Mac OS X backdoor Trojan, now in beta?

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Forum Veteran
Jan 24, 2011
9,380
1
24,874
8,379
malwaretips.com
It appears there is a new backdoor Trojan in town and it targets users of Mac OS X. As even the malware itself admits, it is not yet finished, but it could be indicative of more underground programmers taking note of Apple's increasing market share.
bhrat1-250.png


SophosLabs analyzed the sample we received and determined that it is a variant of a well-known remote-access trojan for Windows known as darkComet.

The Mac version is very basic and there appears to be a mix of German and English in the user interface. Its functions include:

  • Placing text files on the desktop
  • Sending a restart, shutdown or sleep command
  • Running arbitrary shell commands
  • Placing a full screen window with a message that only allows you to click reboot
  • Sending URLs to the client to open a website
  • Popping up a fake "Administrator Password" window to phish the target
bhrat2-475.png


Here is an excerpt from the default text that is displayed in the full screen window with the reboot button:

"I am a Trojan Horse, so i have infected your Mac Computer. I know, most people think Macs can't be infected, but look, you ARE Infected!
I have full controll over your Computer and i can do everything I want, and you can do nothing to prevent it.
So, Im a very new Virus, under Development, so there will be much more functions when im finished.


Continue Reading
 
Jack said:
It appears there is a new backdoor Trojan in town and it targets users of Mac OS X. As even the malware itself admits, it is not yet finished, but it could be indicative of more underground programmers taking note of Apple's increasing market share.
bhrat1-250.png


SophosLabs analyzed the sample we received and determined that it is a variant of a well-known remote-access trojan for Windows known as darkComet.

The Mac version is very basic and there appears to be a mix of German and English in the user interface. Its functions include:

  • Placing text files on the desktop
  • Sending a restart, shutdown or sleep command
  • Running arbitrary shell commands
  • Placing a full screen window with a message that only allows you to click reboot
  • Sending URLs to the client to open a website
  • Popping up a fake "Administrator Password" window to phish the target
bhrat2-475.png


Here is an excerpt from the default text that is displayed in the full screen window with the reboot button:

"I am a Trojan Horse, so i have infected your Mac Computer. I know, most people think Macs can't be infected, but look, you ARE Infected!
I have full controll over your Computer and i can do everything I want, and you can do nothing to prevent it.
So, Im a very new Virus, under Development, so there will be much more functions when im finished.

WoW interesting reading.

Jack could you give me the link to this or where the virus can be obtained? I want to give this to comodo labs

Thanks.

Regards,
Valentin N
 
I added "Continue Reading" at the bottom on original post with the Source link.
 
There is already a lot of malware written for Macs. I mean nowhere near that for Windows, but as the market share grows so will the number amount of malware.

It's all just a question of profit.
 
Status
Not open for further replies.

You may also like...