Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Mac-specific Trojan discovered, injects ads into webpages
Tweaktown ^ | Posted: 3 hours, 39 mins ago | Charles Gantt

Posted on 03/21/2013 1:18:06 PM PDT by Ernest_at_the_Beach

A new virus specific to Mac has been discovered by Russian security firm Doctor Web. Named Trojan.Yontoo.1, the virus injects ads into webpages on the infected machine.

 

mac_specific_trojan_discovered_injects_ads_into_webpages

 

The malware works by installing an adware plugin into any of the popular browsers then overlays an advertisement in key locations on webpages. Doctor Web says that this trojan is just another piece of a large adware puzzle that has been infecting OS X for some time now.

 

mac_specific_trojan_discovered_injects_ads_into_webpages

 

The virus can be caught in several different ways, with the most popular method being the use of movie trailer pages in which users must install a plugin to view the content. Other methods of injection have been media player enhancement programs and download accelerators. One indication of infection is that when launched, Trojan.Yontoo.1 will prompt users to install a program called "Free Twit Tube" or something similar.

 

No information has been released from Apple on a removal tool yet, and it is expected that Apple will just patch its XProtect.plist which already blocks about 15 previous malware attacks. The best thing is to avoid any installs from unknown websites or anything that has a funny name. Remember, Google is your friend and if you are unsure of an application's validity, a five second search could prevent an infection. Be smart.

SOURCE #1


TOPICS: Computers/Internet
KEYWORDS: applemacs; malware
Navigation: use the links below to view more comments.
first 1-2021-37 next last

1 posted on 03/21/2013 1:18:06 PM PDT by Ernest_at_the_Beach
[ Post Reply | Private Reply | View Replies]

To: ShadowAce; SunkenCiv

fyi


2 posted on 03/21/2013 1:19:32 PM PDT by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
Remember, Google is your friend ...

Great post except for the above, which means "all your keystroke are belong to us." It's good to use a search proxy like Startpage.

Thanks again for the helpful Mac info.

3 posted on 03/21/2013 1:22:29 PM PDT by Albion Wilde (Liberalism: knowing you're better than everyone else because of your humility. -- Daniel Greenfield)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

bumpage4later


4 posted on 03/21/2013 1:23:54 PM PDT by CGASMIA68
[ Post Reply | Private Reply | To 1 | View Replies]

To: Albion Wilde
Not sure why this is Apple specific.

Sounds like it would work with Windows or Linux....if someone hacker did the work ....

5 posted on 03/21/2013 1:26:22 PM PDT by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 3 | View Replies]

To: Ernest_at_the_Beach

Impossible. Macs don’t get viruses.

/s


6 posted on 03/21/2013 1:27:34 PM PDT by Responsibility2nd (NO LIBS. This Means Liberals and (L)libertarians! Same Thing. NO LIBS!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

MAC bump


7 posted on 03/21/2013 1:29:48 PM PDT by Pontiac (The welfare state must fail because it is contrary to human nature and diminishes the human spirit.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Responsibility2nd
Impossible. Macs don’t get viruses.

That's why Norton, Mcafee, Webroot, etc,etc,etc. sell Anti-Virus utilities for Mac.

8 posted on 03/21/2013 1:31:35 PM PDT by unixfox (Abolish Slavery, Repeal The 16th Amendment!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Responsibility2nd
"...Impossible. Macs don’t get viruses..."

Heh, I usually hear that from people who don't know anything about computers, or who don't know anythings about Macs.

People who DO know anything about computers don't say that.

9 posted on 03/21/2013 1:33:09 PM PDT by rlmorel (1793 French Jacobins and 2012 American Liberals have a lot in common.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Responsibility2nd

Technically this is not a virus it is a Trojan.


10 posted on 03/21/2013 1:34:00 PM PDT by Pontiac (The welfare state must fail because it is contrary to human nature and diminishes the human spirit.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Ernest_at_the_Beach

It appears that the user has to help out by approving and downloading something to get infected.

Human engineering.


11 posted on 03/21/2013 1:35:09 PM PDT by rlmorel (1793 French Jacobins and 2012 American Liberals have a lot in common.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Albion Wilde

The only search engine I use is called GoodSearch.com

I’ve been using it for years, now, and I find it is excellent!

The other good thing about GoodSearch is that when you first use it, it asks you to name a charity that you support. After you do that, it throws a few pennies to that charity every time you use it.

I listed my “charity” as Second Amendment Sisters in this way. We are a non-profit organization.

You don’t make a lot of money—but we have gotten a couple of checks for around $100.


12 posted on 03/21/2013 1:38:09 PM PDT by basil (basil, 2ASisters.org)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Ernest_at_the_Beach

In other words, they trick you into typing in the root password.

If you’re willing to type in the root password for anything that asks for it, you’re not much of a Unix Sysadmin.


13 posted on 03/21/2013 1:51:15 PM PDT by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox
That's why Norton, Mcafee, Webroot, etc,etc,etc. sell Anti-Virus utilities for Mac.

And I am sure they are all HUGH sellers, too.

14 posted on 03/21/2013 2:01:50 PM PDT by John Valentine (Deep in the Heart of Texas)
[ Post Reply | Private Reply | To 8 | View Replies]

To: proxy_user
In other words, they trick you into typing in the root password.

If you’re willing to type in the root password for anything that asks for it, you’re not much of a Unix Sysadmin.

Oh. Thank you for explaining it in terms I could comprehend, proxy_user. It suddenly makes sense!

15 posted on 03/21/2013 2:03:49 PM PDT by Standing Wolf
[ Post Reply | Private Reply | To 13 | View Replies]

To: Ernest_at_the_Beach
...the most popular method being the use of movie trailer pages in which users must install a plugin to view the content.

Any computer user stupid enough to fall for this ploy ALMOST deserves what they get. I say ALMOST, because nobody, no matter how stupid, deserves to have their computer messed with by a remote A-hole.

16 posted on 03/21/2013 2:04:51 PM PDT by John Valentine (Deep in the Heart of Texas)
[ Post Reply | Private Reply | To 1 | View Replies]

To: null and void

ping. look at the search engine recommendation


17 posted on 03/21/2013 2:23:32 PM PDT by Shimmer1 (No matter how cynical I get, I just can't keep up.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: rlmorel
This one was more serious...looks like they went after Unix-Linux servers:

South Korean Banks, Media Companies Targeted by Destructive Malware

18 posted on 03/21/2013 2:34:54 PM PDT by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 11 | View Replies]

To: basil

It is sponsored by Yahoo, right?

It is nice to support charity, but I prefer DuckDuckGo, which doesn’t track you, at least so far.


19 posted on 03/21/2013 3:13:20 PM PDT by jacquej
[ Post Reply | Private Reply | To 12 | View Replies]

To: Responsibility2nd; Swordmaker

Been using Macs since 1982, and never had a virus/trojan/malware problem yet.

And I am on the ‘net constantly. Just anecdotal, I know. Will wait for Swordmaker to post.


20 posted on 03/21/2013 3:15:37 PM PDT by jacquej
[ Post Reply | Private Reply | To 6 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-37 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson