Latest Comments
"im not receiving my emails can send but cant receive.was fine last night this morning not working"
by r reid | Mar 19, 2010 2:24 AM
 
"hmm... the article sounds very good but isn't his last point spamcop? don't we already have ..."
by anon | Mar 18, 2010 2:35 PM
 
"The claim listed above that NetRegistry CEO Larry Bloch said - and I quote "giving over your ..."
by Joe Baptista | Mar 18, 2010 12:39 PM
 
"yes a survey of 24000 who actually understand the issue rather than a survey of 24000 semi-tech-i..."
by Ash | Mar 18, 2010 12:19 AM
 
"Have the EFA produced the definitive and clear quote yet where Conroy calls his critics ..."
by Mazza | Mar 17, 2010 5:41 PM

Mac worm poses little risk, represents cross-platform innovation

  • Email a Friend
  • Print Page
By Angela Moscaritolo
May 6, 2009 10:27 AM
Tags: Mac | worm | Apple | OSX/Tored.A | malware
A recently discovered Macintosh worm, known as OSX/Tored.A, remains a low-risk threat but is an indication that malware authors are not turning a blind eye to the Apple platform, say researchers.

Mac security vendors received the proof-of-concept malware from the worm's creator in late April,  Peter James, spokesman at Mac security firm Intego, told SCMagazineUS.com.

He said the malware poses little threat and there have been no instances of it circulating in the wild. However, the worm does contain a feature rarely seen – the ability to run across multiple platforms. If the code was “cleaned up” and then circulated, it might be something to worry about, James said.

“The person wanted to show off,” James said. “We think that for now this person just wanted to prove that this is possible.”

Once executed, the malware renames itself “applesystem” or “systemupdate” and attempts to copy itself to system folders, according to an Intego security memo. The program then attempts to obtain email addresses from an infected user's address book and forward itself to other computers. In addition, it attempts to create a botnet, record keystrokes and copy itself to other disks on the computer.

Users likely will not encounter this worm because it attempts to forward itself using an inactive SMTP server, Graham Cluley, senior technology consultant at Sophos, told SCMagazineUS.com in an email. Also, though it attempts to spread to removable disks, it has not been successful in testing conducted by Sophos.

The main interest in this malware is the curiosity value, since it targets the Mac OS X platform, Cluley said.

“Presumably this is being caused by an increased popularity in Macs among the general public, combined with a general laissez-faire attitude among many Mac users to security compared to their Windows cousins," he said.

Also, the malware was created in a way that could enable it to run on other platforms, James said. It was developed using REALBasic, a programming language available for Mac OS X, Windows or Linux that enables programmers to build applications on one platform for another.

“It's the first time we are seeing something that can run on multiple platforms,” James said. “A Java applet can run on multiple platforms, but that still depends on something in the system: Your having Java installed.”

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers