03 May 2011
Danish IT security vendor CSIS Security Group is warning Mac users to expect an avalanche of new information-stealing malware attacks after discovering what it claims to be the first crimeware kit aimed at the Mac OS X platform being traded on underground forums.
The authors of the kit are trying to keep a low profile, but it is being sold under the name Weyland-Yutani BOT and is already fully operational, according to CSIS.
"In the same way as several other DIY crimeware kits designed for PCs, this tool consists of a builder, an admin panel and supports encryption," wrote CSIS partner Peter Kruse in a blog post.
"The Weyland-Yutani BOT supports web injects and form grabbing in Firefox; however both Chrome and Safari will soon follow. The web injects templates are identical to the ones used in Zeus and Spyeye."
The first version of the kit is being sold on several forums for $1,000, he added.
Hacking kits designed for PCs have already spread far and wide on the web's underground forums and have been widely held responsible for the growing threats from malware such as the banking information stealing ZeuS Trojan.
"CSIS finds this crimekit to be quite disturbing news since Mac OS previously to some degree has been spared from the increasing amount of malware which has haunted Windows-based systems for years," said Kruse.
"This could have resulted in a false sense of security that might make Mac OS users especially vulnerable to a sudden and highly sophisticated attack. "
The bad news may not end there for Apple fans, with cyber criminals reportedly developing similar attack kits for the iPad, as well as Linux machines, he added.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Java Deveoper/Programmer/Software Engineer, Algo Trading...
Austin Fraser has the pleasure of appointing a number...
Austin Fraser has the pleasure of appointing a Java Developer...
Austin Fraser has the pleasure of appointing a Senior...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
disparate code for OSX has been out for years...
OSX is full of vulnerabilities and their have been the occassional Trojan placed on sites for the Mac OS and pwning a Mac through Safari is old hat. What is different now is that since a framework has now been created and is being distributed Mac owners are going to find out what Windows users already know: The Internet is like the wild west and it doesn't always take actively working on the Internet to get infected.
Posted by: Fred Dunn 13 May 2011