Posted on 11/05/2010 2:30:16 AM PDT by Swordmaker
bump
New Mac OSX Trojan Discovered... this trojanTrojan.OSX. boonana.a & balso has code which infects Windows (Trojan.Windows.boonana.a) and Linux (Trojan.Linux.boonana.a) machines. PING!
The rating on this trojan for OSX, Linux, and Windows is SEVERE! It includes a key logger, and reportedly seeks passwords and credit cards. The Windows version causes the infected the machine to join a spambot.
Currently, Apple OSX will not recognize this new Trojan as malware, as it is new and not in its malware definition files, but OSX WILL WARN YOU that you are downloading an application or applet from an untrusted website and that it does not have a valid certificate.
If you want on or off the Mac Ping List, Freepmail me.
well just DAMN
if true
we cant be as smug anymore can we?
nor as non diligent
JUST DAMN
There were already 17 known Trojans variants in the wild for OSX... in three families... this is must two more in a fourth family. Compare that to over a million malware for the other platform... OSX will warn you about the other three families and as soon as Apple gets out a security update, it will warn you about downloading this one too.
Many thanks for keeping us up to date!
Bfl
Which is the best antivirus software for Mac, in your opinion?
Just curious, how many of those million will affect up-to-date, patched Windows 7 installations?
SecureMac may have modified its analysis of this Trojan.
see: http://www.securemac.com/boonana-b-bulletin.php
OS X.
There are no known viruses for OS X; Trojans, such as this, require the user to actually do something, typically accomplished through misdirection or trickery.
The best anti-malware for any platform is between the chair and the keyboard. This trojan, for example, is an IM or e-mail purportedly from a friend; it then points to a fake YouTube video, actually a Java applet, which then requires an admin password to install. It’s what hackers call “social engineering.”
That said, ClamXav is free, robust, free, frequently updated, and free. I run it every few months just to make sure I haven’t picked up a Windows virus I might unwittingly pass on. It has yet to find anything.
How many Windows users are on Windows7 at last count? 29%? There are a couple of zero day Internet Explorer exploits that have yet to be patched that are in the wild right now that will walk through the protections for the older systems...
What does this file mascarade as to get users to give permission to install? Is it primarily just for idiots who let every little randomly downloaded to their machines without their initiating the download, and despite warnings that it was downloaded from the internet, and not from a trusted site?
Thanks for the replies...yes, I’m usually alert for any funny stuff that could be a security risk, but I’m not invulnerable, just an average user. So I have Intego VirusBarrier X6 for any kind of malware...and it includes a firewall that I can understand a little better than the options that are given in the OS X firewall.
Yeah, they have added that the Linux variant can now join a botnet...
From what I understand it comes as a link in an email with the text that it is a YouTube of a vide the sender thinks includes YOU in the video... just click on here and instead of a YouTube you get a YouTube look alike site and then it wants to download an app to allow you to view the video. If you accept the aplet, you are then asked to allow the install of the application... which is the Trojan. It takes industrial strength stupid to ignore the warnings OSX puts up about the site being an untrusted site and that the security certificate is not valid... and then installing from the web... etc. But some users are industrial strength stupid and just HAVE to see that video. Some people just have to go see the varmint...
Thanks for the non-answer...
This is giant "We're just not that in to you" to enterprise customers. The Mac Pro may work for mid-sized busnesses and the Mac mini will work with small businesses. But Apples foray into corporate America is over.
Yes... I just posted it and pinged the list... Apple offers new Mac Pro Server configuration to replace Xserve
I don't think it's a good move.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.