Welcome Guest! To access all forums & features, please register an account or sign-in. → Why register?



New Mac OS X backdoor Trojan, Sabpab, discovered


60 replies to this topic * * * * - 4 votes

#1 Dot Matrix

    Neowinian UNSTOPPABLE

  • 5,736 posts
  • Joined: 14-November 11
  • Location: USA
  • OS: Windows 8
  • Phone: Nokia Lumia 920

Posted 14 April 2012 - 03:29

Hot off the heels of the Flashback malware, Sophos has announced the discovery of a new Mac OSX Trojan, Sabpab, which uses the same Java vulnerability Flashback used, and just like Flashback, doesn't need or require any user interaction to be installed.

Quote

The newly discovered Sabpab malware is in many ways a basic backdoor Trojan horse. It connects to a control server using HTTP, receiving commands from remote hackers as to what it should do. The criminals behind the attack can grab screenshots from infected Macs, upload and download files, and execute commands remotely.

The Trojan creates the files


/Users/<user>/Library/Preferences/com.apple.PubSabAgent.pfile

/Users/<user>/Library/LaunchAgents/com.apple.PubSabAGent.plist


Encrypted logs are sent back to the control server, so the hackers can monitor activity.

The potential for abuse of compromised Macs should be obvious, given the Trojan's functionality.


Source: SOPHOS


#2 +sanke1

    Member

  • 2,041 posts
  • Joined: 07-October 07

Posted 14 April 2012 - 05:25

Apple needs to hand over the maintenance of Java over to its main company. Days of Macs being virus proof are over.

#3 +Brando212

    Causer of disasters

  • 5,468 posts
  • Joined: 15-April 10
  • Location: right behind you
  • OS: OSX ML, Windows 7/8 Pro

Posted 14 April 2012 - 06:48

View Postsanke1, on 14 April 2012 - 05:25, said:

Apple needs to hand over the maintenance of Java over to its main company. Days of Macs being virus proof are over.
seriously, I can't understand why Apple wants to be in control of when java updates get pushed (aka almost never)

#4 iron2000

    Mecha-mad

  • 1,908 posts
  • Joined: 14-November 02

Posted 14 April 2012 - 08:39

The coffee is opening holes in the apple :p

Anyway since they already fixed that Java issue, this trojan won't affect patched systems, right?
Maybe Apple can buy an anti-virus company and create Apple Security Essentials :p

#5 BumbleBritches57

    Neowinian³

  • 381 posts
  • Joined: 03-October 10
  • OS: Windows 7 x64, iOS 5.1.1

Posted 14 April 2012 - 08:46

View Postiron2000, on 14 April 2012 - 08:39, said:

The coffee is opening holes in the apple :p

Anyway since they already fixed that Java issue, this trojan won't affect patched systems, right?
Maybe Apple can buy an anti-virus company and create Apple Security Essentials :p

Apples approach to security is light years ahead of Microsoft, Mac OS can require apps to be signed, each app is broken up into separate parts with each part only able to do one thing, like with QuickTime, the Video Decoder, is ONLY allowed read from teh disk and decry pt the content of a video stream. I could go on, but Ars had a great line up in their OS X Lion review.

#6 .Neo

    Generic User

  • 16,998 posts
  • Joined: 14-September 05
  • Location: Amsterdam, NL
  • OS: OS X Mountain Lion
  • Phone: iPhone 5

Posted 14 April 2012 - 13:16

View PostBrando212, on 14 April 2012 - 06:48, said:

seriously, I can't understand why Apple wants to be in control of when java updates get pushed (aka almost never)
Apple just released two updates to address this issue and a removal tool for Macs without Java installed.

#7 +Vice

    Bye!

  • 15,877 posts
  • Joined: 03-September 04

Posted 14 April 2012 - 13:20

View Postsanke1, on 14 April 2012 - 05:25, said:

Apple needs to hand over the maintenance of Java over to its main company. Days of Macs being virus proof are over.

Apple is winding down its support of Java in OS X. But Oracle don't want to support it.

#8 +cooky560

    Neowinian Wise One

  • 3,069 posts
  • Joined: 15-April 05
  • Location: Around
  • OS: Mac OSX
  • Phone: iPhone 5

Posted 14 April 2012 - 13:28

the article fails to mention how easy this malware is to remove, that information might be worth posting if it exists.

#9 funkydude

    Resident Fanatic

  • 565 posts
  • Joined: 18-March 11
  • OS: Windows 8, Xubuntu, Mint (cinnamon)

Posted 14 April 2012 - 13:34

View PostBumbleBritches57, on 14 April 2012 - 08:46, said:

Apples approach to security is light years ahead of Microsoft

Don't think I've laughed so hard in a long time, my chest hurts! When it comes to security, the only thing Apple is light years ahead of Microsoft on is denial.

#10 OP Dot Matrix

    Neowinian UNSTOPPABLE

  • 5,736 posts
  • Joined: 14-November 11
  • Location: USA
  • OS: Windows 8
  • Phone: Nokia Lumia 920

Posted 14 April 2012 - 13:44

Part of me wishes Steve was still alive to declare war on Java just like he did Flash. :/

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.

#11 .Neo

    Generic User

  • 16,998 posts
  • Joined: 14-September 05
  • Location: Amsterdam, NL
  • OS: OS X Mountain Lion
  • Phone: iPhone 5

Posted 14 April 2012 - 13:47

View PostDot Matrix, on 14 April 2012 - 13:44, said:

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.
Agreed. I hate the fact I get a prompt to install Java when I'm launching Adobe Photoshop the first time. :pinch:

#12 Hum

    totally wAcKed

  • 54,480 posts
  • Joined: 05-October 03
  • Location: Odder Space
  • OS: Windows XP, 7

Posted 14 April 2012 - 13:59

good News

#13 +Phouchg

    100% Nutcase Lately

  • 3,795 posts
  • Joined: 28-March 11
  • Location: Krikkit
  • OS: GrumpyOS 6.1.7601 x64

Posted 14 April 2012 - 14:03

Hello, I'm a PC and...

Posted Image

#14 +Brando212

    Causer of disasters

  • 5,468 posts
  • Joined: 15-April 10
  • Location: right behind you
  • OS: OSX ML, Windows 7/8 Pro

Posted 14 April 2012 - 14:39

View PostDot Matrix, on 14 April 2012 - 13:44, said:

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.
I'm a Minecraft player and even I think Java needs to die

#15 virtorio

    1076

  • 6,959 posts
  • Joined: 28-April 03
  • Location: New Zealand
  • OS: OSX 10.8, Windows 8
  • Phone: Windows Phone 7.8

Posted 14 April 2012 - 14:55

At least OS X is getting popular enough for malware writers to bother.