Warning: Mac OS X Trojan Horse making the rounds

“A malicious Trojan Horse has been found on several pornography web sites, claiming to install a video codec necessary to view free pornographic videos on Macs,” security software vendor Intego reports. “A great deal of spam has been posted to many Mac forums, in an attempt to lead users to these sites. When the users arrive on one of the web sites, they see still photos from reputed porn videos, and if they click on the stills, thinking they can view the videos, they arrive on a web page that says the following:”

Quicktime Player is unable to play movie file.
Please click here to download new version of codec.

Intego reports, “After the page loads, a disk image (.dmg) file automatically downloads to the user’s Mac. If the user has checked Open ‘Safe’ Files After Downloading in Safari’s General preferences (or similar settings in other browsers), the disk image will mount, and the installer package it contains will launch Installer. If not, and the user wishes to install this codec, they double-click the disk image to mount it, then double-click the package file, named install.pkg.”

“If the user then proceeds with installation, the Trojan horse installs; installation requires an administrator’s password, which grants the Trojan horse full root privileges. No video codec is installed, and if the user returns to the web site, they will simply come to the same page and receive a new download,” Intego reports.

“This Trojan horse, a form of DNSChanger, uses a sophisticated method, via the scutil command, to change the Mac’s DNS server (the server that is used to look up the correspondences between domain names and IP addresses for web sites and other Internet services). When this new, malicious, DNS server is active, it hijacks some web requests, leading users to phishing web sites (for sites such as Ebay, PayPal and some banks), or simply to web pages displaying ads for other pornographic web sites. In the first case, users may think they are on legitimate sites and enter a user name and password, a credit card, or an account number, which will then be hijacked. In the latter case, it seems that this is being done solely to generate ad revenue,” Intego reports.

Intego reports, “Under Mac OS X 10.4, there is no way to see the changed DNS server in the operating system’s GUI. Under Mac OS X 10.5, this can be seen in the Advanced Network preferences; the added DNS servers are dimmed, and cannot be removed manually. (Intego is currently testing previous versions of Mac OS X; it is likely that they can be infected as well, since all versions of Mac OS X have the scutil command.)”

Intego reports, “The Trojan horse also installs a root crontab which checks every minute to ensure that its DNS server is still active. Since changing a network location could change the DNS server, this cron job ensures that, in such a case, the malicious DNS server remains the active server.”

“This Trojan horse also provides different versions of itself, perhaps according to the country in which the user is located to provide country-specific spoofing. Repeated downloads of the disk image show that there are several different versions,” Intego reports.

MacDailyNews Note: Of course, Intego says that “the best way” to protect against this exploit is to purchase and run Intego VirusBarrier X4 with up-to-date virus definitions, but we suggest that an even better way to protect against such trojans is to use your head and not download, authorize, and install software from porn sites.

[Thanks to MacDailyNews Reader “RadDoc” for the heads up.]

90 Comments

  1. MDN, I would say that the best way to protect against this IS to install Intego’s VirusBarrier. There are many computer users who don’t understand when to enter their password since they are asked so much for it. It’s like reading the license agreements. People just click by it. Many who are still not comfortable with computers (I know many older people like that) need something for protection. Intego is correct and their software is good. I also prefer NetBarrier to many of the options. Intego got a bad rap a few years back for handling something poorly. But they are going strong now and I think it is wise to have some background protection on the Mac for a time when something might sneak up on us.

  2. Difficult to believe, that anyone would use their administrator’s password to say “sure install whatever a porn site suggests…”

    No matter how secure an OS, still can’t stop the user from silly

  3. As a security researcher, this is most likely a case of FUD and an attempt to drive sells for their software. The Trojan that he is describing is a common Windows DNS hyjacker. Not saying that one could not be created for the MacOS. It’s just not very likely and I’ve looked at thousands of Trojans from Porn Websites in the past few weeks and have not found one yet that is targeting the MacOS (Windows IE 6 and IE 7 and even Vista).

    I’d take any claim that a company that sells software to protect against such things with a huge dose of salt. Until independent conformation is made in public, I’m sceptically.

  4. Demon, Rob Griffiths at MacWorld did some looking into this and seems convinced that this is legitimate. Unless new facts emerge, I doubt this is FUD. And of course a security firm will promote its own software. When you go to a car dealer, you expect them to promote their own cars. But you also expect information on their cars that you can’t get elsewhere. OK. Maybe cars is a bad example, but the point is that people in the field will give you information you sometimes need. So to disregard Intego (or any other legitimate company) is not always advisable, IMO. And what’s the problem anyway having some virus and other protection on the Mac? Are you trying to keep Macs clear of such things because your new career is in writing malware?

  5. “Sadly this will effct an abnormal amount of Mac users since most at between the ages of 18 and 35 and are male.”

    But wait! I thought all Mac users were gay! Why would they be interested in heterosexual pornography?

  6. Installing “a codec” from a porn site is one of the dumbest things you can do. Macs have locks on the doors, but if the user is a moron…

    I bet there will people who will install this, and if they learn not to trust everything and everyone – good for them, if not – …well, nature eliminates weak and dumb.

  7. from Hg Wells: “MDN, I would say that the best way to protect against this IS to install Intego’s VirusBarrier. There are many computer users who don’t understand when to enter their password since they are asked so much for it.”

    In my experience, I am VERY rarely prompted for my administrator password, and I darn sure click “cancel” if I’m not explicitly authorizing an install. If your Mac is imitating Vista and nagging you every few minutes for your administrator password, you already have a problem.

    Oh, and I didn’t realize the venerable Mr. Wells was shilling for Intego. Royalties from his books must have dried up. ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

    MDN magic word: “few” – as in, there are so few deceased authors you can trust these days. ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

  8. “If the user then proceeds with installation, the Trojan horse installs; installation requires an administrator’s password, which grants the Trojan horse full root privileges“

    WRONG! It will only give the Trojan ADMINISTRATOR privileges. Unless you know how to use the command line you can’t get root privileges.

  9. Gosh, porn sites… hmmm, never go there.

    Seriously, anyone who downloads from such sources deserves a good kicking (with leather and high heels of course).

    Ahem, I’m not sure the emoticons work, so try this — :-O

  10. @Peter and BalLmeR

    They never specified the type of porn sites. ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

    @Pron

    So now looking at porn you can catch something, and if you have sex you can catch something. Now that is a delimia.

  11. No, H.P. Lovecraft, Hg Wells does not work for Intego. If you check other forums where Intego has been discussed in recent months, you’ll see similar takes. So, would it be your preference to have nothing extra installed on the Mac (saving money)? Or do you have another security company whose software you prefer?

  12. Well the least they could do is list the names and URLs of the websites in question. Not that I want to go there, or anything, but to be sure I could avoid them. Yeah, that’s it, avoid them!!!!

    Magic word “shown”, as in “what would we have been shown if we had gone to one of these sites?”

  13. Hey Fatty, apparently hell is freezing over ’cause on TWIT this week Dvorak actually is advising people to choose Mac. He’s also saying he thinks Ballmer/MicroSoftie is nuts trying to compete with Google selling ads. Microsoft is losing focus and it shows.

  14. I checked the link above for the MacWorld article by Rob Griffiths. Remember that Rob was one of the writers who exposed the Leap A/Oompa-loompa Trojan as a wimpy badly-written piece of code.

    His tone this time around is A LOT different:

    “This is really bad. Really. And even though it’s targeted at porn surfers today, the malware could easily be associated with anything else… Because this thing may spread to other such sites, we spent some time investigating the trojan—no, not its source sites!—to determine the best way to tell if you’ve been infected, as well as how to remove the software if you do find it on your machine.”

    You might wish to bookmark this article just in case. Also, let’s hope ClamXav is updated soon as well to ID this nastyware.

    Although the<u>OSX.RSPlug.A Trojan Horse</u> is not a virus, <u>it is serious</u>!!

    Laughing at this Trojan is not the appropriate response this time around.

    MDN MW = united

    So let’s be united as Mac users in helping us protect one another from real security threats.

  15. what’s to stop some other scammers/assholes to implement this in a more legitimate site – say, a spoof of apple’s quicktime page?

    one could argue that nobody should visit porn sites and do a download – that’s common sense, which, sorry to say guys, even some mac users don’t have. but if you click a link and it looks like apple’s site and says it’s installing a quicktime updater, someone who might not know that macs don’t usually update like that wouldn’t think twice about clicking.

    this is a serious issue and hopefully apple will patch it up soon. we can all still take joy in knowing that our platform has far less malicious software on it than windows. =)

  16. Hmm..being a creative Mac user I suppose I’d either be the porn star gettin’ some pom pom in and being paid lots of $$$, then again be a porn video director – as if direction is required??

    On a serious note I’d like to hear more about this Trojan affecting Macs and from an independant source. Not to say anything is wrong with Intego, after all most anti-virus software developers have been saying this for years.

    They would wouldn’t they, its their business to scare computer users into buying ‘extra protection’ against infectious diseases?

    It is up to each of us if we want to take heed, luckily for us Macheads we don’t have to – pity the poor Windows user who has to take heed or get infected and die.

  17. Ohh..on the subject of spoof websites mentioned above, it doesn’t matter if you’re a Mac user, Windows user or Linux user as those types of emails & websites made to look genuine are more related to identity theft. PayPal is a case in question, I happen to think they’ve been the most spoofed brand of Internet based businesses ever!

    For emails it doesn’t take much effort to delete such scams from your inbox as the email always looks too good to be true, so it probably is, how often do people actually win the Minnesota lottery for instance (let alone I’m 5,000+ miles away from Minnesota) through not having even entered into the draw and get an email saying I’ve won???

    On the Mac side Micheal Tsai’s SpamSieve works perfectly for me after a short period of training it to ‘sieve’ out spam emails with dubious spoofed websites usually provided to catch out the unwary.

  18. “an even better way to protect against such trojans is to use your head and not download, authorize, and install software from porn sites.”

    Pfft, next they’ll be telling us not to take candy from strangers. And then where will we be on halloween?

  19. MacJammer, Mail has uninstalled the current version of SpamSieve TWICE since upgrading to Leo. No apparent help at the site except to say it’s compatible. I reinstalled it the first time and it worked for three days. Conflict with something else? Nothing else is new, but perhaps,,,

  20. “Such rubbish. Mac users don’t look at porn sites. They are too busy creating content and authoring sites.”

    i agree. i have created WAY more porn sites than i have visited….

    and yes, i do the photography as well, why do you ask?

  21. For those who want to look at britney’s bottom: bigfatsearch.biz/britney

    This is a serious threat and it implies that a well organized group wanted to get Mac users private data.

    Look at the bad DNS IP on the disk images, 85% are from Russia or Ukraine.

    Porno is just a way to abuse Mac users. But not the only one.

    For those who ignore that with Javascript it’s easy to download a specific malware for Mac OS X, the britney html source code is for you.

  22. So….

    When I’m driving through the local red-light district,
    and some stranger flags me down,
    and they ask for my keys (which I readily give to them),
    and they tell me to stand well back while they “install” something,
    and they hop in and swipe the car,
    does that mean the make/model of my car is vulnerable to theft??

    Yeesh. Figure it out!

  23. Comment from: bwaha
    “This is why I use either MPlayer or VLC for my viewing pleasure, not Quicktime “

    It doesn’t make any difference what-so-ever what video viewer you use!!! If you click on the downloaded Trojan you get the shaft. Jeeze…me thinks you are in for a real ride one day.

  24. …look, I don’t mean to be indelicate but I’m just going to come out of the closet with this. For the doubters …lift up on OSXs skirt ..yeah, lift it up high and take a good look. I did …OSX has an intimidating package ..yeah, go ahead ..look at it. Now, after you’ve had a good look ..think about the kind of trojan it would require. Yeah, that’s right ..it would have to come straight out of the devils wallet ..but alone ..oh, no …not alone …it would require its own installer ..and if you have any doubts then lift up the skirt again ..maybe, you need to look at the package some more. Maybe, I’m really talking to the midgets at Intego ..I mean little people. Maybe, you think you know what’s under the hood ..and maybe, you don’t want to think you want to know but you really do but you can’t bring yourself to admit that you want to get a look …a long look …a hard look. I think if you could get that far then maybe you’d know that some dirty little someone somewhere is just trying to wipe their dirty little codec on the outer hem of OSXs skirt because they’re just pussy-hackers. So, …maybe, the folks at Intego need to come to terms with their own techno-eroticism. Go ahead, Intego …take another look at the package.

  25. Regardless of this Trojan’s source, it way high time for Apple to change Safari’s ‘Open “safe” files after downloading’ default setting. The fact that Apple puts “safe” in quotation marks is proof that the company realizes there’s no such thing as a truly “safe” file. Every download is a calculated risk.

    Off topic, but in response to the above, I get better performance from the cross-platform Miro than I do from QuickTime, VLC, or MPlayer.

    http://www.getmiro.com/

  26. “Every download is a calculated risk. “

    Only if you don’t run antivirus software.

    “does that mean the make/model of my car is vulnerable to theft??”

    A better analogy is you believe you have the world’s most theft proof car, and no matter what you do it cannot be stolen. So you leave it running with the keys in the ignition in a bad neighborhood. Then you get surprised and start making excuses when somebody just walks up and steals it.

  27. DON’T panic if you see grayed-out DNS entries in the Ethernet section in Leopard’s Network preference pane.

    That’s the first reaction that most people would have. The only visible way of detecting this potential Trojan Horse, according to the Intego report, is the presence of dimmed DNS server entries. There is NO MENTION in this report of other potential (and as it turns out, much more COMMON and WIDESPREAD) reasons for this to occur. (Thankfully, the Macworld article goes into more detail about this). Such as:

    If there’s a hardware router (for instance, a plain vanilla Linksys, as many people will have) between the Mac and the Internet, then the default Ethernet configuration is going to be -exactly as described- in the Intego alert article – the DNS setup in the router also shows up, grayed, in the Leopard network configuration for Ethernet. This is normal! It is NOT a Trojan Horse!

    There are going to be THOUSANDS of people who will look at their Network settings in Leopard after reading about the Intego report and mistakenly think they’re infected with a Trojan Horse. The Intego report, and most, if not all, of the initial followup coverage, makes no mention of the fact that having a simple router between your computer and the Internet will do this.

    How many people will rush out to pay for Intego VirusBarrier to rid themselves of an problem that they -do not have-?

    I think it’s totally irresponsible for them to issue this report with no mention of other (much more LIKELY) potential causes for grayed DNS entries in Leopard’s Network settings. It seems to me that they’re simply taking advantage of this showing up (for the first time in OSX) as a visible network setting in Leopard and trying to scare people into going out and purchasing their software.

    Anyone who is in doubt, please read the Macworld article and reassure yourselves. The first step you can take is to simply log into your router, look at the Ethernet settings for DNS servers, and confirm that the numbers you see there are the same as what’s showing up (grayed) in your Network settings in Leopard. Assuming (extremely highly likely) that they are: you have no problem. For further reassurance, follow the instructions in the Macworld article and use Terminal to check a few other things.

  28. Windows, Linux or OS X-never download anything from a website that you did not specifically go to for the purpose of downloading something and trust(ie. sourceforge, vlc, Apple, etc.).

    Following links in mail, blindly downloading applications from websites and installing programs/codecs/plugins from said sites is stupidity.

    Unfortunately some users will engage in this behavior and get infected with something.

  29. Dave, the MacWorld article was updated later, after it originally didn’t mention/know about this other possibility. I think further research after posters brought it to their attention led to the update. Intego should have also mentioned it. But, in my opinion, regardless of the technicalities involved, having AV software on a Mac is not a bad thing and people constantly trying to find ulterior motives for any company saying anything is not always productive. Many people remember Intego’s cry of wolf some years ago raising concerns unnecessarily about other malware. It was handled badly by them and they had lots of PR to do (not sure they ever did) to overcome the bad feelings people had over it. Nonetheless, most long-time users of their products (most, not all) are pretty comfortable using them.

  30. Nekogami13, get off this thing about calling everyone stupid for not doing what is so easy for you and others to do. Ever helped out some 80 and 90 year olds as they nervously try their hand at a new computer? Where do you and others get off telling them how stupid they are because they can’t remember everything they’re supposed to be doing right? WHY NOT LET THEM HAVE SOME HELP? Anti-virus and other security software is comparatively cheap protection for peace of mind that they probably not allowing their computer to be compromised. Don’t tell me that everyone posting here has always checked out everything before entering their password. Many do. A larger number than you think, don’t. Even those who insist they do can, in a rush, overlook something.

    “Stupid”? You and all the other naive people here who only look at themselves and forget there are others less aware who need some support should come into the real world sooner rather than later. Perhaps by the time you all reach the ripe age of 23, you’ll have taken a fresh look at the world and won’t be as judgmental. MDN included.

  31. Hg,

    My point is that Intego should have mentioned it, because they were certainly aware of the fact that dimmed entries in Leopard’s DNS table were -not- equivalent to an “indicator” of the presence of this, or any other, Trojan. But that’s how their alert made it sound.

    The fact that they deliberately did NOT mention -any other- reasons for the appearance of dimmed DNS servers calls their motives into question.

    Their alert is carefully phrased to ring substantial alarm bells. They specifically say that “the added DNS servers are dimmed, and cannot be removed manually.” The strong implication is that ANY dimmed DNS servers that show up in Leopard (and which, of course, cannot be removed manually) are a result of the Trojan.

    There isn’t the slightest mention regarding something that has now become obvious: when Leopard has been installed, systems which are connected to routers are going to have dimmed DNS servers showing up in their Network preferences. There will probably be a fairly high % of OSX systems that fall into this category. Of those, an overwhelmingly high %, if not virtually all, will -not- have been infected by the Trojan referenced here. Why? It doesn’t spread. The only users affected would have been those that specifically visited the sites in question and who followed all of the social engineering steps required to become infected.

    This is crying “wolf”, in a very public and alarmist way, for an exploit that will not spread, and which sounds as if it will have affected a very small number of users.

    The only responsible way to have disclosed this issue would have been to describe it fully; and to also tell users, (as the Macworld article does) who have a reasonable amount of technical skill how to verify whether or not they have a problem, without having to shell out $80+ to Intego for the privilege.

  32. Hmmmm, So:

    What does this trojan do anyway?????

    I have had the ocassional site try and force me to down load an .exe file. It had the typical, “Download this file? (YES) ” single option and the window would not let me close it without selecting yes. Once it started, I would click stop from the downloader and its an exe file so it does not bother my mac anyway,———

    But– Anyone know whats up with that? Would it have to be a virus or trojan file when it will not let you opt out, or is that just more stupid windows junk going on??

    Just curious. (and glad it showed up on my home mac vs my work pc) ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

    en

  33. Dave, although they should have known, it’s possible that they were not “certainly aware of the fact that dimmed entries in Leopard’s DNS table were -not- equivalent to an “indicator” of the presence of this, or any other, Trojan.” MacWorld’s pretty savvy, too, but didn’t know that when the article was first written until brought to their attention. Like in the previous fiasco, it’s clear that Intego continues not being careful enough in how they word their announcements. It’s possible their European division are even responsible for their news releases and Europeans are sometimes known for slightly slanted releases (not that the U.S. isn’t). And, unlike last time, no one has (yet) come out and said this doesn’t exist or is no significant threat. The details seem to still be being shaken out. On the positive side, and assuming this is real, Intego still did its job by telling people that it’s out there.

    There seems to be an undercurrent that Intego shouldn’t have said anything at all since it’s some sort of conflict of interest since they also sell security software. That position makes no sense to me. Again assuming this is legitimate, of everyone, I expect security companies to announce these sorts of things. After all, who else is watching for them? And, OK, so Intego’s PR people still don’t have their full act together. But I don’t think it calls for a blanket condemnation. If the malware is real, I think we should be grateful to know about it, even if the details didn’t make it out correctly.

    I suspect we’ll hear from the other security companies in short order to confirm or deny all this.

  34. Really… who visits porn sites anymore? Isn’t that what P2P was made for? Anything under 100 MB is a waste of time too. And if you download a video, and VLC, MPlayer, or QT cannot open it, find another video because there is something wrong with the one you just downloaded.

  35. Truthifinder, no, this is not (yet) the same thing that happened in 2004. That was indeed poorly handled by Intego. Again, I feel this is more by not having several people at the company validate press releases like these to be sure they are very, very carefully worded with full details. In 2004, others came out pretty quickly to dispute the Intego release. That may yet happen today, but so far it has not. Until it does, it’s better to be safe and take the warning seriously. Because a person or a company made a past error in how something was worded, does not call for ignoring them the rest of their existence. You still look carefully at each announcement to see if a threat exists. So far, we assume it does. And porno sites are not the big issue. The existence of this malware means it can show up other places, too.

    MacWorld is well aware of Intego’s past. But they appeared to take this seriously. I believe that is the safe, responsible thing to do regardless of Intego’s still not completely getting their announcement right.

  36. Exactly HOW does this trojan manage to gain root access, particularly if root has NOT been enabled (Apple factory default) and a user is running:

    • in administrator user space

    • in a non-administrator account space

    Have seen no discussion about the particulars as to HOW root is commandeered.

    Root Man Fat

  37. @HG Wells-I did not call anyone stupid. I am stating that everyone who knows better needs to inform everyone else not to engage in dangerous behavior-regardless of their OS. I constantly remind my 60+ year old parents and nephews/nieces about this because I am their tech support.
    Providing users with a security blanket called AV software is not the answer, considering AV software is reactive not proactive. New threats come out all the time, by the time AV software catches up it is to late-infection has already occurred.

    Pull your head out of your ass and be proactive-inform everyone not to open email attachments or follow links, don’t download anything from untrusted sites, do not enter your admin password without knowing why.

  38. “AV software is reactive not proactive. New threats come out all the time, by the time AV software catches up it is to late-infection has already occurred.”

    If you update daily, it reduces the window of attack for known viruses to 24hrs or less.

    And clearly you haven’t looked at antivirus software for some years now. Products now look for suspicious behavior and can block virus like activity before an actual signature exists.

    Not doing dumb things is always a good policy, but for the vast majority of computer users who don’t seem to be able to stop themselves from doing dumb things there’s antivirus software.

    Since they have been told over and over their OS is invulnerable, Mac users are like a field of passive herbivores waiting to become dinner for the first predator walking by.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.