Jump to content
The Inquirer-Home

iWork trojan turns Macs into Zombies

But they are too stupid to notice
Monday, 20 April 2009, 17:16

TWO INSECURITY researchers have found a botnet which is populated by Apple Mac owners who are too smug to realise that they are vulnerable.

According to Virus Bulletin the botnet was created by a flaw in the super secure Apple software iWork 2009 trial version. It was an illegal copy which was appearing on the file sharing networks. However since Apple tells users that no one has ever come up with a virus for their super secure software, many Apple users downloaded it.

Since most Apple users don't have virus protection at all, because they think their operating system is somehow safe, the virus spread like wildfire.

Two researchers, Mario Ballano Barcena and Alfredo Pesoli, have now discovered two separate variants of the malware, each using distinct techniques to compromise users' machines.

The botnet is being used to launch denial of service attacks on websites.
What is amusing is that the smug members of the botnet are blissfully unaware that they have a virus, simply because they have a faith that Apple code is secure.

Security experts have been warning for ages that the only reason that Apple code is 'safe' is because virus writers don't bother with obscure operating systems. This is because it is hard to get distribution over a large number of minority operating systems.

However, downloading Apple software from P2P sites is a good method of getting machines infected and then distributing the code to other Apple users. µ


L'INQ
PCWORLD

Share this:

Comments
JAJAJA

This is just too awesome to be true!
It was about time someone got it out on the open. They have been daring people, and now that dare has been taken. I wonder if apple has enough money to spend on research in security.

posted by : missingxtension, 20 April 2009 Complain about this comment
Pshhh.

It's a lie. We all know that Mac users know better.

posted by : Mat, 20 April 2009 Complain about this comment
Slow news week

Must be a slow news weeks this was out 2 weeks after iWork 09 and the fix was out a week after. Trojans are not new to Mac OSX and like a Windows Trojan relies on user stupidity and greed.
There is a similar Trojan that presents itself as a Quicktime plugin that also requires the user to enter there administrator password. I am sure this will be reported on the next slow news week.

"I i am a trojan click me to install, please click again to give me full access to your operation system and enter your password."

posted by : Jeri, 20 April 2009 Complain about this comment
Botnet? only in the imaginary plane.

What trojan attack and botnet?
Looks like this couldn't have come at a worse time for Apple after their smug rebuttal of the windows laptops - http://forums.appleinsider.com/showthread.php?threadid=97382

posted by : bitten fruit, 20 April 2009 Complain about this comment
Yeah, but this is in no way a 'virus', is it?

It's a rogue piece of software that's designed to do bad things, that the user has to install, for them selves. Calling that a 'virus' is like saying self-inflicted hammer injuries might be infectious. The fact that lots of Mac users are, apparently, all capable of whacking themselves with the same a hammer is no doubt amusing, but to call this an 'outbreak' of anything other than stupidity is a lie. I really think you stretch the bounds of reality to quite bizare limits, in order to assert your world view, Farrel. Don't just lie, and get things wrong, in order to make a headline. That's a lame way of getting page views. Anyway, the Register reported this one last month. What the hell were you doing, back then? If you're gonna be wrong at least try to keep up.

posted by : Daniel, 20 April 2009 Complain about this comment
Not possible

Nah, you're lying. My CPU usage is constantly 100%, OS X runs slow as hell, so what? Job said Macs don't get virus, so they don't! Period. Must be bad energy vibrations from my neighbor's Windows PC.

posted by : ssj4Gogeta, 20 April 2009 Complain about this comment
There's something

Very satisfying about this article, can't quite put my finger on it. Oh that's it Mac's aren't as good as their fanbois think they are. This is written on a MacBook and I'm under no illusions as to how crap it is. Cracked case, palm rest split, SMB can hang this thing quicker than Judge Jeffreys.Quality my arse.

posted by : Efros, 20 April 2009 Complain about this comment
Verily!

Woe be to the "Fair-U-See" who believeth that he is saved by iWorks' 2009 trial versions, alone; for he shall soon be the "Sad-U-See". Blessed be the applestolic who have the fave; for theirs is the kingdom of smug! What doth it profit Stephen? Even so fave, if it hath not iWorks, is not diad, being alone. The PCs also believe, and tremble. Apps 2:12

posted by : Nickodamnus, 20 April 2009 Complain about this comment
Not A Virus, ooooooldddddd, funny non the less

This is supper old, its a Troyan (its not the same, right ?), and i kinda disliked "wasting" my time reading the same line again and again (apple fanbois think they cant get virus, they dont know they have virus, etc)

pd: i do have a macbook, but i do have 4 pcs too :P

posted by : Roberto, 20 April 2009 Complain about this comment
Yawn

Why does anyone care so much what brand of computer another person has? Why would anyone be happy that a particular operating system is just as insecure as their own. They are F&cking computers. Greedy f&cktards who try and get free software are greedy f&cktards whether it's MS or OSX under the hood. Or anything else for that matter.
Yipes, if you like mac and it works for you good-o. If you are content with your Windows machine then just as good-o. If you prefer the penguin, that's marvelous too.

...I suspect the strange glee at any negative news to do with the fruit, is due to nothing more than jealousy about the conspicuous wealth required to own one.

posted by : CP, 20 April 2009 Complain about this comment
ROTFLMAO

can I be the first to christen this "Smugware"?

posted by : TimB, 20 April 2009 Complain about this comment
Super secure Apple software!

Jaja. Beware of what you click on Apple fanboy! Apple users see: install Malware? (yes or yes) lol. Naa OSX is DA creme, that are just rumors so just click yes to all and no worries cuz you will never know! ;b

posted by : Gerald, 20 April 2009 Complain about this comment
Nick . . .

I double triple dog dare you to write one positive thing about Apple. Can you? . . . I think not.

posted by : Garrett, 20 April 2009 Complain about this comment
8793893949 viruses 1 virus

OS X got a virus on it so Macs suck and I should never buy one. Got it.

Try to write an article where you don't appear to be an arrogant prick.

I hope Windows always stays on top so that I can continue to worry about 1 virus a year in OS X.

posted by : A normal person, 21 April 2009 Complain about this comment
LIES! DAMN LIES!!!

I'm a fan-boy and I know one thing ....... ***sticking my fingers in my ears**** going LALALALALALALA! - No virus existed for my Fruity loops EVER! LALALALALA

posted by : I know, 21 April 2009 Complain about this comment
botnet

Loving all the people who are claiming its not a virus or that its 'old news'...

Yes, the two seperate trojans have been known about for some time - what's news is that when combined they open a back door in your system for inclusion in a botnet.

The botnet is thought to have infected 20,000 macs and confirmed to have been used in two DDoS attacks.

So yeah. Macs need security too.

posted by : Locastus, 21 April 2009 Complain about this comment
@Locastus

No anti virus software in the world can prevent a user from clicking install and entering there admin password.

This trojan has been about for quite a while now and the removal tool was out very shortly after and well publicized. That 20,000 Mac users have been tech savvy enough to torrent iWork, and/or the porn Quicktime plugin yet have been unable to execute the removal tool is beyond stupidity. Though the products are targeted at the consumer end of the Mac market and the most likely victims of this will be the "switchers" that even on there Windows system if something popped up on there screen saying "press me i am a trojan and want to be installed" well need i go on.
Give a idiot a saw and he will cut his finger, give a idiot a power saw and he will cut of his arm and when asked why he will say "Because the power saw advertised it was safe to use."

posted by : Jeri, 21 April 2009 Complain about this comment
@Jeri

"Though the products are targeted at the consumer end of the Mac market and the most likely victims of this will be the "switchers" that even on there Windows system if something popped up on there screen saying "press me i am a trojan and want to be installed" well need i go on"

Wow, what kind of an elitist pr!@k are you? Now there are two kinds of Mac users, the real ones who are all knowing and would never get a virus, and those stupid former windows users.

So I guess now you have to be born into a Mac family or you will always be "one of them.:

posted by : Ron, 21 April 2009 Complain about this comment
@Ron

Don't spout nonsense if you have no argument. I made my opinion based on fact.

There are many different computer users and one group happens to be non tech savvy to click though all the warnings these are not necessarily Mac or Windows users but users in general that just don't have a clue or don't want to.

You know the type that only use MS Office at work but call it Windows, there out there and no mater how safe or secure the platform is user ignorance and stupidity will bring it down.

posted by : Jeri, 21 April 2009 Complain about this comment
Welcome.

@ Jeri

I'm guessing you've never used AV software before then, because that's exactly what it does. Sometimes even before you can download it, it becomes blocked. Other times the moment it's downloaded it's gone. You go to double click on it and it's not there. You can't click install on a program that's not there...... rookie MAC user mistake though, don't worry you'll get used to it.

posted by : Bounty, 21 April 2009 Complain about this comment
@Bounty

Ran Windows, Linux, Solaris, and Mac OS machines for years, well actually i am a rather new Mac user as i only considered it a option once i stopped PC gaming and was looking for a serious workstation and laptop combo.
And yes i have had the misery of having to deal with anti virus software and even before there was such things as dual core CPUs where i would have to stop everything to let it scan my hard drive. I have been though a lot of the major Windows virus and have dealt with the removal of many virus and trojans coming from Windows 95 - XP and more recently Vista business 64bit.

Heres the interesting bit, Anti virus does not work on trojans 100% because trojans rely on user stupidity and when i was young the rather tempting "download me i am the movie you want" sometimes had a nasty payload with it.
Also for Anti virus software to work it has to know what the virus/trojan is and how to remove it that does not happen the moment the virus is in the wild and very often for trojans and worms anti virus companies release a removal tool as has happened with this trojan.

It is a rather big assumption that i am a mac user also, though i do use two macs for work i also have a Solaris workstation, 2 linux servers, and a Windows box for gaming. Soon the Solaris box will be retired as i can run its software natively on OSX being there both Unix and the testing of my software is almost complete.

posted by : Jeri, 22 April 2009 Complain about this comment
Apple make pc's.

They use the exact same hardware as a "windows" pc, except the Mac hardware costs 50% more.

Macs are also "Made in China", in cheap Chinese factories, by low paid Chinese workers.

The Mac OS is just some software, like Windows is just some software. They are all written by fallible humans.

@Jeri, I doubt you have learned your "getting infected" lessons. Do you run AV on your Mac or just hope for the best?

And admit you're a total Apple fanboy, I've seen several pro-apple comments from you today.

All of our hardware and software is made by regular joes, no matter how much we pay or believe the marketing.

Don't believe the hype, try not to get sucked in, or take this too seriously.

posted by : interested_party, 22 April 2009 Complain about this comment
not yet.

The challenge was to create a self-propagating VIRUS. Trojans have existed for Macs (and every other operating system, no matter HOW secure) for years. However, they still need human intervention to install, and there's nothing one can do to protect from luser stupidity.

So sorry, still waiting for a Mac virus. Let me know when (not if) it happens. Because it will, some day. But today is not that day.

posted by : Marc, 22 April 2009 Complain about this comment
@interested_party

To be a fan i would have to consider my computers as idols to follow when in truth i go with the best for the software i run and my productivity.
With my macs i can consolidate my aging Solaris applications and use my design apps on one box and even maintain my Linux servers and boot into Windows for 3D max on one computer. Not only do i get the best of all worlds i do it extremely cheaply as it works out more expensive for the same hardware from other companies.

And no i do not run Anti virus software on Solaris, Linux nor Mac OS as currently there only use is to remove Windows virus. Once there is a Virus for any of these systems then i will look at getting a Anti virus solution until then since they would not know what to do with and do not scan for Virus on these platforms that is a pointless endeavor.

Asking some one to admit to being a fanboy i have to cover again, Why?
What is the porpoise of being a fanboy of a manufacturer?
Is this not best saved for the console kids or must professional computer users also pwan imba 1337 haxxors my os is better than yours?

And further the point of my original comment in this story that you may have missed is that this is very old news that has been pulled out of the writers ass to generate traffic. This happened months ago and the fix was released by several anti virus companies and other solutions were released by other users of Mac OSX.

It would be like reporting on a trojan that infected Windows 3 months ago, has long since been dead and burred but some idiot users did not use the removal tool so are still blissfully being bots witch when it comes to computer users happens more often than not and no having anti virus software installed will not help the Mac users with this trojan as they do not scan for it, the scan for Windows virus to stop that spreading when sharing documents.

Downloading the removal tool or following a removal guide are the only solutions other than not downloading illegal software to begin with especially when its only £50 for a license.

posted by : Jeri, 22 April 2009 Complain about this comment
@Jeri

I'm curious, what "facts" do you have to suppourt your theory that it is former windows users that are most likely to be the victims of this trojan? If you can back up this argument then I will change my opinion, but until then I believe that the percentage of stupid users on OSX and Windows is the same.

posted by : Ron, 23 April 2009 Complain about this comment
mac user 4life

i love it apple makes computers and there os x system Microsoft makes software not computers just cause you cant afford a mac don't dig up rumors of stupid people that give the outside world access to there computer i had a pc running windows xp and all i did was login to my yahoo email and got a computer crashing virus i sometimes see my download window pop up when i login to yahoo or other sites on my mac
but it cant get access to my mac so pc users enjoy your disease catching hookers and further more who cares anyway

posted by : christopher , 13 October 2009 Complain about this comment
Advertisement
Subscribe to the INQ Newsletter
Sign-up for the INQBot weekly newsletter
Click here to sign up Existing user
Advertisement
INQ Poll

Windows 7 impressions

How is windows 7 working out for you?