New trojan Horse on OS X

http://www.macworld.com/news/2007/10/31/trojan/index.php

Security research company Intego on Monday issued a security alert about a new Trojan Horse called OSX.RSPlug.A that specifically targets Mac users. The Trojan is a form of DNSChanger that changes the Mac’s Domain Name Server (DNS) address.

According to Intego, the Trojan has been found on several pornographic Web sites. When trying to view a movie, the user is told that “Quicktime Player is unable to play movie file. Please click here to download new version of codec.”

When the user clicks the link a disk image (.dmg) is downloaded to the desktop. When the user installs the software, they are actually installing the Trojan, not a free video codec. The Trojan is installed with full root privileges, which means it has access to all files and commands on the system.

When the malicious DNS server is active, it hijacks some web requests, leading users to phishing web sites (for sites such as Ebay, PayPal and some banks) or to web pages displaying ads for other pornographic web sites, according to Intego.

The Trojan also installs a root crontab which checks every minute to ensure that its DNS server is still active, the company said. Since changing a network location could change the DNS server, this cron job ensures that, in such a case, the malicious DNS server remains the active server.

Obviously its ITW. I hope ALWIL got a sample to add to the VPS.

Wonderful news here (read Vlk’s respond):

http://forum.avast.com/index.php?topic=30519.msg259420#msg259420

Details on the Sunbelt Blog:

http://sunbeltblog.blogspot.com/2007/10/mac-trojan-overhype-you-tell-me.html

http://sunbeltblog.blogspot.com/2007/10/screenshot-of-new-mac-trojan.html

http://sunbeltblog.blogspot.com/2007/10/mackanapes-can-now-can-feel-pain-of.html

Wll Id be intrested to know if it was included in the VPS update. As mac malware will most likely not be very widespread I wonder if there will be probelms getting samples to analyze?

Hey Mac, Is this anything for mac users to be concerned about?

http://www.news.com/8301-10784_3-9807471-7.html

Until this is fixed ( 10.5.1? ) it is an issue for those that do not have a router or some other kind of hardware firewall.

Thanks Mac.

UPDATE: There have been lots of new variants of this trojan created to avoid detection by AV scanners. I Hpe ALWIL is getting these Variants added to the VPS.

F-Secure Weblog in the variants:
http://www.f-secure.com/weblog/archives/00001312.html

I see various DNS changer itsms in the VPS changelog bt they are for the Win32 variants.

Win32:DNSChanger-OL [trj], Win32:DNSChanger-OM [trj], Win32:DNSChanger-ON [trj], Win32:DNSChanger-OO [trj], Win32:DNSChanger-OP [trj], Win32:DNSChanger-OQ [trj], Win32:DNSChanger-OR [trj], Win32:DNSChanger-OS [trj], Win32:DNSChanger-OT [trj], Win32:DNSChanger-OU [trj],

No mention of the OS X variants.

this malware downloads a specific variant of dnschanger dependant to OS… we got more windows samples than the mac ones… anyway - also the mac variant should be supported…

Also, malware researchers: You may be able to find the DNS Changer Trojan by going to a DNS changer codec site, and using “.dmg” as your file extension instead of “.exe”. As an example, vivacodec(dot)net/download/vivacodec1000.exe downloads the Windows trojan. But going to vivacodec(dot)net/download/vivacodec1000.dmg brings down the Mac binary. Remember to set your user agent to look like a Mac. (Obviously, don’t download these binaries unless you know what you’re doing.)

http://sunbeltblog.blogspot.com/

Happy hunting!

ook… we’ll try to download the files via wget or similar stuff… thanx

Update on the firewall problems.

It appears Apple is going to have the fix in the 10.5.1 update which has entered beta-testing:

http://www.appleinsider.com/articles/07/11/07/first_builds_of_mac_os_x_10_5_1_pack_over_two_dozen_fixes.html