Technology content trusted by users in North America and around the world.
4,958 Articles | 29,940 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

TRENDING NOW: Xbox One - Just what is Microsoft thinking?!
USA EditionYou are located: Home > All News > Hacking & Security News > Another OS X Trojan has been identified, this one bypasses user permissions

Another OS X Trojan has been identified, this one bypasses user permissions

By: (more) | Hacking & Security News | Posted: Jul 25, 2012 3:30 am

Apple have been hit again, with security firm Intego and their virus team identifying yet another Trojan horse that attacks Apple's Mac platform. The new Trojan called "Crisis", hasn't been seen in the wild yet, but Intego says that the Trojan is engineered to make analysis of the malware difficult for security experts.

 

another_os_x_trojan_has_been_identified_this_one_bypasses_user_permissions

 

Intego have stressed alertness regarding Crisis, as it appears to be quite smart, having the ability to bypass OS X security features and install itself, all without any user interaction.

 

Crisis has been tracked, back to the IP address of 176.58.100.37, which it then calls back to every five minutes for instructions. There's only two OS X versions that are said to be susceptible to Crisis, OS X 10.6 and 10.7. Crisis can install and run itself without the need for the user to enter in their password. It's also resistant to reboots, and will run until it is detected and removed.

 

If Crisis is installed onto a user account with root permissions, the Trojan will install additional programs in order to hide itself. With or without root access, Crisis will install the following file:

 

/Library/ScriptingAdditions/appleHID/Contents/Resources/appleOsax.r

 

When Crisis has root access, it installs two additional files:

 

/System/Library/Frameworks/Foundation.framework/XPCServices/com.apple.mdworker_server.xpc/Contents/MacOS/com.apple.mdworker_server

 

and

 

/System/Library/Frameworks/Foundation.framework/XPCServices/com.apple.mdworker_server.xpc/Contents/Resources/

 

Intego has updated its VirusBarrier X6 software to guard against this new malware, and other definitions dated July 24, 2012 or later.

 

Now the question is to your Mac, "can it run Crisis?" ;)


SOURCE #1, #2

Related Tags



Further Reading: Read and find more Hacking & Security news at our Hacking & Security news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: MSI Z77A-GD65 Gaming Series (Intel Z77) Motherboard Review
  • Upcoming Content: HGST Travelstar 7K1000 1TB 2.5" Hard Drive Review
  • Upcoming Content: Western Digital My Passport Edge for Mac 500GB External HDD Review
  • Upcoming Content: PQI Air Card 4GB Wi-Fi SDHC Review
  • Upcoming Content: LaCie CloudBox 1TB Personal NAS Review
  • Upcoming Content: Star Trek: The Next Generation - Season Three (1989) Blu-ray Review
  • Upcoming Content: The Hobbit: An Unexpected Journey (2012) Blu-ray Movie Review
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: ADATA DashDrive Elite UE700 USB 3.0 Flash Drive Review
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review


Hacking & Security News Posts

View More Hacking & Security News Posts


TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Hacking & Security Press Releases

View More Hacking & Security Press Releases