03 May 2011
Security experts are warning of a "new and extremely rare" fake anti-virus scam dubbed MAC Defender targeted specifically at Mac users.
Fake anti-virus or scareware has been around for several years, gaining in popularity among cyber criminals who see it as a quick way to make money out of victims.
In fact, it has become so popular that around 12 per cent of all malware detected in the wild last year was fake anti-virus, according to security vendor Panda Security.
However, scareware almost exclusively targets Windows PCs, so this discovery by Mac security firm Intego is potentially the first of its kind aimed at conning Mac users out of their money.
Cyber criminals get the Mac Defender app onto victims' machines by using blackhat SEO techniques to lure them into clicking on malicious links.
They are sent to a fake Windows screen with an animated image showing a malware scan. A window then tells the user that their computer is infected, before JavaScript on the page automatically downloads a compressed file containing the MAC Defender installer, explained Intego in a blog post.
"Upon installation, the application adds itself to the user's Login Items, so it will relaunch each time the user logs in or starts up their computer. The application itself cannot be quit easily, as there is no Dock icon," the firm said.
"This application is very well designed, and looks professional. There are a number of different screens, and the grammar and spelling are correct, the buttons are attractive, and the overall look and feel of the program gives it a professional look. It will occasionally display alerts, telling users that viruses are found."
The app also periodically opens web pages of pornographic sites in what is apparently another effort to trick users into thinking they have malware on their machines and to persuade them to click on the register button of the app where they can purchase a 'licence' for the program which will supposedly protect them.
"The scam here is to charge users for a program that doesn't do anything; the virus warnings presented are bogus, and after paying, they no longer display, so users think the program has done something useful," said Intego.
"It is also possible that these credit card numbers, given via an unsecure web page, could be used for other purposes."
The news comes as security researchers in Denmark warned of a potential tsunami of information-stealing malware targeted at Mac users after they discovered the first crimeware kit aimed at the OS X platform being sold on underground forums.
Latest stories from Software
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Java Deveoper/Programmer/Software Engineer, Algo Trading...
Austin Fraser has the pleasure of appointing a number...
Austin Fraser has the pleasure of appointing a Java Developer...
Austin Fraser has the pleasure of appointing a Senior...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
affirmative!
I was just Skyped by my daughter who had this "virus" on her computer. I sat with her for fifteen minutes trying to get rid of it. I eventually found that it had been downloaded to the Applications folder. I got her to drag it to the trash bin, but couldn't empty the trash, because it was still "in use". After shutting down the laptop and then restarting it, I found I could empty the trash. When she shut down and restarted the laptop, the small red button and the application seemed to have been removed. The warnings no longer appear on her screen. Do you think this has effectively removed the "virus"? I hope so......
Posted by: John Daszak 03 May 2011