.
Kaspersky Lab security researcher Costin Raiu has discovered another Mac OS X Trojan. Dubbed Backdoor.OSX.SabPub.a (or just SabPub, for short), the malware uses Java exploits to infect a Mac, connect to a remote Web site, and wait for instructions that include taking screenshots of the user's Mac and executing commands.
"The Java exploits appear to be pretty standard, however, (and) they have been obfuscated using ZelixKlassMaster, a flexible and quite powerful Java obfuscator," Raiu wrote on the Securelist blog. "This was obviously done in order to avoid detection from anti-malware products." Related stories
Raiu's discovery comes as Mac users are on high alert over the Flashback Trojan, which reportedly infected over 600,000 Macs worldwide. That exploit, which also uses Java, is capable of nabbing user passwords and other information from their Web browser or some applications. Apple on Friday released a tool designed to remove Flashback from infected machines. Prior to that launch, it was believed that 270,000 Macs were infected with the Trojan, down significantly from its height.
In a follow-up post on Securelist yesterday, Raiu provided a bit more information on SabPub to help differentiate it from Flashback. He reported that there are at least two SabPub variants in the wild today, including one that dates back to February. The malware appears to be delivered through targeted attacks, which should limit its ability to make widespread incursions a la Flashback.
Raiu also reported that the malware appears to be spreading through Word documents that exploit the CVE-2009-0563 vulnerability related to a stack-based buffer overflow in Office on the Mac.
"The most interesting thing here is the history of the second SabPub variant. In our virus collection, it is named '8958.doc.'" Raiu wrote on the blog. "This suggests it was extracted from a Word document or was distributed as a Doc-file."
Apple did not immediately respond to CNET's request for comment.
And so it begins...if you own a mac please by a 3rd party AV solution to protect your machine.
Just had an Apple software update for Java that said it removed malware.
Was that bogus?
swordmaker may be able to help.
My bet is that it was legit. OSX is being torn up by java malware right now.
So far everything is working, except the ice maker went out on the Sub Zero...
The problem is not exploit of the Apple's OS X but the Java that also runs on OS X that is being over hyped. Leo Laporte said you can actually disable Java!
Run the software update. Apple has addressed this problem in software updates.
If you disable Java system-wide, your safe. Ways to disable Java: http://osxdaily.com/2012/04/07/tips-secure-mac-from-virus-trojan/
Note, also that, contrary to the article, the Flashback NEVER, EVER infected 600,000 Macs, and the number was reduced to 227K, ADMITTED BY KASPERSKY, if even that! The number was ESTIMATED, and we are STILL not finding ANYONE in the real world who claims to have been infected! Where are the infected Macs????
This version requires an even OLDER unpatched version of JAVA... SHEESH!
Can you say "Proof of Concept?"
If you want on or off the Mac Ping List, Freepmail me.
Thanks, if that is so, good enough.... I wonder if Facebook video calling will still work though because looks like Skype plugin running on Java...?
That is a BS statement... re-analyzing the data provided by Doctor Web, it was found that they had exaggerated the threat by quite a bit... and that the number was 227,313 IF THAT... since no one is finding any infected machines in the WILD!
Doctor Web was claiming that you could submit your Mac's UUID to them and have them check with the CONTROL SERVER for the MacBOT to find out if you were infected, but KNOWN clean machines so submitted to their automatic checking site, some without JAVA being installed at all, were being reported as being members of the botnet!, including brand new Macs, right out of the box!
Thiscombined with the dearth of infected machines being reported on all the forumspretty much proves the botnet a hoax in my bookmade up of artificially generated UUIDs from the known range assigned to Apple Macs!
Thanks for Ping!! Keep me posted.
Even if that’s true that doesn’t change the fact that OSX now has confirmed malware in the wild.
“Just had an Apple software update for Java that said it removed malware.
Was that bogus?”
Nope, it was aimed at the Flashback malware. The Java update also removed the vulnerability, so attacks like Flashback won’t work.
This Cnet article was fairly worthless, as they didn’t make it clear that the latest Java patches remove the vulnerability.
There is apparently another variant that targets Microsoft Word for Mac, but you’re fine if you either don’t run Office, or simply don’t open documents from unknown sources. I didn’t see anything about a patch for this yet, it might be worth check Microsoft’s site for one.
I’ll also link a decent article on maximizing Mac security. It’s a bit overly paranoid in my view (I have Java and Flash installed, though I may get rid of standalone Flash). I guess at this point I’d recommend installing an anti-malware solution. I’m using Sophos, which is free and seems pretty lightweight.
“Even if thats true that doesnt change the fact that OSX now has confirmed malware in the wild.”
Not for a fully patched machine. There has been “theoretical” malware targeting Macs for years.
It is still a minuscule problem compared to the Windows free-for-all.
It looks like the Apple is starting to get worms. I guess it’s becoming time to pitch the Apple and get PCs which have much more mature and developed exploit removal tools.
“It looks like the Apple is starting to get worms. I guess its becoming time to pitch the Apple and get PCs which have much more mature and developed exploit removal tools.”
There’s a saying about that: “It’s like cutting off your nose to spite your face!”
It’s funny watching each release of Windows add the same things that earlier releases of MacOS had. I hear Windows 8 is going to have a backup system. Just imagine!
You know that’s a lie. A fully patched windows machine is secure.
“You know thats a lie. A fully patched windows machine is secure.”
You apparently don’t know that you’re uninformed. Do a search on “zero day exploit”.
Guess which OS gets vastly more of them?
I’ll steal a page from Swordmaker. There are no 0 day exploits in the wild for a fully patched windows7 machine.
If there is prove it. I will navigate my windows 7 machine to any website you want me to.
Thanks for the clarity.
The pc-shills have been screaming
this in every news venue.
“If there is prove it. I will navigate my windows 7 machine to any website you want me to.”
The first phase of a zero day exploit is one nobody knows about - like the Flashback malware before people were aware of it. That is how hundreds of thousands or millions of machines become infected.
Good luck with Windows. As for me, I will continue to enjoy the painless and productive MacOS - along with its best in class bundled applications.
I’m not saying OSx is garbage, all I’m saying is the security of both OSX and windows 7 is about the same. OSX enjoys the benefit of having a smaller user base so the target is smaller. But as it becomes more popular we will see more and more attacks on OSX.
So all I’m saying is get ahead of the game and apply a good 3rd party AV solution to your system to help protect your data.
“Even if thats true that doesnt change the fact that OSX now has confirmed malware in the wild.”
yeah, but YOU LIED LIKE OBAMA’S MOMMA when you wrote “OSX is being torn up by java malware right now.”
That is not a lie. It is being torn up with java malware. When you go from having 0 to hundreds of thousands of cases that’s being torn up.
There HAVE been... several. They are now patched.
To use your logic. I’ve never been hit nor anyone I know that was running a fully patched windows 7 machine—therefore it does not exist.
Kind of like the recent malware on OSX.
b/ the latest issue is now shown to be from infected MICROSOFT 9did you get that, MICROSOFT!) Word docs, from an exploit that goes back to THREE YEARS:
Kaspersky's Costin Raiu writes in the Securelist blog that: "At least two variants of the SabPub bot exist today". He adds that "The earliest version of the bot appears to have been created and used in February 2012. The malware is being spread through Word documents that exploit the CVE-2009-0563 vulnerability." He notes that "SabPub stayed undetected for more than 1.5 months." (More below)Summary:It needs to be addressed, but it's not "tearing up" the Mac community.
Graham Cluley warns that: "Unlike the earlier sightings of Sabpab, there is nothing about this attack which relates to the Java vulnerability exploited by the Flashback botnet." Cluley wrote in his blog that: "Rather than relying upon a Java vulnerability - it appears to be exploiting malformed Word documents instead."
Cluley's concern is that: "Any Mac users who believe that they have protected themselves because they don't use Java probably needs to realise that that's not an effective defence".
It was previously thought that Sabpab used the same vulnerability in the OS X's Java plug-in to infect Macs. Sophos had earlier warned that just like Flashback - all that needs to happen is for you to visit an infected webpage. It had been thought that if you have updated Java on your Mac then you would be protected from the new threat, and most Mac anti-virus software will protect against Sabpab as well. This is not the case.
The Trojan works as follows, according to Cluley: "If you open the boobytrapped Word document on a vulnerable Mac, a version of the OSX/Sabpab Trojan horse gets installed on your computer opening a backdoor for remote hackers to steal information or install further code." He adds that: "Mac users may be caught out by the attack, as there is no prompt to enter your username or password when the malicious software installs itself onto your Mac."Sophos anti-virus products will detect the Word documents as Troj/DocOSXDr-A, and protection against OSX/Sabpab-A has been updated to detect this variant also, Cluley notes, suggesting that Mac users install security software.
This Word exploit is nothing new. Cluley points to an earlier blog about another Mac malware, identified by AlienVault back in March. In that case the Trojan was hidden in a booby trapped Word document and relied upon a critical security vulnerability discovered in Microsoft Word back in 2009...
The OS should NOT allow an application to be exploited like that. Microsoft has been beaten up for years over such things.
Thank you for all you do. I’ve no other source for straight skinny as good as yours.
It doesn’t. The data stacks and heaps are non-executeable memory locations in OSX. Microsoft was apparently doing something that is not permitted under the system programming that moved data into executable areas. This was patched THREE YEARS AGO. It is not in the wild as far as I can see. It’s theoretical, again, if you haven’t updated your MS Word, or your Mac, you might get hit by this.
How does Microsoft do something that isn’t permitted? The OS controls that stuff. The app should just crash when that happens or not be allowed to be compiled/installed. Or at least warn the user that the app they are installing is altering the OS at ring0.
“The OS should NOT allow an application to be exploited like that. “
Oh yeah, and I am sure you aren’t one of those nincompoops who scream “Apple has too much control of the apps”.
Try spending as much time beefing about Obama, and be productive.
PS - Ever notice how Mac users will hardly ever even post a comment on a Windows thread? IF YOU AREN’T USING A MAC, go whine somewhere else.
Uh actually the reason I’m doing this service of posting in Mac threads is because for years we had knuckleheads post in windows threads to get a Mac. I’m not even say to go back to windows. I’m just saying get a real AV solution and use good security practices because no OS is fool-proof.
Also you are RIGHT I’m not one of those guys that say Apple has too much control of the apps. I hate android and that’s one of their biggest issues—did you see the instagram malware for android? Why on earth would you even bring this up on this thread? Are you a macbot or apple zealot?
“OSX is being torn up by java malware right now....Even if thats true that doesnt change the fact...Uh actually the reason Im doing this service...Im just saying ....”
My suggestion is to use native Skype. Skype by itself works fine on my Macbook Pro.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.