{"id":47276,"date":"2012-04-05T14:20:01","date_gmt":"2012-04-05T12:20:01","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=47276"},"modified":"2012-04-05T14:25:37","modified_gmt":"2012-04-05T12:25:37","slug":"beware-mac-malware-have-you-been-infected","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/47276-beware-mac-malware-have-you-been-infected.html","title":{"rendered":"Beware: Mac malware &#8211; have you been infected?"},"content":{"rendered":"<p>Russian anti-virus vendor, Doctor Web has found that a trojan disguised as a flash installer has infected at least 600,000 <a title=\"Apple\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/342717-Apple-inc\">Apple<\/a> Mac computers, including 274 machines from Cupertino where Apple is headquartered.<\/p>\n<p>Most of the machines infected by the BackDoor.Flashback trojan are located in the US (56.6%) and Canada (19.8%), with Doctor Web reporting that the UK is in third place (12.8%) and Australia in fourth with 6.1%.<\/p>\n<p>According to Doctor Web, attackers began using two different Java vulnerabilities to spread the malware in February 2012, but switched to another exploit after March 16.<\/p>\n<p>Oracle reportedly patched the vulnerability in February already, but Apple only issued the fix to close the hole on April 3 2012.<\/p>\n<p>The exploit saves an executable file onto the hard drive of the infected Mac machine, Doctor Web explained. The file is used to download malicious payload from a remote server and to launch it.<\/p>\n<div id=\"attachment_47278\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-47278\" class=\"size-full wp-image-47278\" title=\"Flashback - Dr Web 600k tweet\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-Dr-Web-600k-tweet.jpg\" alt=\"Flashback - Dr Web 600k tweet\" width=\"600\" height=\"481\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-Dr-Web-600k-tweet.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-Dr-Web-600k-tweet-93x75.jpg 93w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-Dr-Web-600k-tweet-174x140.jpg 174w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-Dr-Web-600k-tweet-250x200.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-47278\" class=\"wp-caption-text\">Dr Web analyst tweets new numbers, Cupertino and Finland stats<\/p><\/div>\n<p>Doctor Web said the launched malware first searches the hard drive for the following components:<\/p>\n<ul>\n<li>\/Library\/Little Snitch<\/li>\n<li>\/Developer\/Applications\/Xcode.app\/Contents\/MacOS\/Xcode<\/li>\n<li>\/Applications\/VirusBarrier X6.app<\/li>\n<li>\/Applications\/iAntiVirus\/iAntiVirus.app<\/li>\n<li>\/Applications\/avast!.app<\/li>\n<li>\/Applications\/ClamXav.app<\/li>\n<li>\/Applications\/HTTPScoop.app<\/li>\n<li>\/Applications\/Packet Peeper.app<\/li>\n<\/ul>\n<p>Only if the files are not found, does the Trojan execute a special routine to generate a list of control servers to which it sends an installation success notification.<\/p>\n<p>Each bot includes a unique ID for the infected machine in the query string it sends to a control server. Doctor Web said its analysts used sinkhole technology to redirect the botnet traffic to its own servers and thus were able to count infected hosts.<\/p>\n<p>F-Secure has published a step-by-step guide to detect and remove the malware on its site. An uninfected machine should display the following results:<\/p>\n<div id=\"attachment_47282\" style=\"width: 599px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-47282\" class=\"size-full wp-image-47282\" title=\"Flashback - F-Secure manual detection and removal\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-F-Secure-manual-detection-and-removal.jpg\" alt=\"Flashback - F-Secure manual detection and removal\" width=\"589\" height=\"190\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-F-Secure-manual-detection-and-removal.jpg 589w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-F-Secure-manual-detection-and-removal-100x32.jpg 100w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-F-Secure-manual-detection-and-removal-185x59.jpg 185w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/04\/Flashback-F-Secure-manual-detection-and-removal-250x80.jpg 250w\" sizes=\"(max-width: 589px) 100vw, 589px\" \/><p id=\"caption-attachment-47282\" class=\"wp-caption-text\">F-Secure manual detection and removal of BackDoor.Flashback<\/p><\/div>\n<p>Doctor Web advised Mac users to download and install the security patch recently released by Apple.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trojan already built a 600,000-strong botnet, according to Doctor Web<\/p>\n","protected":false},"author":23,"featured_media":24671,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[36,605,10490,10486,10488,2120,801,10492,10484],"class_list":["post-47276","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-apple","tag-backdoor-flashback","tag-dr-web","tag-flashback","tag-mac","tag-malware","tag-sorokin-ivan","tag-trojan"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/47276"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=47276"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/47276\/revisions"}],"predecessor-version":[{"id":47288,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/47276\/revisions\/47288"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/24671"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=47276"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=47276"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=47276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}