New Mac OS X backdoor Trojan, Sabpab, discovered


Recommended Posts

Hot off the heels of the Flashback malware, Sophos has announced the discovery of a new Mac OSX Trojan, Sabpab, which uses the same Java vulnerability Flashback used, and just like Flashback, doesn't need or require any user interaction to be installed.

The newly discovered Sabpab malware is in many ways a basic backdoor Trojan horse. It connects to a control server using HTTP, receiving commands from remote hackers as to what it should do. The criminals behind the attack can grab screenshots from infected Macs, upload and download files, and execute commands remotely.

The Trojan creates the files

/Users/<user>/Library/Preferences/com.apple.PubSabAgent.pfile

/Users/<user>/Library/LaunchAgents/com.apple.PubSabAGent.plist

Encrypted logs are sent back to the control server, so the hackers can monitor activity.

The potential for abuse of compromised Macs should be obvious, given the Trojan's functionality.

Source: SOPHOS

Apple needs to hand over the maintenance of Java over to its main company. Days of Macs being virus proof are over.

seriously, I can't understand why Apple wants to be in control of when java updates get pushed (aka almost never)

The coffee is opening holes in the apple :p

Anyway since they already fixed that Java issue, this trojan won't affect patched systems, right?

Maybe Apple can buy an anti-virus company and create Apple Security Essentials :p

Apples approach to security is light years ahead of Microsoft, Mac OS can require apps to be signed, each app is broken up into separate parts with each part only able to do one thing, like with QuickTime, the Video Decoder, is ONLY allowed read from teh disk and decry pt the content of a video stream. I could go on, but Ars had a great line up in their OS X Lion review.

Apples approach to security is light years ahead of Microsoft

Don't think I've laughed so hard in a long time, my chest hurts! When it comes to security, the only thing Apple is light years ahead of Microsoft on is denial.

  • Like 3

Part of me wishes Steve was still alive to declare war on Java just like he did Flash. :/

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.

Agreed. I hate the fact I get a prompt to install Java when I'm launching Adobe Photoshop the first time. :pinch:

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.

I'm a Minecraft player and even I think Java needs to die
  • Like 3

Best advice I can give is to just keep Java disabled in your browser of choice. It's already disabled by default in Safari on Lion (even if you have Java installed like Adobe has forced me to do).

Apples approach to security is light years ahead of Microsoft, Mac OS can require apps to be signed, each app is broken up into separate parts with each part only able to do one thing, like with QuickTime, the Video Decoder, is ONLY allowed read from teh disk and decry pt the content of a video stream. I could go on, but Ars had a great line up in their OS X Lion review.

I assume you mean the other way around. Microsoft has always had a huge head start on the security front and they've had the infrastructure and teams established within the company to deal with threats for considerably longer. Your example is great, but IE has had protected mode since Vista AND that can be used by any other apps to switch threads or processes to low IL.

Haven't even touched on ASLR, DEP, and other technologies (I have a larger list in a notebook at home).

Windows 8 will bring even more improvements for intra process security and doing the same application signing requirements for Metro apps.

Apple just released two updates to address this issue and a removal tool for Macs without Java installed.

That's the point I don't understand. Flashback and this new supposed one are Java exploits....so if my Mac doesn't have Java installed how can my machine get infected and thus need this removal tool? Isn't the best defense on this just not to have Java installed along with a good a/v scanner?

That's the point I don't understand. Flashback and this new supposed one are Java exploits....so if my Mac doesn't have Java installed how can my machine get infected and thus need this removal tool? Isn't the best defense on this just not to have Java installed along with a good a/v scanner?

Yes.

I'm glad I upgraded all my Macs to Windows 7 in time.

Yupp.

Zero vulnerabilities. :rolleyes: :laugh:

Glassed Silver:mac

  • Like 3

And did you ditch OS X completely ? If so, I don?t understand your point. If anything, your Macs are a couple of times more vulnerable than ever before. It?s your call, man.

I still have OS X but I have no real reason to use it anymore. The question then becomes, why did I get a Mac in the first place? I didn't know Windows 7 was so good. If I did at the time, I would have saved myself some money and built my own PC.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • 0 chance of that happening, forget it. Get it installed by some tech guy or do it yourself with the bypasses, that's how MS is being lenient and looking the other way to give users a chance.
    • Ooooooh, now we got the big tech corps fighting
    • Segra 1.6.3 by Razvan Serea Segra is a free, open-source OBS-powered game recorder offering fast gameplay capture, instant clips, AI highlights, deep game integration, and seamless uploads—perfect for gamers, streamers, and content creators. Lightweight, fast, zero bloat. Segra key features: Automatic Game Recording: Begin capturing gameplay the moment your game launches, with zero manual setup. Instant Clipping: Save important moments instantly using a customizable hotkey—perfect for highlights, montages, or quick shares. Segra AI Highlights: Let Segra automatically detect kills, assists, deaths, and key events to generate polished highlight reels without manual editing. Gameplay Uploads: Upload recordings and clips directly to Segra.tv for fast sharing and cloud access. Deep Game Integration: Enjoy advanced game-data tracking across hundreds of supported titles, enabling smart highlight generation and stat-informed clipping. High-Performance Capture: Record up to 4K at 144 FPS using OBS-powered technology with minimal performance impact, supporting NVENC, AMD VCE, and custom quality controls. Segra Editor: Edit recordings easily with timeline controls, segment management, and event-based navigation to build the perfect clip. Customization Options: Adjust hotkeys, output formats, storage paths, codecs, capture quality, and performance settings for a tailored recording experience. Segra 1.6.3 changelog: Recording: Reworked the whitelist/blacklist into per-game recording with individual setting overrides. Settings: Added Windows Game Mode and Startup window mode options. Audio: Improved noise suppression for microphone capture. Clips: Added a separate export mode for segment clips. Updates: Fixed pending update state not showing by replaying it when the frontend reconnects. Recording: Fixed an issue where audio could break or sources could linger between recordings. Stability: Fixed a rare crash that could happen when a game closed. Settings: Fixed settings not applying correctly on some non-English systems. Download: Segra 1.6.3 | 74.5 MB (Open Source) View: Segra Homepage | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • So, recently, I saw on the news (yes, on this website) that Samsung is introducing features where it can provide education using AI-powered sets, and because of this, I got concerned about whether the AI gives out wrong info during education sessions, causing controversies in the process. What are your thoughts on this? 
    • TCL's Bang & Olufsen soundbar is 40% off on Amazon by Ivan Jenic The TCL Design Series A65K is currently $299.99, down from $499.99. That's 40% off and $200 saved on a soundbar tuned by Bang & Olufsen, which is not a combination you'd normally expect at this price point (purchase link below). Bang & Olufsen doesn't typically show up in the sub-$500 category. The Danish audio brand is known for speakers that cost several times more, so having their acoustic tuning on a $300 soundbar is very appealing. TCL handles the hardware, B&O handles the sound engineering, and the result is what the company calls "accessible luxury." Still, accessible luxury isn’t full-fledged luxury, so don’t expect wonders. But this is a decent soundbar, nevertheless. The A65K is a true 3.1.2 channel system with nine physical drivers, including genuine up-firing height speakers for Dolby Atmos and DTS:X. Many soundbars at this price simulate overhead effects through virtual processing, rather than actual hardware. So, you’re getting the real deal. The design is unusually slim for a system with Atmos compatibility. The bar is just under 2 inches deep and should fit beneath most TV screens. The wireless subwoofer is also compact at roughly 14 x 14 x 5 inches. Total output is 460W, and you can connect to the soundbar via HDMI eARC, Bluetooth 5.3, or USB. There are also eight sound modes through the TCL Home app and an AI calibration capability. Although it’s worth mentioning that AI capabilities in most of these devices are inconsistent, to say the least, and that shouldn’t be the biggest selling point. Still, at $299.99, the A65K is a strong buy for anyone who wants a soundbar that sounds and looks noticeably better than what this price range usually offers. And the Bang & Olufsen branding surely sounds nice - pun intended. TCL Design Series Bang & Olufsen A65K - $299.99 | 40% off on Amazon Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Apprentice
      jahara21 went up a rank
      Apprentice
    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      529
    2. 2
      +Edouard
      263
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      96
    5. 5
      macoman
      59
  • Tell a friend

    Love Neowin? Tell a friend!