Detailed info about potential Mac OS X Trojan horse

Intego, the Macintosh security specialist, yesterday announced that it had updated its virus definitions for Intego VirusBarrier to protect Mac users against the first Trojan horse that affects Mac OS X.

Intego has posted a Q&A document which contains questions and answers and provides more information about this Trojan horse and detailed technical information as to how it functions.

Full article here.

34 Comments

  1. I don’t get these trojan horses on my dell dj. mac users are so funny, no market share and now trojan horses. I can’t write any more, because i’m off to the walmart music store, 88 cents a download makes mac users cry a crapload.
    suuuuucccckkkkkeeeers.

  2. This is really bad….

    When the trojan runs all of you files in your home folder will be deleted…

    The Apple party is over…

    One double-click and all of your data is gone for good (secure-delete)
    Even on a external back-up hard drive
    Even on a server…..

    Wow this is really bad.

  3. To all the TROLLS out there:
    Nobody ever said that Mac OS X was impervious to trojan horses and the like, only that it was much more secure than ANY version of Windoze. Still is…

  4. sputnik, your a friggin retard. windoze has trojans too. the difference being no one has found a way to send this one. besides apple is already working on this and will probably have it fixed in a couple of days. besides this is all youve got on the mac os dont even get me started on your piece of S*** os. it take MS months to figure out there crap and then a few more to figure out how to fix it only to find out theyve created another hole along the way so they have to patch their patches. you really need to take your head out of your a** and wake up to a real os.

  5. Who the hell are these guys (Intego)? I have been using Mac since 1986, and have never heard of them. Virex – yes, NAV – yes, SAM – yes, Intego – no.

    Has anyone ever used their products?

  6. birdseed
    Of course everybody knows Intego!
    It is like SCO, owned by M$…
    Newer seen this company anywhere!
    Did they make this “maybe-trojan” to sell their products?
    Maybe Intego is one of these comanies since yesterday wana bee?
    No one else knows this trick and that includes real companies like CA and F-Secure…

  7. NAV was recently updated with the virus definitions for this ‘trojan’.

    I’ve heard of Intego, they have their products sold at the Apple Store.

    Jobzzz…If OS X had 2% of the virii the Windows did, I’m pretty sure we’d have more than one, barely existent trojan. Go home to Thurott.

  8. This Intego stunt seems like the Janet Jackson one at the super bowl.
    Just make some headlines and you’re in the market.

    Janet Jackson with the famous stunt at the super bowl is now selling records. Before that, nobody paid attention to her. Now her CD is everywhere and now she is ‘in’ (sorta)

    Same thing with Intego: they made some headlines (or lots of them) with the PR release stating they “discovered” this trojan, and even if they didn’t discover it (not the first ones at least) and even if it’s not a threat, they will be remembered ad the “company who discovered the first virus for OS X” (I know it’s not a virus)
    And now next time someone considers to buy anti-virus software, Intego is among the options, whereas before they were non-existent and nobody paid attention to them.

    So boring and obvious…

  9. It seems like the envy has caused a backlash as the MS users seem to be trying to party over a non existent trojan, sorry guys but there is no trojan, intego’s sales have dropped dramatically because of their shadey past and bad service thus a nice stab at the trojan philosphy it isn’t there what they have is static and absolutely no threat much like the ignorance of sputnik, it’s not damaging just annoying.

  10. This is amazing: Windows users, the most affected by viruses, worms, and trojan horses do not even know the difference between those. They should be expert and instead they are the more in the dark.

    Anyway, apart the fact that users do receive a warning and have to click OK, it also say the trojan (the mp3 file) contain the malware as Carbon code. Now, I do not have OS 9, nor Classic. Physically my system (as many others who have no use for legit sw) cannot launch Carbon or OS9 applications.
    So what would happen? a pop-up panel saying: you are trying to run a Carbon application, please install Classic?

    Just wondering.

    To Windows users: pathetic. Till the day come when by simply connectin a Mac on the net, you and millions others get infected you better stay silent. LOL, destroying all files? ROFLMAO so used to the fact that on Windows anything could do anything anytime you think this is common? Ever heard of account privileges: one has to be root and/or provide root password to do that.

    Must sux big time to be so frigging ignorant: go buy an XBox and stay with it. In any case apart FPS a PC has no real use. Never seen nor will ever be any Windows system on supercomputer. So go conpete with PlayStation with your PC toys. Only good for playing games and breed viruses.

  11. Forget about my wonder. Carbonized apps do not need Classic. My bad, most use I have of OS X is on Unix.

    Anyway, it is beating a dead horse: if it does require active collaboration from users it is a nuisance, not a virus. Spread? what should happen, click many times OK?

  12. This is all such a joke. There is no trojan horse – it dies when you email it, it’s totally un-spreadable unless you pass it around as a compressed archive. This is just a loser mac software company trying to justify its existence, since there are still no known mac os x viruses…

  13. hehe, CNN titles “Virus *tries* to take bite out of Apple’s security” and the article describe what is a “proof-of-concept”… of what? of a Trojan. No need of proof for that. The problem on OS X (and Macs in general) has never has been that to enter the system via a Trojan (which is a legitimate code/application:remember MS Word macros embedded on legit word files) but to allow the malicious code – however it has entered – to act without user knowledge and replicate itself and spread again without user knowledge or intervention or authorization.

    These last points are still unaccounted for – which is the reason Unix platform are inherently more secure. And no, spoofing user password is not enough unless s/he is logged as root.

  14. This isn’t even a trojan, I would say. The only way to preserve the malicious code within the file is to compress it before transfering across a network. Who in the hell passes mp3 files around compressed into sit or zips, since they would be no smaller? I wish people would do their homework on this topic.

  15. the dude, yep, it seems Intego thought about a way to get some visibility and came out with this *proof-of-concept*.

    I have another as valid viral proof-of-concept: if you provide me with your root password and IP# I can delete all your files if you allow remote ssh connection.

    LOL, to think that this is the *best* they (whoever) came up with after more then 3 years of existence of OS X… it will still be worth a laugh as soon as Apple adds internal security gates (lol, gates… too funny) to forbid even this to happen.

    BTW, noticed how CNN talks about “less than 5% of computers”: could it be that little by littel people start to realize that monthly sales market shares has very little to do with presence online)

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.