28 Aug 2009
Security firm Trend Micro has detected several sites purporting to offer free Snow Leopard upgrades which are in fact packed with malware.
The sites were discovered by advanced threat researcher Feike Hacquebord, who said that, far from delivering an operating system upgrade, the files contain malware known as Jahlav which is designed to entrap Apple users.
"Once executed, OSX_JAHLAV.K decrypts codes which include a script that downloads other malicious scripts," the company said in a blog post.
"The script then alters the DNS configuration and includes two additional IP addresses in its DNS server. Users are thus possibly redirected to phishing and other fraudulent sites. In fact, some of these bogus sites are reportedly hosting FAKEAV variants and components."
Trend Micro said that it is already blocking the sites that host the malware, and is advising Apple users to purchase the Snow Leopard upgrade from Apple directly.
Latest stories from Operating Systems
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
TFL director of Games transport Mark Evers discusses how the public transport network is preparing for this summer's event
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Security Assurance Consultant ( CLAS ) with HMG and Information...
Solutions Design Architect - Oracle - Exadata - Dataguard...
My Client is a tier one investment bank based in Edinbugh...
Analyst Programmer Web Developer required to work for...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
But Macs don't get malware...
But that's social engineering. Its not exploiting any integral fault in the OS, unlike Windows malware, which uses things like pretending to be a legitimate program to get past UAC... Oh, wait.
Posted by: JH 29 Aug 2009
Not shocking
LMAO - Funny after seeing the MAC commercials on TV MAC saying " if you want Viruses get a PC". Appearently, you dont have to now:-) Funny how people think that Mac's are invulnerable. Lmao, before people flame me, I have a 7 different PC/Laptops and 2 MAC's. BTW My MacBook my fastest Windows 7 notebook:-) The commercials should actually be more accurate and post this link :-)
Posted by: NetAdmin NJ 28 Aug 2009
hehe
Thank god i have a PC.
Posted by: bob 28 Aug 2009
If this is so...
then why haven't the owners of these sites been arrested? It isn't terribly hard to figure out where a Web site is being hosted and who owns it. And there are very severe laws in place to prosecute malware authors and those who disseminate malware. If "Trend" has identified these sites, why haven't they been put out of business and why haven't the perpetrators been jailed?
Posted by: Keith Snell 28 Aug 2009