The Inquirer-Home

Mac fake anti-virus malware is evolving fast, doesn't need a password

What works for Windows, works for Mac
Thu May 26 2011, 12:15

CRIMINALS RESPONSIBLE for fake anti-virus malware on Mac OS X have been hard at work, using techniques they've used on Windows versions of malicious software to make it that much more effective.

Two security vendors, Sophos and ESET, noticed that a new version of Macdefender is now in the wild that doesn't need an administrator password. First encountered at the beginning of May, the Trojan hits Apple users after they find their way to fake websites by following poisoned search results.

In its advisory over the issue, Apple said an administrative password prompt is a good time for a user to abort the installation of the fake anti-virus software. Now its attacks won't ask for a password, following a method used by criminals on Windows PCs to avoid user account control (UAC) warnings.

Now all you need to do is to follow a bad link via a poisoned search image result for an installation to start. Once installed, the malware prompts you for credit card details to purchase the software, which of course you should not do.

Dan Clark of ESET recommended that users disable the 'open safe file after downloading' option on Mac systems, at least until Apple releases the security update it recently promised.

Also known under names like Macsecurity and Macguardian, the threat has evolved significantly since it was first detected early this month. Windows PC users will be used to these types of threats, but Mac users might be more naive about the problems caused by this type of malware. µ

Share this:

Comments
Jobs responds...

This is a non-issue.

posted by : VrycekD, 28 May 2011 Complain about this comment
Consider this

"...but Mac users might be more naive about the problems caused by this type of malware..."

Mac users wouldn't be naive enough to download the thing in the first place. This malware is targeted at former Windows users who are highly sensitized to virus threats and therefore vulnerable to the "fear factor" this program is using to get people to fork over money and credit card info.

posted by : CMMC, 28 May 2011 Complain about this comment
For me it all seems like

This will be as anti-climactic as "antenna-gate." Apple was doomed, and the Microserfs rejoiced. Apparently Apple is once more doomed and the Microserfs are back rejoicing in full swing again.

Who knows, maybe Jobs was right, they're holding it the wrong way.

posted by : Drew, 27 May 2011 Complain about this comment
It is not!!

Are some of you daft? It is not a virus and it is not malware!! It is a phishing scam plain and simple. It may download itself but you still need to agree to open it and click continue.

posted by : dan goode, 26 May 2011 Complain about this comment
As a former Apple employee

What I found so amusing when I went to work for a local Apple Store was that every Mac in the store used Norton AV! If Apple believed their own claims, then why does every Mac on Apple's network use Norton? When I pointed this out, the Apple faithful working there informed me of my error. Even when I opened Norton's app on the Mac, they faithful refused to see it and dismissed it as if it was not installed! AMAZING FAITH THEY HAVE!

The lesson learned here is simple:

99% of all computer infections is because of the end user no matter the OS.

Apple should be leading the charge and suggesting that all Mac users use some type of AV. maybe Apple will follow M$ lead and offer a free AV app

posted by : Dave J, 26 May 2011 Complain about this comment
How do you get a virus on Windows today?

Every MAC person I talk to switched to a MAC because they heard you cant get viruses on it. When I asked when was the last time you got a Virus on windows the answer is always well I never got a Virus on windows because I ran anti-virus. My anti-virus application told me what a great job it was doing. Wait so you switched to mac because they dont get Viruses but you didn't get a virus on your PC the entire time you owned it? Yea but I got popups all the time. Well my friend that's called selling you on buying their Anti virus product again. Most AV applications want to tell you what a great job they are doing so you are either scared into buying it again or so you think how great its doing and buy it. Whats worse is they generally have the free AV software which isnt full blown anti-virus application which does nothing but show popup adds telling you to buy their product over the AV only free version.

If I didnt frequent the dark side of the internet ever so often I never would get a virus warning on my computer. Windows is not full of viruses and I would rather have a PC with an Alarm system than a MAC with no alarm. MAC's are like leaving your front door wide open do it long enough and you will come home to find all your stuff gone and the best part is you had no alarm for them to trigger. Enjoy your mac.

posted by : Mitchell, 26 May 2011 Complain about this comment
At Apple Users (inc LPF)

@LPF: In all probability, it is highly likely that I have a much greater knowledge of general and scientific computing than you can possibly fathom. In my aged cognizance, Windows 95 is still new and thus I wish you the best endeavours in any efforts to outwit me.

In respects of the demarcation between a Virus, Malware and Trojan, it should be obvious that in all instances, whether it be solicited or unsolicited, that it is the vector who brings about the exogenous infection. In all occurrences, this results in a compromised digital ecosystem, one in which the infectious agent bears the ability to replicate and disseminate at will, if designed so. However, in order to compromise another digital ecosystem, the infectious agent will require a new vector, whether it be autonomous or dependent. Please do not let computing terminology obscure the distinction between infectious agents, vectors and a compromised system. The vector in this occurrence appears to be an indirect browser flaw derived from a compromised GUI design. Additionally, Apple Inc. have contributed to the information asymmetry that exists within the computing community via inappropriate marketing and this has indirectly unwritten the theory of moral hazard amongst its users.

Thus, unknowingly, Apple users are effectively sitting ducks…

p.s. The MSCE has expired…

posted by : RSX-11, 26 May 2011 Complain about this comment
Happy

I´m really pleased and happy to know that! I never believed that MAC was the most secure OS in the world. We just never saw that until now because MAC was never as popular as PC, so, why wasting your time developing a virus (or malware) for MAC if the damages are not high? PC is much more attractive to create viruses for, but now that Fanboys are growing I expect to see many other threats to come soon!

posted by : Me, 26 May 2011 Complain about this comment
Poor quality control

They really need to stop allowing anyone to post their thoughts. This article is poorly written and clearly written by someone with little to no IT knowledge!.

posted by : He1ler, 26 May 2011 Complain about this comment
Oh Please...

The rather simple idiot who just posted please be aware that there are plenty of people who have both a MAC and a PC.

I've been using Windows since Windows 3.1 was first released back in the early 90's, which I presume is before you were born judging by the puerile comment you posted.

The reason I went with a MAC over a PC is simple. I was sick and tired of my PC gradually grinding to a halt after 18 months. No matter how muchanti SpyWare, malware, AV and other necessary tools I had in place the system would just crawl. So it was the usual step of rebuilding the system etc etc etc...

I've had an iMac for 18months now and it's as good as it was from day 1.

Let’s re-visit this in 18 months and see how many AV, SPyWare, Malware attacks your PC has had against my MAC.

posted by : PatriseLeFarge, 26 May 2011 Complain about this comment
@RSX-11

Again which part or Malware is not a virus dont you understand? if you cant work it out, it shows just how much your MCSE is truly worth!

What is instreating is , whether they are installing this malware as a user land program, to avoid tipping people off, by asking for administrator priviliges.

Of course it could be a couple of Anti-Virus companies trying to drum up business ...NO surely not.

posted by : LPF, 26 May 2011 Complain about this comment
"The day of retribution"

“26th May 2011 – The day of retribution”

You disgustingly irritating Apple Fanboys have finally received your comeuppance. We have sat quietly in the Microsoft shadows for the past 15 years listening to your mindless drivel such as “Apple’s don’t get viruses, just windows” “windows is badly coded” “Microsoft is rubbish” “don’t be a PC be a Mac” etc.

Well it looks like the Apple virus wagon is in full speed and the wheels of hype are about to fall off the wooden Apple carriage. The crash is going to be spectacular.
If you need any help, ask someone with a PC they are well educated about viruses , malware and the internet in general.

Regards
MCSE since 2001

posted by : RSX-11, 26 May 2011 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?