All the latest UK technology news, reviews and analysis

Experts warn of malicious Snow Leopard sites

by Iain Thomson

28 Aug 2009

Comments: 4

  • Tweet this
Snow Leopard
Malware writers are targeting Snow Leopard upgraders

Security firm Trend Micro has detected several sites purporting to offer free Snow Leopard upgrades which are in fact packed with malware.

The sites were discovered by advanced threat researcher Feike Hacquebord, who said that, far from delivering an operating system upgrade, the files contain malware known as Jahlav which is designed to entrap Apple users.

"Once executed, OSX_JAHLAV.K decrypts codes which include a script that downloads other malicious scripts," the company said in a blog post.

"The script then alters the DNS configuration and includes two additional IP addresses in its DNS server. Users are thus possibly redirected to phishing and other fraudulent sites. In fact, some of these bogus sites are reportedly hosting FAKEAV variants and components."

Trend Micro said that it is already blocking the sites that host the malware, and is advising Apple users to purchase the Snow Leopard upgrade from Apple directly.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

46%

3%

11%

40%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Security Assurance Consultant

Security Assurance Consultant ( CLAS ) with HMG and Information...

Solution Design Architect

Solutions Design Architect - Oracle - Exadata - Dataguard...

Project Manager

My Client is a tier one investment bank based in Edinbugh...

Analyst Programmer

Analyst Programmer Web Developer required to work for...

To send to more than one email address, simply separate each address with a comma.