“Russian security firm Dr Web warns that at least 600,000 Macs are infected and part of a growing bonnet,” Ed Oswald reports for ExtremeTech. “76% of these Macs are located in the US and Canada, with another 13% in the UK.”
“Possibly more embarrassing for Apple is the fact that 274 infected computers are located in Cupertino, California, which may indicate Macs belonging to Apple employees or even on the company’s campus might be infected,” Oswald reports. “Mac users are advised to ensure their Macs are up-to-date to prevent infection, and some four million compromised web pages are believed to exist, including portions of DLink’s website, Dr Web claims.”
Oswald reports, “The Flashback Trojan is the culprit here, but is nothing new. The Trojan first appeared disguised as a Flash installer last September, and disabled Mac OS X’s built in malware protections. This version makes its way into Macs through a Java vulnerability, and is loaded onto unpatched Macs without interaction from the user.”
MacDailyNews Note: Apple on Tuesday released Java for OS X 2012-001. It is available via Software Update and also via standalone installers for Mac OS X 10.6 Snow Leopard (more info here) and OS X 10.7 Lion (more info here).
Read more in the full article here.
To check your Mac (a clean Mac will deliver the message “does not exist”) follow F-Secure’s instructions here.
Related articles:
OS X trojan variant preys on Mac users with unpatched Java – February 27, 2012
Warning: Flashback Trojan horse spreading; Mac users should be wary of Flash installers – September 28, 2011
Apple updates OS X Lion, Snow Leopard malware definitions to address new trojan – September 26, 2011
Hence Apple’s reason for removing all plug-ins from the default Lion install.
By the way:
For those who want to check if mac is infected (from F-Secure instructions):
Run the following command in terminal:
defaults read /Applications/Safari.app/Contents/Info LSEnvironment
defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES
If you get “The domain/default pair … does not exist” for both – you are clean
Note to terminal noobs: paste one command at a time. 🙂
The above is correct (in case you were suspicious).
^ Thanks for the support 🙂
Wait a minute.
A Russian site called Dr. Web is considered legit???
The same question might have been asked about a company that named itself after a fruit.
Well… They do have accurate instructions on how to remove the infection. Whether they created the virus to begin with or not, we will never know, but those instructions work.
PS: for terminal super noobs…. Cmd+Spacebar. then type “terminal” then press return.
😉
Thanks. First time in Terminal. Never had the need…
Clean. Whew.
There are lots of reasons to check out Terminal. Get a decent Unix handbook and have at it.
My this old Macbook 5.1 now automatically boots into 64 bit mode and is ready for Mountain Lion, thanks to resetting a few items in the OS using Terminal. Pine with Procmail on your remote mail server is an excellent way to filter mail too.
Twenty three years on Mac and I’ve never gone to terminal. I believe I could qualify as a super super noob!
Thank you dinjin201
Seriously? I’ve been on Macs for only 16 years, but I learned to love the Terminal while running OS X 10.0. It was really pretty necessary to use it while running that beta-quality version of the Mac OS.
🙂 haha well, now you’ve learned something new 😀
you’re very welcome.
‘Whether they created the virus to begin with or not, we will never know, but those instructions work.’
dinjin201: It’s NOT a virus. – repeat – It’s NOT a virus.
*whoops* slip of the tongue, there. Sorry. Trojan. I meant trojan 😛
Well, so maybe did the NYT, but it’s too late after the fact.
🙁 you have a good point there 🙁
Thanks dinjin201.
What other way can people scan for this trojan?
If so what to use? I believe Dr. Web is the culprit here posting baloney information. I have tried in the past the software and since installing it has found many things no other app found, yet never completed its task – freezing the machine and forcing me to restore from time machine. Not once has the software ever made a complete scan job.
I don’t know of any other ways to scan for this trojan, sorry 🙁
I should also mention, most antivirus softwares for mac just scan for windows viruses. It’s a total waste of your CPU cycles, time, and money.
It’s really EASY to do, even for a noob. Just follow the instructions and copy and paste the commands. No need to be concerned that you don’t know what you are doing. Just follow the steps.
I had followed the instructions – I was asking for another way just to verify if this procedure was valid – Dates of these steps pre-date the threat and are not targeting Java directly but focus on Safari. Sure Safari uses Java however one just wishes to confirm that their is no threat – thx. Sorry if that makes me a noob, by your definition.
Re-visited this article today Apr 10th, because of this news,
Thanks, dinjin201!
Ran the commands, and I’m clear (just like I was 99.98% certain was the case).
Thanks dinjin201 for the post. I never needed to use terminal, and your instructions were right on. And as I suspected, nothing was found.
You’re very welcome. Yes, the original instructions are in the article, but they don’t tell you how to use terminal, and I figured why not throw a few tips in there 🙂
you can also just right-click and choose “show package contents”
I haven’t tried this. Remember if there is no infection, those locations may not even exist. and I’m not sure if they would be hidden or not… so terminal is the safest way to go with this one…
Thanks… The link from the article WAS BAD… classic.
It happens. I don’t know what it is but that seems to happen a lot… 😛
So I figured why not post and help everyone out 🙂
ahem! Right above the “Related Articles” section above is MDN’s recommendations:
To check your Mac (a clean Mac will deliver the message “does not exist”) follow F-Secure’s instructions here.
Jeff, if you click on links when a new article is posted, sometimes they don’t work. I’m sorry if you think my comment was redundant, but I was just helping people out here, without them having to go to an external link, and provided a few tips on how to use terminal because not everyone knows.
If helping others bothers you that much, and if other people thanking me for making things simple for them makes you feel unhappy somehow, you have my sympathy, because jealousy must be a hard thing to live with.
Thanks again dinjin201!
didjin201 – I appreciated you posting the info.
Thanks!
oops – dinjin201
Sorry ’bout that.
You’re welcome. It’s okay, I feel like he was just trolling… and I was irked enough by his trolling that I had to go off on him a bit 😛
If you follow the link and go look at the instructions, they just don’t explain *anything* about terminal. They literally say “run the following commands” and give a a whole list…. (including the removal commands)
What if you get a file for the first one but not the second?
You may be infected. Instructions on how to remove the infection are found on the Dr. Web site that MDN linked to at the bottom of the article.
Are you really “infected” by a Trojan? There must be a better word … how ’bout “afflicted”???
plagued? 😉
How about a word that reflects the level of difficulty of finding and eliminating the threat – pestered.
Hahahaha Touché 🙂
If anyone wants a simpler (non-command line) way to check for the Trojan, you can use this free tool: http://rsdeveloper.com/downloads/test4flashback.zip
anyone checked the validity of these claims/numbers. They are after all coming from an Antivirus software company.
correction “security firm” who are generally in cahoots with the AV companies.
Correction: Anti-malware firm in RUSSIA.
Therefore, I treat this figure with suitable skepticism. But we know the Drive-By, no password required Java infection of Macs is entirely real and dangerous.
My recommendation is to turn Java OFF. I provide how-to instructions in my Mac-Security article HERE:
CRITICAL Java Updates: Mac OS X 10.6 Update 7 and 10.7 Update 2012-002 (formerly 001)
I am trojan free…phew
How did you come to this conclusion?
I would like a simple way to check – thx.
be careful not to make babies lol
and always do the balloon test first
Hahahahahahaha
Was that comment a Fluke?
(no, wait, that was free Trojans…)
😉
First you find the vulnerability.
Then you create and release the Trojan.
Then you create the almost benign Bot-net.
Then you sell the anti-virus software.
5. Profit!
Hahah yeah…
of course, you can also release totally accurate info regarding how many are infected, what IP the infections are coming from, etc… 🙂 LOLOLOLOL
and of course: “here’s how you get rid of it”
Sounds like a conspiracy to me.
Dr. Web is the only free Mac app on the AppStore that sees all .exe files as a threat. The other apps that I have bothered to play with (manual apps) see my machine as clean.
I’m also thinking the culprit may in fact be the Dr. himself.
I don’t buy the numbers. Off to do some digging.
appreciated
My MBP is clean
same…Went through the checking process anyway as I was curious to see what else I might find…nothing! 🙂 So disappointed 😉
I believe I am clean also. Never miss an update from Apple. Do not have or run Flash browser plugin. Whats is the simplest way to scan for this?
I figure my Mac is clean – however just like a simple way to check if this trojan is nested in my machine?
F-Secure terminal procedure is beyond my skills.
And updating Java does not remove the trojan.
Dr. Web free app – it takes forever and thinks every .exe is a threat quarantines all. Bitdefender and VirusBarrier both see nothing.
On f-secure’s webpage the firs step is to copy paste the terminal command into the the terminal app. Just open the terminal app and copy past the text they have in red under step 1, then hit return.
Thank you, yes – read and did all that.
F-Secure is targeting Safari. Not Java or Flash plugin.
Thinking this is so Oscar Myers – baloney – a trojan article.
STEP 1 RETURNS: does not exist.
instructed to go to step 4.
STEP 4 RETURNS: No such file or directory
—
Plus ran all anti-virus apps I have – just to see the results.
Now installing Sophos in addition to Dr. Web, BitDefender, Claim and Virus Barrier.
The Dr.Web is the only app that sees any .exe as a threat.
Feeling this a scam scare.
And you fell for it by installing every Mac AV software out there. Then, you’ll feel unsafe if you get rid of all the AV software because you’re scared of what could happen in the future. And that’s the beginning of the end.
Ha ha – no – I uninstalled every anti-virus app and bought a book to learn Terminal.
Question, should I even be worried if I don’t have Java installed on my iMac?
Nope. You’re completely safe. Having Java disabled saves you as well. This is why Apple no longer includes any plugins, including Java and Flash, in its default Lion install.
Anyway you look at it, this should not have happened the OS is not supposed to install anything that has not been approved by the user even Apples own updates can not be installed without Admin approval. Some one at Apple needs to do some splainin. Installed is different than running. I can see an app in a WEB page running without approval but as soon as it tries to install something then it should be sttopped.
The Flashback trojan DOES require a novice user to INSTALL a fake Flash player installer, and in some cases, even accept a falsely signed certificate that the OS actually warns is not valid.
The OS is in no way responsible for a user’s own lack of knowledge/awareness/stupidity.
Ok, reading up on the latest version, and in some places it claims no interaction, but others say that a certificate prompt comes up. I’m not going to test it myself. 🙂
But, either way, this is a Java vulnerability and not the OS.
Whenever some builds a fool-proof system, someone else builds a better fool…
It gets better. Apple continues to hide more and more of the file system with every release unless you use the terminal or 3rd party software like Rixstep x-File.
One of the really nasty things about this is it faked Apple’s Software Update and if you had automatic updates on would not tell you what you were signing off on. I’m really tired of the endless dumbing down of the Mac OS.
Interesting point – however – I would believe the Apple Software update check – directly connects to truly Apple.
Also, please note that once you run Software update check, you can enter the preferences to (disable) check weekly and (disable) download automatically.
Quite a few corporations and universities remap the Apple Software Update address to local servers in their Mac OS authorized builds so they can check the updates for compatibility with home grown software and systems. The people with those Macs are always behind the curve on updates until the IT people push updates out locally.
Relax, Jeff. The sun will rise tomorrow.
Culling the gene pool, that’s all. Those who get lax with their own security measures, and more importantly, become lulled into a false sense of security because they use Macintosh, get pulled down by the short hairs.
Vigilence is paramount. I learned that just by watching the Windows Wars and the massive virus storms that scorched a billion machines every year throughout the Nineties.
The blame for much of it is lost on the billions of users who are too stupid to own a computer. Ninety-percent of them chose the wrong platform in the first place, and then failed to develop a healthy respect for a computer capable of destroying your life, and those around you. Imagine the cost of just the collateral damage alone?!
The disease will find you by following your trail of breadcrumbs! You are being studied, get it? You are a creature of habit and unfortunately, the one you turn to for permission to act on your impulses, is asleep at the wheel.
So long, it was nice to kmow you.
Tremble. Drool. Gibber. Cringe.
Where is the download??
… are not entirely correct. No mention is made of “run this from an Admin account” – quite a few Windows users are running ALL their admin AND user jobs from admin accounts already without being aware of the danger in that. Also, why continue to Step 2 if “The domain/default pair … does not exist”?
also F-Secure instructions are old and targets Safari
as stated in the article, “This version makes its way into Macs through a Java vulnerability.” so one would figure even if the Java update has been done that F-Secure terminal instructions would target Java and the Flash plugin.
Clean also, I don’t buy these numbers too – MDN how about putting a quick survey up to see how many Mac’s are clean/infected?
Clean as a whistle here! As I expected, since I have been cured of M$ for about 4 years now. Cured I tell ya!!
So this one site has these numbers, how? Because… who planted the trojan? And the “Cupertino” numbers – meaning to imply residents of Cupertino CA proper(?) or that someone got trojans past Apple’s firewall, us knowing that ‘Cupertino’ is often a left handed referral to Apple’s HQ. How come the usual chorus of anti-virus folks aren’t singing about it… I am always somewhat suspicious of anti-virus companies to begin with, who determines their ‘legitimacy’? Not to mention..(as a child of the Cold War) . a Russian security firm? If I knew little about command line use I would be somewhat dubious to run the command line prompts to ‘check for infection’. For all you know you are opening a way in for some future trojan when you run the test…
As Apple grows so do the threats, that much is a given. Compared to everyone else in the industry Apple stand head and shoulders above, no, maybe orbits above all others relative to security.
Apple’s customers expect a reasonable level of protection and security from Apple’s designs and they should. To me, Apple’s challenge is to do just that, at a reasonable level.
Defining the reasonable level will always stir the debate…
What the web articles I have read today have failed to say is this:
If you had proper AV software with up to date definitions this problem does not exist.
From the Intego Security Blog:
“Intego VirusBarrier X6 with current malware definitions protects against this new version of the Flashback malware; Intego did not need to update its malware definitions to detect this new variant.” March 7, 2011
“Intego VirusBarrier X6 protects against Flashback and all other Mac malware. The Intego Malware Research Center is ensuring that regular updates to the program’s threat filters include new malware definitions for the latest variants of the Flashback malware.” April 5, 2011
http://www.intego.com/mac-security-blog/
No, I do not work for Intego although I am a customer.
I’m just not buying this. 600K clueless Mac users who’ve given their password during a bogus ‘install’?
The install dialog box didn’t (and doesn’t) say “Enter administrator password to install bogus Java update.”
Buy it.
There are actually three commands you need to enter in Terminal.
Enter this command in terminal:
defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES
Result if not infected:
The domain/default pair of (/Users/gordon/.MacOSX/environment, DYLD_INSERT_LIBRARIES) does not exist
Enter this command in terminal:
defaults read /Applications/Safari.app/Contents/Info DYLD_INSERT_LIBRARIES
Result if not infected:
The domain/default pair of (/Applications/Safari.app/Contents/Info, DYLD_INSERT_LIBRARIES) does not exist
Enter this command in terminal:
defaults read /Applications/Firefox.app/Contents/Info DYLD_INSERT_LIBRARIES
Result if not infected:
The domain/default pair of (/Applications/Firefox.app/Contents/Info, DYLD_INSERT_LIBRARIES) does not exist
Well, Gordon (your name is in the 5th line down), please explain why people should take your advise over the professional antivirus firm since only one of the three commands you say users should type is among the two the pros say should be typed.
I would also point out that very few users will see a response in Terminal that includes the word “gordon”.
Greg, you’re right in saying that very few will see the word Gordon… I should have explained that part. Regarding the three lines I simply read the instructions here:
http://reviews.cnet.com/8301-13727_7-57403430-263/detecting-and-removing-the-flashback-malware-in-os-x/
followed them and transcribed my results here to help those who seemed a bit confused above.
Thanks. I tried all three and am still clean.
BTW everyone, I am using avast! (avast! website HERE) It’s $25 and very nice. It runs continually in the background watching for suspicious behavior.
I also use ClamXav (ClamXav website, HERE) to scan volumes for infections.
I recommend both.
My Mac’s are all clean!!!!
Wolf!!!
Me too.
There are a couple of different simple and logical actions that will keep users completely safe from this Trojan. And basically only lazy and foolish people will get infected.
It’s like I told a friend recently – Apple makes great products, but using them cannot make a stupid person smart.
Maybe that will come in OS XIII. 😉
Didn’t find any Trojans but did find a few Durex.
Collect 365 of them, recycle them, and call the product a Goodyear!
Nothing to see here, move on!
The seven Macs in my house are all unaffected, but then none of them has Java active.
I’m calling bullshyt on those numbers!
My MBP IS CLEAN, too.
Clean here. Three Macs. More FUD.
I’m still a VIRGIN!
Is it OK just to disable Java in Safari preferences or should you also disable Javascript. If I disable Javascript some elements of websites I visit regularly do not function.
Yes. In spite of the names, Java and Javascript are entirely different and separate entities. It is safe to leave Javascript enabled.
Windows computers unaffected…..
My machines are clean too but this raises concerns I didn’t pay much attention to with past similar reports. In the past it’s always been about knowing better than to run as an Admin and not giving your password when something wants to install.
“This version makes its way into Macs through a Java vulnerability, and is loaded onto unpatched Macs without interaction from the user.”
Okay, it’s only one but gees, this is so Windoze like. To me, that’s the real story here. “Nothing to see here, move along” ? I don’t think so. Do we have to start running resource draining protection software now?
Did “resource draining protection software’ help hundreds of millions of Windows users?
BTW, clean here. FUD.
I hope Apple finds a way to get Flash and Java off the Mac platform. Both are buggy resource hogs that are potential vectors for hackers to invade your system. Best to purge them entirely for the sake of the user.
…i feel a scratchy throat and slight fever coming on… but my Mac is just fine…damn viruses…!
YAY I’m clean!
I’m clean. In a related topic, did anyone read how relatively easy it is to remove this thing? It’s just a matter of locating the files and deleting them. Not in the same class as Windows malware at all.
——RM
Clean!
NOTE: The Flashback Trojan horse has 14 versions, according to Intego. The F-Secure method of checking for infection ONLY checks for ONE of those versions, the most dangerous version that uses a Drive-By web infection method not requiring your Admin password.
I you or one of your users is a beginner, newbie or ‘LUSER’ user, it is well worth using the free ClamXav app to check for ALL versions of the Flashback Trojan. You can read about and download ClamXav at the link below. I’m part of a team that works to keep the source ClamAV project up-to-date with current Mac malware.
ClamXav Website
Grammar police. Please read:
‘IF you or one of your users is…’
Thanks frist time to go there ! It was easy just like you said. Apple was no help and I am not happy about that because everything I own is apple. Thank you again.
Answer me this. Let’s say I was infected. Will updating with mac update remove the threat?
Thanks for your help.
No
You guys are a bunch of holocaust/Mac malware deniers. It is security through obscurity, plain and simple. Don’t keep listening to Derek Currie “the computer store worker” who’s main line is “FUD, it is all FUD”. With more popularity of Apple will come more malware. It will be on a progressive scale and not a linear one.
You can keep saying “FUD” but the malware will keep coming. It the malware writer wanted to infect more Macs he just should of laid the code into an iframe in every third party ad server with a load timer that serves up the Mac community and we would of seen a million plus infections easily. The pros have not even lifted a finger yet. This is only one of many to come.
You don’t think the Russian Business Network and China’s Red Dawn malware writers are watching this easy Pwnage of Macs?
You are an idiot or a liar.
There were a handful of viruses for the Mac back during the pre-OS X days. Are you seriously claiming that Macs are MORE obscure now than they were then?
Malware writers HAVE been targeting the Mac all along. But it is just so much harder to create successful malware for a platform that is, gee, I dunno… SECURE.
Flashback has shown that Macs are not invulnerable. But the scope and degree of the threat is microscopic next to the security train wreck that is Windows.
The Russian Business Network and China’s Red Dawn were not around then. Let’s talk today’s reality. Let’s talk the last two years. Not 30 years ago with OS 8 and script kiddies.
Mac’s have for the most part have just been of recent “value” to code malware for in the past two years, and the value of pwning them is only going up as their #’s increase.
I know all my Windows only friends are going Mac after owning an iPhone and iPad. The numbers of people owning Macs has come to the point that writing and distributing malware for organized crime is profitable.
Yea, but look at the holocaust/Mac malware deniers. “They say ” I am not infected so there for it is all FUD. Dr. Web is selling FUD”. Hello!!! Dr Web sink holed the command and control servers. They know what the he(( they are talking about, and they know what they are doing.
Half the people who posted on this thread are total frickin idiots with the way they are talking. Clueless to advanced malware and it’s delivery system and delivery plan.
Are you mentally incapable of stating factually correct information? I am talking about 12 years ago, a time when the Mac platform was THE choice for graphic designers and the motion picture industry. No value, riiight.
So in the entire 11 year history of OS X, the total count of malware capable of infecting the platform without user assistance is now ONE.
And if you ever read anything other than anti-Apple propaganda, you would have noticed that the tech press, especially the Mac-oriented sector of it, is giving this malware major coverage. And they are also pointing out the easy way to identify, remove and guard against the threat WITHOUT needing to spend any money or even install a new program. Contrast that with the state of “security” in the Windows world.
No, 12 years ago Mac malware was a -10 value for organized crime because organized crime as we see it today did not exist.
Oh, I think have a handle on how malware is proliferating on the internet. I have about 3000+ hours of security podcasts from AV venders, analyses venders, academics, corporate penetration experts, gray hat hackers, and white hats.
The OSX malware you saw in the past 2 years has been amateur malware. badly written code that doesn’t complete the writers roadmap of completion. IE amateur. This last Flashbacks variants had some “pro” skill with a strong viable roadmap of completion. More will come, organized crime saw just how easy it was on this one.
Here is another guy who gets it. His name is honeymonster.
“But obviously they are not happy about this publicity. They used a good number of tricks to try to fly under the radar.
Obviously these guys know their stuff. They are in it for the money, not publicity.
Still, this attack is only moderately advanced. It is certainly more sophisticated than a simple trojan as it now infects at drive-by as well. But it is only a taste of what is yet to come.
Expect them to bring over more tricks from their Windows experience, such as morphing code, blended attacks and a hole suite of exploits.
With thus success rate you can be *certain* that they will be back. Stronger. The smug Apple crowd is in for a brute awakening.
As I have written before, Apple has a systemic problem where they *do not* control or materially influence the publication of information about vulnerabilities in their stack. The various open source libraries follow their own schedules and Apple will have a hard time reigning them in and making them commit to coordinated publication when Apple is ready to patch.
In effect, *every* time an external project on which OS X depends publicizes a vulnerability (because a patch is available), this is the equivalent of a zero-day vuln in OS X.
And we know from the Windows experience that only a fraction of 1% of attacks uses attacker-discovered vulns. Attackers now can simply sit back and wait for patches to libxml, apache, java etc.
They know that OS X will be notoriously late, so they’ll have a window of opportunity practically every time.
And the best part: The Mac users are shockingly complacent (evidenced in these very talkbacks) and refuse to accept that they can be affected. They are easy targets.”
First off Derek, I think using Sophos Free for Mac is far superior to ClamXav. Sophos is very very light on resources and scans in real-time. ClamXav is only an on-demand scanner except for if it is setup with it’s Sentry Scanner for downloads and email. With such light use of resource use Sophos scans http traffic and all processes.
Here is a question I asked Chester Wisniewski of Sophos labs..
http://nakedsecurity.sophos.com/2012/04/07/sscc-87-mac-botnet-global-payments-flash-player-updater
Ted asks…
Could this java vul be used in a third party ad server where the Mac community hangs out, IE mac geek sites and be used in a hidden i-frame and install and pwn under the radar? If yes, and if they laid out the attack different, it looks like they could of pwned millions. Comments please.
Reply
Chester Wisniewski says:
April 9, 2012 at 9:17 pm
Unfortunately, yes. Just like any other web vulnerability targeting Windows users the malicious code can be embedded/distributed through any method you can dream up.
This is not Apple’s fault so no need for them to be embarrassed. Adobe should strap up, step up and do something about Flash, like Microsoft did with macro vulnerabilities for many years.
I’m not sure why but this website is loading incredibly slow
for me. Is anyone else having this issue or is it a problem on my end?
I’ll check back later and see if the problem still exists.