All the latest UK technology news, reviews and analysis

Mac Defender scareware variant MacGuard installs without admin password

by Phil Muncaster

More from this author

26 May 2011

Be the first to comment

  • Tweet this

Security experts are warning Mac users of a new variant of the Mac Defender scareware which does not require its victims to type in their administrator password to install.

Mac security firm Intego, which first revealed details of the original Mac Defender scareware, explained in a blog post that it has discovered MacGuard, a similar fake anti-virus product which also targets Mac users via blackhat search engine optimisation (SEO) techniques.

"Unlike the previous variants of this fake anti-virus, no administrator password is required to install this program. Since any user with an administrator account - the default if there is just one user on a Mac - can install software in the Applications folder, a password is not needed," explained Intego on its Mac Security blog.

"This package installs an application - the downloader - named avRunner, which then launches automatically. At the same time, the installation package deletes itself from the user's Mac, so no traces of the original installer are left behind."

The program then works like a classic scareware scam, with the MacGuard application running to look like an authentic virus scanning program.

MacGuard will then occasionally run 'scans' and inform the user that their PC is infected, requiring them to submit their credit card details to purchase a licence for the software, which will supposedly protect their computer.

Intego has labelled the MacGuard threat as a 'medium' risk "in part because the SEO poisoning has been very efficient in leading Mac users to booby-trapped pages, but also because no password is required to install this variant".

The incident yet again confirms the increasing risks to Mac users as cyber criminals gradually turn their attention to a platform which was until recently largely ignored owing to its low market share.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Digital Account executive 25k Fulham

Digital Account Executive Fulham, London 25k A great...

Oracle Apps DBA

Our global consultancy client currently seeks a number...

Support Analyst x 1/2 (Apple Mac OSX/Windows) - Bristol/Bath

Support Analyst x 1/2 Skills: Apple Mac OSX, Windows...

Network Consultant - London - 55-65k

Network Consultant - London - 55-65k My client are...

To send to more than one email address, simply separate each address with a comma.