Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

The First Mac OS X Virus? (A New OS X Trojan)
MacRumors.com ^ | 02/16/2006

Posted on 02/16/2006 5:27:22 AM PST by Panerai

On the evening of the 13th, an unknown user posted an external link to a file on MacRumors Forums claiming to be the latest Leopard Mac OS X 10.5 screenshots. The file was named "latestpics.tgz"

The resultant file decompresses into what appears to be a standard JPEG icon in Mac OS X but is actually a compiled Unix executable in disguise. An initial disassembly (from original discussion thread) reveals evidence that the application is virus-like or was designed to give that impression. Routines listed include:

_infect: _infectApps: _installHooks: _copySelf:

The exact consequences of the application are unclear, but according to the users that originally executed the application have noted that it appeared to self propogate:

If anyone remembers last night, when lasthope spread that picture that opened in terminal. I just turned on my other computer and it said it had an incoming file, from my computer, which was the latest pics file. Any help. I have already secure deleted it off of my harddrive, but how do i know that it will not come back. Andrew Welch who had done some of the initial disassembly is posting updates to this thread.

According to the initial investigation, the application uses Spotlight to find the other applications on the infected machine and subsequently inserts a stub of code into each application executable.

Update: It appears that there is some debate about the classification of this application, and as it does require user activation, it appears to fall into the Trojan classification, rather than self-propogating through any particular vulnerability in OS X.


TOPICS: Technical
KEYWORDS: apple; mac; osx; spyware; trojan; virus
Navigation: use the links below to view more comments.
first 1-2021-4041-51 next last

1 posted on 02/16/2006 5:27:23 AM PST by Panerai
[ Post Reply | Private Reply | View Replies]

To: Swordmaker

OSX Trojan


2 posted on 02/16/2006 5:28:32 AM PST by Panerai
[ Post Reply | Private Reply | To 1 | View Replies]

To: Panerai

So it's not a virus.


3 posted on 02/16/2006 5:34:36 AM PST by HAL9000 (Get a Mac - The Ultimate FReeping Machine)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Panerai
There is no virus written for Unix. Its obvious since to get a program installed, you need to log on as a superuser in Linux/Mac OS X. I still don't have an antivirus program on either my Linux laptop or Mac Mini since there doesn't appear to be any instance of a successful Unix virus in the wild. I think this is a hoax.

(Denny Crane: "I Don't Want To Socialize With A Pinko Liberal Democrat Commie. Say What You Like About Republicans. We Stick To Our Convictions. Even When We Know We're Dead Wrong.")

4 posted on 02/16/2006 5:36:58 AM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TexasGreg

Ping - Gottcha


5 posted on 02/16/2006 5:38:50 AM PST by GarySpFc (de oppresso liber)
[ Post Reply | Private Reply | To 1 | View Replies]

To: goldstategop
Boo!


6 posted on 02/16/2006 5:39:00 AM PST by IncPen (Torture should be safe, legal, and rare.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: HAL9000
So it's not a virus.

But you're missing the point! Macs are no longer immune! (Oh, happy day!) ;^>

7 posted on 02/16/2006 5:41:25 AM PST by papertyger
[ Post Reply | Private Reply | To 3 | View Replies]

To: papertyger
Your wrong. The program had to prompt the user to enter his password. I.E. the user has to allow the installation off the program. No computer in existence is 'immune' to a user installing something deliberately. Macs never were immune to that so their 'immunity' has not changed.
8 posted on 02/16/2006 5:47:13 AM PST by TalonDJ
[ Post Reply | Private Reply | To 7 | View Replies]

To: Panerai

Getting closer to the first self-propagating worm. It'll happen eventually. Still, five years into OS X and we're still waiting for the first one.


9 posted on 02/16/2006 5:48:29 AM PST by antiRepublicrat
[ Post Reply | Private Reply | To 1 | View Replies]

To: TalonDJ

Lighten up, Francis. Do you not know what ;^> means?


10 posted on 02/16/2006 5:51:36 AM PST by papertyger
[ Post Reply | Private Reply | To 8 | View Replies]

To: antiRepublicrat
You have to get past the root user. Most people in Unix don't have to run as root so you can't download or install anything. That makes these computers inherently much more secure than Windows. And malware written for Unix can't harm Windows and vice versa.

(Denny Crane: "I Don't Want To Socialize With A Pinko Liberal Democrat Commie. Say What You Like About Republicans. We Stick To Our Convictions. Even When We Know We're Dead Wrong.")

11 posted on 02/16/2006 5:53:40 AM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 9 | View Replies]

To: antiRepublicrat

Why not issue a challenge for someone to develop such a worm or virus? That would prove interesting.


12 posted on 02/16/2006 5:57:36 AM PST by TommyDale
[ Post Reply | Private Reply | To 9 | View Replies]

To: papertyger
But you're missing the point! Macs are no longer immune! (Oh, happy day!) ;^>

Immune? Did you read what the users had to do to get this thing running on their machine? ANYONE can write a program that ASKS to be installed with admin privilege that then does nefarious things.

Surf a website and have a OS X system compromised, then come talk to me.

13 posted on 02/16/2006 6:15:28 AM PST by SengirV
[ Post Reply | Private Reply | To 7 | View Replies]

To: TommyDale
Why not issue a challenge for someone to develop such a worm or virus?

Somebody started one a while ago, but withdrew the offer due to legal reasons.

14 posted on 02/16/2006 6:21:19 AM PST by antiRepublicrat
[ Post Reply | Private Reply | To 12 | View Replies]

To: goldstategop
You have to get past the root user.

That makes it hard, but not impossible. The first successful worm will probably use one exploit as a delivery method in conjunction with a privilege-escalation exploit to install and propagate.

15 posted on 02/16/2006 6:24:12 AM PST by antiRepublicrat
[ Post Reply | Private Reply | To 11 | View Replies]

To: Panerai

This oughta make Apple happy, actually ... it means that they're getting popular enough for people to write viruses for them. Their market share may be heading north soon....


16 posted on 02/16/2006 6:25:30 AM PST by r9etb
[ Post Reply | Private Reply | To 1 | View Replies]

To: goldstategop

Yes i never seen a virus on a unix or linux box, but i wouldnt be doubting someone out there is trying to exploit one of the thousands of security vulnerabilities on MAC OSX.... OSX might be based on BSD, but soon as steve jobs adds all those pretty bells and whistles to the operating system and complicates and bloats the code, there is bound to be some serious security flaws.


17 posted on 02/16/2006 6:26:33 AM PST by Element187
[ Post Reply | Private Reply | To 4 | View Replies]

To: SengirV

No, no, NO! Macs are not safer! Lalalalalalalala. I can't hear you...


18 posted on 02/16/2006 6:34:03 AM PST by papertyger
[ Post Reply | Private Reply | To 13 | View Replies]

To: Element187
but soon as steve jobs adds all those pretty bells and whistles to the operating system and complicates and bloats the code, there is bound to be some serious security flaws.

Empirical evidence would seem to indicate otherwise...

19 posted on 02/16/2006 6:37:45 AM PST by papertyger
[ Post Reply | Private Reply | To 17 | View Replies]

To: papertyger

In order to install this virus you must enter your user name and password.


20 posted on 02/16/2006 6:41:05 AM PST by SlowBoat407 (The best stuff happens just before the thread snaps.)
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-51 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson