Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New Trojan Backdoor Malware Targets Mac OS X And Linux, Steals Passwords And Keystrokes
Forbes ^ | 8-31-2012 | Anthony WIng Kosner

Posted on 09/01/2012 8:34:42 AM PDT by grey_whiskers

Russian anti-virus software maker Doctor Web, has identified, “The first Trojan in history to steal Linux and Mac OS X passwords.” BackDoor.Wirenet.1, is the first Trojan Horse program that works on the Mac OS X and Linux platforms that is, “designed to steal passwords stored by a number of popular Internet applications.”

The company, which sells anti-virus software that, conveniently, protects you against the malware they are identifying, explains that, “When launched, it creates its copy in the user’s home directory. The program uses the Advanced Encryption Standard (AES) to communicate with its control server whose address is 212.7.208.65.”

The malware, “also operates as a keylogger (it sends gathered keyboard input data to intruders); in addition, it steals passwords entered by the user in Opera, Firefox, Chrome, and Chromium, and passwords stored by such applications as Thunderbird, SeaMonkey, and Pidgin.”

(Excerpt) Read more at forbes.com ...


TOPICS: Business/Economy; Culture/Society; News/Current Events; Technical
KEYWORDS: apple; computers; mac; macmalware; malware; trojan
NO Cheers, unfortunately.
1 posted on 09/01/2012 8:34:47 AM PDT by grey_whiskers
[ Post Reply | Private Reply | View Replies]

To: grey_whiskers; zeugma; dayglored; unixfox; Swordmaker; dfwgator; Hulka; cynwoody
Mac *PING*!

Not sufficiently versed to know whether this is FUD or exaggerated or legit.

Please discuss / advise.

g_w

2 posted on 09/01/2012 8:37:03 AM PDT by grey_whiskers (The opinions are solely those of the author and are subject to change without notice.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: grey_whiskers

"Somebody say 'Trojan'?"

3 posted on 09/01/2012 8:37:31 AM PDT by Joe 6-pack (Que me amat, amet et canem meum)
[ Post Reply | Private Reply | To 1 | View Replies]

To: grey_whiskers
The company, which sells anti-virus software that, conveniently, protects you against the malware they are identifying

Nice business model they got there.

4 posted on 09/01/2012 8:38:58 AM PDT by vbmoneyspender
[ Post Reply | Private Reply | To 1 | View Replies]

To: grey_whiskers
“Looks like meat penguin is back on the menu boys!”

How bout a nice cup of "secure" Java with that?

"ooops"

5 posted on 09/01/2012 8:41:15 AM PDT by OldEarlGray (The POTUS is FUBAR until the White Hut is sanitized with American Tea)
[ Post Reply | Private Reply | To 1 | View Replies]

To: grey_whiskers

This looks like a hoax. All the stories on it are low budget cut and paste of “russian security firms say XXX)” and there is no detailed analysis of it available nor any information on propagation. I have Mac OS and Linux with Fusion on this box and I am not worried in the least.


6 posted on 09/01/2012 8:45:12 AM PDT by palmer (Jim, please bill me 50 cents for this completely useless post)
[ Post Reply | Private Reply | To 1 | View Replies]

To: grey_whiskers
First off, it's a trojan", which means that you have to click on an email attachment or something in order for it to trigger.

Second, I have never seen an instance where Mac OS X will not ask your permission before allowing modifications to your home or system folders.

I suspect this is mostly FUD.

7 posted on 09/01/2012 9:01:15 AM PDT by jtonn
[ Post Reply | Private Reply | To 2 | View Replies]

To: grey_whiskers

I get a little nervous when I hear the words trojan and backdoor in the same sentance.


8 posted on 09/01/2012 9:09:18 AM PDT by V_TWIN (obama=where there's smoke, there's mirrors)
[ Post Reply | Private Reply | To 1 | View Replies]

To: grey_whiskers; Swordmaker

I strongly suspect FUD, but am no expert on such matters. Swordmaker will be along and his opinion is more well informed than mine.

So many of these claims have come along, and most prove to be flawed, hyped, or promos for the company claiming to have the “fix” for them.

Nobody go panic and buy this company’s software until Swordmaker tells us that our hair is on fire, and we are doomed.


9 posted on 09/01/2012 9:17:25 AM PDT by jacquej
[ Post Reply | Private Reply | To 2 | View Replies]

To: Joe 6-pack
"Somebody say 'Trojan'?"

"Somebody say 'back door'?"

10 posted on 09/01/2012 9:24:18 AM PDT by Tanniker Smith (Rome didn't fall in a day, either.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Tanniker Smith
"Somebody say 'back door'?"

Yeah, it must be circulated by 0h0m0.

11 posted on 09/01/2012 9:27:20 AM PDT by melancholy (Professor Alinsky, Enslavement Specialist, Ph.D. in L0w and H0lder)
[ Post Reply | Private Reply | To 10 | View Replies]

To: grey_whiskers
Not to worry. Yet.
12 posted on 09/01/2012 9:47:59 AM PDT by cynwoody
[ Post Reply | Private Reply | To 1 | View Replies]

To: OldEarlGray

I am guessing that because this is in Forbes. It’s real. There is no reason why virus code, malware, trojans, etc cannot attack a mac.

Mac has been flying under the radar because it was such a low percent of the installed base. This is rapidly changing with the blossoming iphone market.


13 posted on 09/01/2012 9:51:30 AM PDT by shineon
[ Post Reply | Private Reply | To 5 | View Replies]

To: shineon

>>This is rapidly changing with the blossoming iphone market.

Uhuh. Wait until the brute-force reality of “bring your own device” = “bring your own botnet” sinks its teeth into technocratic middle manglement’s progressively buzz-word/NewSpeaking arse.


14 posted on 09/01/2012 10:36:56 AM PDT by OldEarlGray (The POTUS is FUBAR until the White Hut is sanitized with American Tea)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Tanniker Smith

Quick! Tell Barney Frank it’s a false alarm.


15 posted on 09/01/2012 10:53:56 AM PDT by DPMD
[ Post Reply | Private Reply | To 10 | View Replies]

To: grey_whiskers; Swordmaker
At present, my belief is that this is just another false alarm, like the others raised periodically by the anti-virus vendors to hawk their wares.

The overblown false alarms are getting more outrageous (Remember that alleged botnet of half a million Macs a few months ago? What ever happened to that story?? No one ever identified the truly affected machines. It was a lie, to sell software!) <> So my best guess is that this is just another piece of FUD. They have nothing to lose and everything to gain from lying again.

That said, malware of various types that targets Mac users will continue to grow -- mostly user-target Trojans, since true OS-target viruses for Macs are essentially still non-existent.

I downloaded and ran the free ClamXav A/V product for Macs the other day (system was clean, as expected), and I think it's wise to have something like that on hand in case I suspect anything. I recommend that to all Mac users, because it's free and painless, and anybody can accidentally visit an infected website or open an infected email.

It's true that Mac users are still largely unaffected by malware, but that's no reason to have one's head in the sand.

16 posted on 09/01/2012 11:18:58 AM PDT by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: vbmoneyspender
Nice business model they got there.

"Bricks thrown through your window? Call Al's Glass."

17 posted on 09/01/2012 11:22:11 AM PDT by dfwgator (I'm voting for Ryan and that other guy.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: grey_whiskers; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; ...
 This is the same Doctor Web that started the claim about the 600,000 infected Macs last Spring that nobody could find. . . Except them. . . So I give this even less credence. They are claiming it use the same Trojan engine, for what that's worth. . . And being spread from the same .xxx sites. BS in my book. —PING!


Apple Security Ping!

Please, No Flame Wars!
Discuss technical issues, software, and hardware.
Don't attack people!
Don't respond to the Anti-Apple Thread Trolls!
PLEASE IGNORE THEM!!!

If you want on or off the Mac Ping List, Freepmail me.

18 posted on 09/04/2012 12:29:48 AM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: grey_whiskers

Have to program the IP to be blocked.


19 posted on 09/04/2012 11:10:40 AM PDT by CORedneck
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

-


20 posted on 09/05/2012 6:46:18 PM PDT by I see my hands (The prideful and petulant ABR crowd think their support of Zero is forgiven. Never ever.)
[ Post Reply | Private Reply | To 18 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson