19 May 2011
Apple user forums are showing a marked increase in reports of the Mac Defender malware spreading among Mac OS systems, and security vendors have also noticed a recent surge in reports.
A discussion in the Mac Pro forums on Apple's web site on removing Mac Defender is now the second most popular topic with over 4,000 views. Readers are complaining of fake anti-virus software infections and appealing for help to get rid of them.
The Mac Defender software, discovered earlier this month by Mac security software house Intego, is a scareware package of the type increasingly affecting Windows systems.
The malware spreads via web pages that are search engine optimised to appear near the top of search rankings. The software is injected onto the target system as a JavaScript download, and then informs the user that they are infected with a virus, which can be removed for a fee.
"The Trojan package downloaded from the web contains two more packages: macprotector.pkg and macProtectorInstallerProgramPostflight.pkg," said McAfee's security team in a blog post.
"The former is the application, and the latter contains a bash script that will launch Mac Protector once the installation is finished. The installation is the same as we are used to seeing, and it requires root privileges."
As an added annoyance the software randomly displays pornography on the user's desktop in pop-up windows, in order to give the appearance of malware at work and encourage the purchase of the fake anti-virus software.
Although initially thought to be rare, the malware appears to be proliferating and several new variants have been found in the wild, according to Intego spokesman Peter James.
"It's clearly a serious problem, and one that's spreading. People are confronted by this when doing Google searches, as well as through ads on some well-known web sites, so it's very new to them," he told V3.co.uk.
"While it requires a user to enter a password, hence via social engineering, it seems that many people don't know not to enter their password."
AppleCare staff have reportedly been told not to remove the software, although this has not been confirmed by Apple, which declined to comment on this story.
Security experts have long warned that Apple users have become complacent about malware infections, and have predicted that malware writers will target the Apple platform as it grows in popularity.
There have been increasing reports of Mac malware, although nothing on the scale suffered by Windows users.
Earlier this month, however, the first automated malware toolkit for the Apple platform was discovered, and it seems that Apple users are in for more attacks in the future.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
The Role: As a Field Service Engineer working from...
The Role: Make the most of your IT knowledge in one...
Head of IT / Infrastructure Manager (Marketing Services...
A Multi-national data analytic's and cloud computing...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Wrong Perspective
"Security experts have long warned that Apple users have become complacent about malware infections" Actually, it seems the only people being infected are those who are not complacent. That says a lot.
Posted by: Tim 20 May 2011
Think I've heard this before
Every year the same old line, yet it never seems to happen. Makes me wonder if the real malware isn't the people who play chicken little every year in hopes of selling their software, they lost their credibility a long time ago. It's the old boy who cried wolf story, sooner or later there will be a real threat, but no one will believe it because of the chicken little cry of the sky is falling.
Posted by: Thomcarl 19 May 2011