Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Half a million Mac computers 'infected with malware'
BBC ^ | April 2012 Last updated at 08:54 ET

Posted on 04/05/2012 8:45:23 AM PDT by null and void

An investigation by Dr Web suggests that about 600,000 Macs have the malware - potentially allowing them to be hijacked and used as a "botnet".

It says that more than half that number are in the US.

Flashback was first detected last September when anti-virus researchers flagged software masquerading itself as a Flash Player update. Once downloaded it deactivated some of the computer's security software.

Remote control

"By introducing the code criminals are potentially able to control the machine," the firm's chief executive Boris Sharov told the BBC.

"We stress the word potential as we have never seen any malicious activity since we hijacked the botnet to take it out of criminals' hands. However, we know people create viruses to get money.

"The largest amounts of bots - based on the IP addresses we identified - are in the US, Canada, UK and Australia, so it appears to have targeted English-speaking people."

Dr Web also notes that 274 of the infected computers it detected appeared to be located in Cupertino, California - home to Apple's headquarters.

Update wait

Apple released its own "security update" on Wednesday - more than eight weeks later. It can be triggered by clicking on the software update icon in the computer's system preferences panel.

The security firm F-Secure has also posted detailed instructions about how to confirm if a machine is infected and how to remove the Trojan.

Although Apple's system software limits the actions its computers can take without requesting their users' permission, some security analysts suggest this latest incident highlights the fact that the machines are not invulnerable.

"People used to say that Apple computers, unlike Windows PCs, can't ever be infected - but it's a myth," said Timur Tsoriev, an analyst at Kaspersky Lab.

Apple could not provide a statement at this time.

(Excerpt) Read more at bbc.co.uk ...


TOPICS:
KEYWORDS: apple; bots; flashback; hacking; internet; mac; malware; microsoft; osx; tech; virus; windows
Navigation: use the links below to view more comments.
first previous 1-20 ... 121-140141-160161-180181-185 next last
To: dayglored
Still have to account for the very low number of actual user complaints. Although that could be explained if the ONLY way to get infected was to visit some super-raunchy porn site, and nobody wants to admit to that... LOL!

Others are starting to comment on the dearth of reports of infected Macs being seen on forums. They JUST AREN'T THERE!

Here is a website with a script that you can run that will easily check your Macs for the presence of the Flashback Trojan... no terminal and cutting and pasting of the commands:

Site with Flashback checking script

Just downloaded and run it from the script editor.

161 posted on 04/07/2012 12:23:07 AM PDT by Swordmaker
[ Post Reply | Private Reply | To 159 | View Replies]

Comment #162 Removed by Moderator

To: Swordmaker
There's another thing really weird about this whole thing. What does the infected computers in this alleged "botnet" do? Has anyone seen it actually DO anything yet?

Granted, an infected computer appears to "check in" after infection -- that's the signature activity of a bot. So if the computers are doing that, it's a botnet, but a dormant one. I wonder, has anyone claimed yet to see it DO anything, like send spam or scareware (like Conficker), or claimed to find code in it that looks like it will do anything?


Meanwhile hysterical, inflammatory attack pieces like this are appearing:

Mac Malware Outbreak Is Bigger than 'Conficker' (PC World)

"To put the size of the threat in some perspective, the Flashback Trojan botnet is even bigger than the massive Conficker botnet…relatively speaking." ... "Based on market share, the Flashback Trojan botnet is equivalent to a Windows botnet of nearly 8.5 million PCs. That makes it an even larger threat than Conficker"

"A malware attack such as this has even greater odds of success on Mac OS X than it does on a Windows system." ... "the Mac culture is conditioned to believe the OS is virtually invulnerable. Fewer users have any security software installed to protect their Mac OS X systems," ... "It doesn’t help anything that Apple perpetuates the myth of invulnerability."

What a helpful article..... NOT!

And should this whole thing eventually be demonstrated to be a mistake or a fabrication from the anti-virus folks... will we see a retraction of these articles? Yeah, right.

163 posted on 04/07/2012 7:38:38 AM PDT by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 160 | View Replies]

To: Swordmaker

How many were RINOs and MITTBOTS?


164 posted on 04/07/2012 8:14:05 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 156 | View Replies]

To: Swordmaker

btw to my point I said liberal not Democrat. And I read a survey where liberals preferred Apple and Conservatives preferred Google. Looks like you are the one making up myths.


165 posted on 04/07/2012 8:17:04 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 156 | View Replies]

To: dayglored

Sorry, dayglo. My brain must have in a blender.

Not thinking very clearly these days.


166 posted on 04/07/2012 8:18:53 AM PDT by jacquej
[ Post Reply | Private Reply | To 120 | View Replies]

To: jacquej
> Sorry, dayglo. My brain must have in a blender. Not thinking very clearly these days.

Thanks, no problem. :) I hope things clear up for you.

167 posted on 04/07/2012 8:30:21 AM PDT by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 166 | View Replies]

To: dayglored
"To put the size of the threat in some perspective, the Flashback Trojan botnet is even bigger than the massive Conficker botnet…relatively speaking." ... "Based on market share, the Flashback Trojan botnet is equivalent to a Windows botnet of nearly 8.5 million PCs. That makes it an even larger threat than Conficker"

Relatively speaking... RIGHT... and we can't even find an infected computer yet! This is all based on reports from links into an INTERCEPTED BOTNET control server that Doctor Web claims to have identified and somehow hijacked! Doctor Web now even claims the ability to take your UUID from your Mac, hook up to the Member UUID data base in the hijacked Botnet control server where ever it is located, and check your computer against the database to see if it is registered as a member of the bonnet! How is this possible? They have publicized this and the criminals have not CLOSED this door???

Several persons have reported that they have used the tools to show that their computers are completely clean, but Doctor Web reports they are members of the botnet. This is highly suspicious. One reported that he had just completed running the check script, found his four Macs clean of the Flashback Trojan (two of which were OSX Lion and did not even have JAVA installed on them, but checked just for thoroughness) and then ran all four UUIDs through Doctor Web's on-line Database checker and ALL FOUR were reported as being members of the BotNet!!!

This goes back to my suspicion that we are seeing a carpet bomb attack with someone spoofing the attacks using UUIDs generated in the range known to be OSX Macs. That matches not seeing large numbers of infected Macs showing up on the forums.

168 posted on 04/07/2012 1:04:51 PM PDT by Swordmaker
[ Post Reply | Private Reply | To 163 | View Replies]

To: Swordmaker
Well, there will be some serious egg on some Russian anti-virus "experts" faces if this turns out to be a false alarm.

Of course, the damage in the public eye will have already been done, so they will still be paid their fee for "discovering" the problem.

Wanna bet on the spike in 3rd-party Anti-Virus-for-Mac in the past few days?

What? Me cynical? Moi???

Here's how cynical I am. I would bet -- if this turns out to be fake -- that if you could trace the money ALL the way back, it would start somewhere in Washington State.

But I'll withhold that bet until we see if this botnet is real or not. I really would hate to think that even Ballmer, desperate as he is these days, would stoop that low.

169 posted on 04/07/2012 2:03:59 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 168 | View Replies]

To: dayglored
There's another thing really weird about this whole thing. What does the infected computers in this alleged "botnet" do? Has anyone seen it actually DO anything yet?

Well, according to Kaspersky, it's being used for "Click fraud"... what a waste. I simply don't believe it even exists. I am STILL not finding any credible Mac users reporting they are infected! None. Zero! Nada. Where are they? Where are the panicked users?????????

170 posted on 04/07/2012 4:09:09 PM PDT by Swordmaker
[ Post Reply | Private Reply | To 163 | View Replies]

To: for-q-clinton
I need to make sure people don’t believe those fools.

Why do you feel it is your personal responsibility to look out for those fools?

171 posted on 04/07/2012 4:18:05 PM PDT by itsahoot (Tag lines are a waste of bandwidth, as are most of my comments.)
[ Post Reply | Private Reply | To 124 | View Replies]

To: itsahoot

Same reason a person volunteers at a food bank I guess. Just helping my fellow man.


172 posted on 04/07/2012 6:47:05 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 171 | View Replies]

To: Swordmaker

Denial is one of the many stages you will go through. The quicker you move to the next stage the quicker you can heal.

I’m sure if apple thought this was fake they’d correct the record. They have said it was fake or a non issue so it must be true.


173 posted on 04/07/2012 6:50:45 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 170 | View Replies]

To: for-q-clinton
Just helping my fellow man.

Then maybe you should recognize that we Mac Addicts don't want to get clean, and let it go at that. I have never hunted for a Windows addict group and tried to get them to kick the bill.

174 posted on 04/08/2012 6:40:06 AM PDT by itsahoot (Tag lines are a waste of bandwidth, as are most of my comments.)
[ Post Reply | Private Reply | To 172 | View Replies]

To: itsahoot

Then kindly ignore my post. I’m just helping all those kind macbots that posted in windows threads when a virus on XP was announced and instead of saying the logical stuff like get the latest version of windows they said Macs can’t get malware. So I’m really helping those folks out by repaying the favor.


175 posted on 04/08/2012 7:49:27 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 174 | View Replies]

To: for-q-clinton
I've been searching the forums and news reports all weekend, 4q, and I am STILL not seeing anyone with a Mac posting anything along the lines of "Help! I'm infected with the Flashback Trojan/virus/malware/worm etc.! How do I get rid of it?" None! Nada! Zip!

This has not even been the case when there were claimed proof-of-concept viruses announced that we're NEVER even in the wild; there were people who thought they had them. This time NOTHING except a few obvious trolls who don't even know how to spell Mac or claim they spent three grand for their now infected iMac.

176 posted on 04/08/2012 5:46:12 PM PDT by Swordmaker
[ Post Reply | Private Reply | To 173 | View Replies]

To: Swordmaker

Well I bet even if you do see that you’d dismiss it just like null and voids issue.

I’m sure if this was a fabrication apple would correct the record. I’ve searched apple’s website and forums and have found no corrections. But I did see where they patched the vulnerability 8 weeks late. Until apple corrects the record we have to assume it’s true.


177 posted on 04/08/2012 5:59:37 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 176 | View Replies]

To: for-q-clinton
The vulnerability existed. Apple patched it.

You know very well Apple never comments as you want them to. What I am saying is that the hype given to this "exploit" simply does not match the apparent level of user reports being posted. And so far we are looking at only a single source—although confirmed by analysis of their released data by other security firms—news story. That one source which somehow has TOO MUCH access to the botnet server, now providing users with direct checking if your OSX Mac is infected by comparison to the list of UUIDs in the Botnet Server's database! Just how is that possible???? And KNOWN CLEAN Macs are reported to be in that database, including Macs that didn't even have JAVA installed in them! BAH!

178 posted on 04/08/2012 8:03:03 PM PDT by Swordmaker
[ Post Reply | Private Reply | To 177 | View Replies]

To: Swordmaker

Well apparently Apple never had to respond to this stuff before but now that they are getting more and more cases of malware in the wild they need to reconsider as this isn’t any old lie any longer.

Apple would be wise to respond and take a page out of Microsoft’s book. They learned after several years of ignoring it that they need to address these things head on. But then again with OSX really only competing with XP I can see Apple has a ways to go in its maturity before they realize how they should respond.


179 posted on 04/09/2012 7:51:22 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 178 | View Replies]

To: Swordmaker
Just downloaded Flashback Checker from Github.com. "No Infection Found." Quick, easy download. And free.

Nearly 100K downloads of "Flashback Checker" at this point. Would be interesting to find out how many did in fact have this "infection." In my circle of friends who use Apple, no one has been hit with it.

180 posted on 04/10/2012 5:04:16 AM PDT by donozark (We're ALL Greeks now...and possibly, quite soon, Portugese.)
[ Post Reply | Private Reply | To 178 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 121-140141-160161-180181-185 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson