Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New Mac OS X Trojan unearthed. Call it SabPub
CNET ^ | April 16, 2012 | Don Reisinger

Posted on 04/16/2012 9:00:32 PM PDT by iowamark

Here we go again.

Kaspersky Lab security researcher Costin Raiu has discovered another Mac OS X Trojan. Dubbed Backdoor.OSX.SabPub.a (or just SabPub, for short), the malware uses Java exploits to infect a Mac, connect to a remote Web site, and wait for instructions that include taking screenshots of the user's Mac and executing commands.

"The Java exploits appear to be pretty standard, however, (and) they have been obfuscated using ZelixKlassMaster, a flexible and quite powerful Java obfuscator," Raiu wrote on the Securelist blog. "This was obviously done in order to avoid detection from anti-malware products." Related stories

Raiu's discovery comes as Mac users are on high alert over the Flashback Trojan, which reportedly infected over 600,000 Macs worldwide. That exploit, which also uses Java, is capable of nabbing user passwords and other information from their Web browser or some applications. Apple on Friday released a tool designed to remove Flashback from infected machines. Prior to that launch, it was believed that 270,000 Macs were infected with the Trojan, down significantly from its height.

In a follow-up post on Securelist yesterday, Raiu provided a bit more information on SabPub to help differentiate it from Flashback. He reported that there are at least two SabPub variants in the wild today, including one that dates back to February. The malware appears to be delivered through targeted attacks, which should limit its ability to make widespread incursions a la Flashback.

Raiu also reported that the malware appears to be spreading through Word documents that exploit the CVE-2009-0563 vulnerability related to a stack-based buffer overflow in Office on the Mac.

"The most interesting thing here is the history of the second SabPub variant. In our virus collection, it is named '8958.doc.'" Raiu wrote on the blog. "This suggests it was extracted from a Word document or was distributed as a Doc-file."

Apple did not immediately respond to CNET's request for comment.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: apple; mac; sabpub
Navigation: use the links below to view more comments.
first 1-2021-4041 next last

1 posted on 04/16/2012 9:00:46 PM PDT by iowamark
[ Post Reply | Private Reply | View Replies]

To: iowamark

And so it begins...if you own a mac please by a 3rd party AV solution to protect your machine.


2 posted on 04/16/2012 9:11:09 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 1 | View Replies]

To: iowamark

Just had an Apple software update for Java that said it removed malware.

Was that bogus?


3 posted on 04/16/2012 9:18:37 PM PDT by Clint N. Suhks
[ Post Reply | Private Reply | To 1 | View Replies]

To: iowamark

Bookmark


4 posted on 04/16/2012 9:25:53 PM PDT by GOP Poet
[ Post Reply | Private Reply | To 1 | View Replies]

To: Clint N. Suhks; Swordmaker

swordmaker may be able to help.

My bet is that it was legit. OSX is being torn up by java malware right now.


5 posted on 04/16/2012 9:38:06 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 3 | View Replies]

To: for-q-clinton; Swordmaker

So far everything is working, except the ice maker went out on the Sub Zero...


6 posted on 04/16/2012 9:47:02 PM PDT by Clint N. Suhks
[ Post Reply | Private Reply | To 5 | View Replies]

To: Clint N. Suhks
Just had an Apple software update for Java that said it removed malware.

The problem is not exploit of the Apple's OS X but the Java that also runs on OS X that is being over hyped. Leo Laporte said you can actually disable Java!

7 posted on 04/16/2012 10:01:07 PM PDT by hamboy
[ Post Reply | Private Reply | To 3 | View Replies]

To: Clint N. Suhks

Run the software update. Apple has addressed this problem in software updates.


8 posted on 04/16/2012 11:02:49 PM PDT by BigSkyFreeper (You have entered an invalid birthday)
[ Post Reply | Private Reply | To 3 | View Replies]

To: hamboy
Simply downloading and installing “Java for OS X 2012-003″ through software updates disables Java.
9 posted on 04/16/2012 11:05:14 PM PDT by BigSkyFreeper (You have entered an invalid birthday)
[ Post Reply | Private Reply | To 7 | View Replies]

To: iowamark

If you disable Java system-wide, your safe. Ways to disable Java: http://osxdaily.com/2012/04/07/tips-secure-mac-from-virus-trojan/


10 posted on 04/16/2012 11:06:42 PM PDT by BigSkyFreeper (You have entered an invalid birthday)
[ Post Reply | Private Reply | To 1 | View Replies]

To: iowamark; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ...
Another variation of the JAVA exploit... contrary to the breathless tone of this article, this one is ALSO handled by simply turning OFF JAVA... and is based on a 2009 EXPLOIT that was patched by Apple in 2009!—PING!

Note, also that, contrary to the article, the Flashback NEVER, EVER infected 600,000 Macs, and the number was reduced to 227K, ADMITTED BY KASPERSKY, if even that! The number was ESTIMATED, and we are STILL not finding ANYONE in the real world who claims to have been infected! Where are the infected Macs????

This version requires an even OLDER unpatched version of JAVA... SHEESH!

Can you say "Proof of Concept?"


Apple Security Ping!

Please, No Flame Wars!
Discuss technical issues, software, and hardware.
Don't attack people!
Don't respond to the Anti-Apple Thread Trolls!
PLEASE IGNORE THEM!!!

If you want on or off the Mac Ping List, Freepmail me.

11 posted on 04/17/2012 1:20:30 AM PDT by Swordmaker
[ Post Reply | Private Reply | To 1 | View Replies]

To: BigSkyFreeper
Simply downloading and installing “Java for OS X 2012-003″ through software updates disables Java.

Thanks, if that is so, good enough.... I wonder if Facebook video calling will still work though because looks like Skype plugin running on Java...?

12 posted on 04/17/2012 1:24:42 AM PDT by hamboy
[ Post Reply | Private Reply | To 9 | View Replies]

To: iowamark
.

.

Mitt's Fault

.

.

13 posted on 04/17/2012 1:26:30 AM PDT by Jeff Chandler (This place is nuts.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: iowamark
Prior to that launch, it was believed that 270,000 Macs were infected with the Trojan, down significantly from its height.

That is a BS statement... re-analyzing the data provided by Doctor Web, it was found that they had exaggerated the threat by quite a bit... and that the number was 227,313 IF THAT... since no one is finding any infected machines in the WILD!

Doctor Web was claiming that you could submit your Mac's UUID to them and have them check with the CONTROL SERVER for the MacBOT to find out if you were infected, but KNOWN clean machines so submitted to their automatic checking site, some without JAVA being installed at all, were being reported as being members of the botnet!, including brand new Macs, right out of the box!

This—combined with the dearth of infected machines being reported on all the forums—pretty much proves the botnet a hoax in my book—made up of artificially generated UUIDs from the known range assigned to Apple Macs!

14 posted on 04/17/2012 1:34:15 AM PDT by Swordmaker
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
I have been getting this java from apple never had a problem. My kaspersky antivirus sent a Removal tool. Only if I wanted to use it not that I had it. After I sent a scan it came up empty. I still never had the headaches of a Windows os. I know I started on windows exp. Windows is way behind Apple.

Cheers!

15 posted on 04/17/2012 1:42:10 AM PDT by johngrace (I am a 1 John 4! Christian- declared at every Sunday Mass , Divine Mercy and Rosary prayers!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Swordmaker

Thanks for Ping!! Keep me posted.


16 posted on 04/17/2012 1:43:54 AM PDT by johngrace (I am a 1 John 4! Christian- declared at every Sunday Mass , Divine Mercy and Rosary prayers!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: for-q-clinton
My bet is that it was legit. OSX is being torn up by java malware right now.

BS. You have been on the anti-apple train since your startup date. It is in your posting history.
17 posted on 04/17/2012 1:56:05 AM PDT by PA Engineer (Time to beat the swords of government tyranny into the plowshares of freedom.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: PA Engineer

Even if that’s true that doesn’t change the fact that OSX now has confirmed malware in the wild.


18 posted on 04/17/2012 5:00:18 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Clint N. Suhks

“Just had an Apple software update for Java that said it removed malware.

Was that bogus?”

Nope, it was aimed at the Flashback malware. The Java update also removed the vulnerability, so attacks like Flashback won’t work.

This Cnet article was fairly worthless, as they didn’t make it clear that the latest Java patches remove the vulnerability.

http://www.securelist.com/en/blog/208193467/SabPub_Mac_OS_X_Backdoor_Java_Exploits_Targeted_Attacks_and_Possible_APT_link

There is apparently another variant that targets Microsoft Word for Mac, but you’re fine if you either don’t run Office, or simply don’t open documents from unknown sources. I didn’t see anything about a patch for this yet, it might be worth check Microsoft’s site for one.

I’ll also link a decent article on maximizing Mac security. It’s a bit overly paranoid in my view (I have Java and Flash installed, though I may get rid of standalone Flash). I guess at this point I’d recommend installing an anti-malware solution. I’m using Sophos, which is free and seems pretty lightweight.

http://www.securelist.com/en/blog/208193448/10_Simple_Tips_for_Boosting_The_Security_Of_Your_Mac

http://www.sophos.com/en-us/


19 posted on 04/17/2012 5:14:07 AM PDT by PreciousLiberty (Pray for America!!!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: for-q-clinton

“Even if that’s true that doesn’t change the fact that OSX now has confirmed malware in the wild.”

Not for a fully patched machine. There has been “theoretical” malware targeting Macs for years.

It is still a minuscule problem compared to the Windows free-for-all.


20 posted on 04/17/2012 5:17:48 AM PDT by PreciousLiberty (Pray for America!!!)
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson