Mac OS X backdoor Trojan, now in beta?

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
It appears there is a new backdoor Trojan in town and it targets users of Mac OS X. As even the malware itself admits, it is not yet finished, but it could be indicative of more underground programmers taking note of Apple's increasing market share.
bhrat1-250.png


SophosLabs analyzed the sample we received and determined that it is a variant of a well-known remote-access trojan for Windows known as darkComet.

The Mac version is very basic and there appears to be a mix of German and English in the user interface. Its functions include:

  • Placing text files on the desktop
  • Sending a restart, shutdown or sleep command
  • Running arbitrary shell commands
  • Placing a full screen window with a message that only allows you to click reboot
  • Sending URLs to the client to open a website
  • Popping up a fake "Administrator Password" window to phish the target
bhrat2-475.png


Here is an excerpt from the default text that is displayed in the full screen window with the reboot button:

"I am a Trojan Horse, so i have infected your Mac Computer. I know, most people think Macs can't be infected, but look, you ARE Infected!
I have full controll over your Computer and i can do everything I want, and you can do nothing to prevent it.
So, Im a very new Virus, under Development, so there will be much more functions when im finished.


Continue Reading
 

Valentin N

Level 2
Feb 25, 2011
1,314
Jack said:
It appears there is a new backdoor Trojan in town and it targets users of Mac OS X. As even the malware itself admits, it is not yet finished, but it could be indicative of more underground programmers taking note of Apple's increasing market share.
bhrat1-250.png


SophosLabs analyzed the sample we received and determined that it is a variant of a well-known remote-access trojan for Windows known as darkComet.

The Mac version is very basic and there appears to be a mix of German and English in the user interface. Its functions include:

  • Placing text files on the desktop
  • Sending a restart, shutdown or sleep command
  • Running arbitrary shell commands
  • Placing a full screen window with a message that only allows you to click reboot
  • Sending URLs to the client to open a website
  • Popping up a fake "Administrator Password" window to phish the target
bhrat2-475.png


Here is an excerpt from the default text that is displayed in the full screen window with the reboot button:

"I am a Trojan Horse, so i have infected your Mac Computer. I know, most people think Macs can't be infected, but look, you ARE Infected!
I have full controll over your Computer and i can do everything I want, and you can do nothing to prevent it.
So, Im a very new Virus, under Development, so there will be much more functions when im finished.

WoW interesting reading.

Jack could you give me the link to this or where the virus can be obtained? I want to give this to comodo labs

Thanks.

Regards,
Valentin N
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
I added "Continue Reading" at the bottom on original post with the Source link.
 

LoftedAphid86

New Member
Feb 24, 2011
1,107
AyeAyeCaptain said:
I bet more and more people will start to make/write/attack due to their INSANE pricing structure... LOL
Do you mean Apple's?
If you do, then I totally agree with you. :biggrin:
 

Chiron

Level 1
Feb 24, 2011
250
There is already a lot of malware written for Macs. I mean nowhere near that for Windows, but as the market share grows so will the number amount of malware.

It's all just a question of profit.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top