New Mac OS X backdoor Trojan, Sabpab, discovered


Recommended Posts

That's the point I don't understand. Flashback and this new supposed one are Java exploits....so if my Mac doesn't have Java installed how can my machine get infected and thus need this removal tool? Isn't the best defense on this just not to have Java installed along with a good a/v scanner?

Better to be safe than sorry I guess? If you run Adobe CS5 you're forced to install Java, so that's not always an option. For most of the public here a a/v scanner still isn't necessary really. Just disable Java in your browser and don't install software from untrusted sources.

I'm glad I upgraded all my Macs to Windows 7 in time.

Yes because we all know there are no trojans whatsoever for Windows.

Apples approach to security is light years ahead of Microsoft, Mac OS can require apps to be signed, each app is broken up into separate parts with each part only able to do one thing, like with QuickTime, the Video Decoder, is ONLY allowed read from teh disk and decry pt the content of a video stream. I could go on, but Ars had a great line up in their OS X Lion review.

I've never really looked into mac security all that much, but if you can exploit java then it doesn't matter HOW MUCH security you put in with signed executables (I don't think they need to be signed, it's got the same 'mark as dirty/from another computer' security bit that windows does which gives a 'are you SURE you want to run this application' message), because you can exploit valid signed programs and do things with them.

Anyway, macs are getting more popular so there's going to be a huge rapid increase in exploits and viruses for them in the future.

Edit: Also, PC vendors are all from different manufacturers and whatnot, (I'm talking laptops/netbooks/ultrabooks/tablets specifically here) whereas all of apples line use the same base hardware, which includes the exact same password say, for the administration functions of the battery, and with that power it doesn't take much to blow one up as a security researcher demonstrated (FYI; apple still haven't stopped using the same battery firmware password OR allowed you to change it).

I still have OS X but I have no real reason to use it anymore. The question then becomes, why did I get a Mac in the first place? I didn't know Windows 7 was so good. If I did at the time, I would have saved myself some money and built my own PC.

It depends if you have a desktop or not. Of all laptops that I have seen in my life, I would buy a MacBook with Windows 7 on it over anything else. They just gave me an HP from somebody else last week at work and couldn?t stand it, now I have my Toshiba for myself and it?s even worse. I?m still considering telling them I want to use my MacBook Pro instead :p

Then again, of all desktops I have seen, the iMac remains my favorite one too, but the difference is less marked with an iMac, because you can easily build a tower with exactly what you want.

When it comes to security, the only thing Apple is light years ahead of Microsoft on is denial.

and customer loyalty, and bank account, and tablet market, and phone sales, and service support, and apps, and on and on... and before you flame, i do not own a mac, i just am starting to see that apple hate is getting very annoying from kids that are too young (or adults that are too old) to comment on stuff they are obviously biased on.
  • Like 2

and customer loyalty, and bank account, and tablet market, and phone sales, and service support, and apps, and on and on... and before you flame, i do not own a mac, i just am starting to see that apple hate is getting very annoying from kids that are too young (or adults that are too old) to comment on stuff they are obviously biased on.

Apple !== Microsoft

Note the extra equal sign.

How can people get so charged up over tech companies is beyond me.

resol612:whatever platform i'm typing on

First and foremost I am not anti-Apple- However this should be a wake up call... for now it is only Flash and Java based attacks.... Apple should realize that now they are on the radar instead of flying just below. This is how it started for them before...You will have to remember back in the days when there was IBM DOS and they said back then... Only DOS gets viruses, then the attacks started for the Apple II machines...

The true question now is.... How will Apple handle this? Denial, Acceptance or Locking a user to only approved applications to be installed on OSX?

Days of Macs being virus proof are over.

In 1982, as a high school student at Mt. Lebanon High School, Skrenta wrote the Elk Cloner virus that infected Apple II machines. It is widely believed to be the first large-scale self-spreading personal computer virus ever created.

http://en.wikipedia.org/wiki/Rich_Skrenta

Seems like the Mac was a haven for virus right from the start. Apple have a wonderful way of brainwashing people. I own an ipod.

  • Like 2

and customer loyalty, and bank account, and tablet market, and phone sales, and service support, and apps, and on and on... and before you flame, i do not own a mac, i just am starting to see that apple hate is getting very annoying from kids that are too young (or adults that are too old) to comment on stuff they are obviously biased on.

Calm down dear! It's not "Apple hate", it's a dig response to Apple adoration, and completely on-topic with security, which your post is not.

First and foremost I am not anti-Apple- However this should be a wake up call... for now it is only Flash and Java based attacks.... Apple should realize that now they are on the radar instead of flying just below. This is how it started for them before...You will have to remember back in the days when there was IBM DOS and they said back then... Only DOS gets viruses, then the attacks started for the Apple II machines...

The true question now is.... How will Apple handle this? Denial, Acceptance or Locking a user to only approved applications to be installed on OSX?

Couldn't one say that if you didn't have flash or java installed then you wouldn't have this issue? So far....is there an actual virus/trojan/exploit for os x itself and not flash or java on os x?

So far....is there an actual virus/trojan/exploit for os x itself and not flash or java on os x?

Yes.

Anyway, that's a pointless argument. Does anyone ever say "Hmm, got a virus, but good thing [Company X] code wasn't involved!"

Trojan vs virus? [To your credit, you aren't making a distinction in your post, but others are] Does anyone ever say "Hmm, my computer is infected and taking commands from a remote server and transmitting my banking information to criminals. Good thing it's just a trojan!"

Couldn't one say that if you didn't have flash or java installed then you wouldn't have this issue? So far....is there an actual virus/trojan/exploit for os x itself and not flash or java on os x?

The problem actually could possibly be that Apple allowed people to install Java and Flash.... they could take the alternate route of only allowing approved programs to install-- I.E. those that are bought at through iTunes or on an Apple DVD. Though from what I understand java was included with OSX but has since been removed. Many programs still unfortunately require java in order to run though.

Though you could actually say if they were not installed then you would not have those issues, however, just in these programs being exploited one must ask the inevitable question.... "What else are the hackers and male-ware developers working on to exploit my system?"

For many years Apple has been under the radar of such exploits, now all of sudden something like this appears.

Sure, by all means remove Java and Flash, but the question is "Where is the next attack coming from and how to avoid it?"

Some have suggested- the next exploit could actually be the way it handles viewing images... but that remains to be seen.

The point is, for so long has there not been little research into avoiding Virus and Male-ware, but now it may be time to look into ways to prevent it.

In Windows now through Security Updates, Malicious Software Removal Tools, Anti-Virus, Script Blockers, Resident programs (like that in Spybot Search and Destroy) or other programs like that to block out the bad.

Also more and more programs are choosing to run in user modes and also inside memory sandboxes, it may now be time for Apple to consider applying programs like that in order to circumvent the next outbreak.

- I had always thought each system in order to do an update to help stop malicious code would need to reboot before installing them or actually having to insert a boot dvd in order to make system changes...

Windows downloads updates then prompts you to insert your install medium to reboot and install updates... also this would be required when a program wants to add itself to the start up of the computer.

(these were just thoughts to help stop the spread of Male-ware and Viruses)

Yes.

Anyway, that's a pointless argument. Does anyone ever say "Hmm, got a virus, but good thing [Company X] code wasn't involved!"

Trojan vs virus? [To your credit, you aren't making a distinction in your post, but others are] Does anyone ever say "Hmm, my computer is infected and taking commands from a remote server and transmitting my banking information to criminals. Good thing it's just a trojan!"

Good point... the relative term from what is a virus and male-ware are small.... but this should be a wake-up call that Apple is now on the radar.

Apples approach to security is light years ahead of Microsoft, Mac OS can require apps to be signed, each app is broken up into separate parts with each part only able to do one thing, like with QuickTime, the Video Decoder, is ONLY allowed read from teh disk and decry pt the content of a video stream. I could go on, but Ars had a great line up in their OS X Lion review.

Wow you can not be so wrong. Both companies try to build security into their products, but no security is perfect and that's where the similarities end. The companies' approach to security response is completely different.

One has a dedicated security team who puts out timely patches and advisories, tries to work pro-actively with hackers to prevent a 0-day release (a 0-day is where a security hole is being exploited before the company knows that there even was a security hole), puts out a patch to a 0-day hole as soon as possible, releases monthly removal tools for common Malware (especially those that used a 0-day), offers free antivirus to all paying users. There is nothing more they could possible do that they are not already doing.

The other likes to advertise their security quite strongly, especially compared to the other, but when a security hole is found despite all their "advanced securities" they keep it a secret for months, and then when it is found out that it is being actively exploited they deny that there is anything wrong with their software, say that it is not their fault that there is a security hole affecting their products, sit on their hands for more months while they decide if they even want to close the security hole, and then eventually many more months after that they decide to put out an update to clean up the infected machines.

I wonder how it will go next time that a security bug is found which Apple won't fix and a virus comes in which will silently overwrite all the time machine backups with dummy data either straight away (because many users leave their time machine disks always plugged in or use Time capsule) or waits until the Time machine backup is plugged in while making it look like the time machine is working properly.Then when it has finished making the time machine backup useless (PS: Time Machine supports only ONE backup destination) it will then wait until a certain time to allow the virus to spread without being detected. After this it will then overwrite all the data on the main computer itself and then all Mac users will be screwed with no backup and no data at the same time because Apple did not do anything about security.

...

I wonder how it will go next time that a security bug is found which Apple won't fix and a virus comes in which will silently overwrite all the time machine backups with dummy data either straight away (because many users leave their time machine disks always plugged in or use Time capsule) or waits until the Time machine backup is plugged in while making it look like the time machine is working properly.Then when it has finished making the time machine backup useless (PS: Time Machine supports only ONE backup destination) it will then wait until a certain time to allow the virus to spread without being detected. After this it will then overwrite all the data on the main computer itself and then all Mac users will be screwed with no backup and no data at the same time because Apple did not do anything about security.

I have heard that could be a possible exploit... the time machine-- whereby no active file is written which bypasses the security when the maleware/virus is inserted-... then when the user uses the time machine to go back - he then will have rights to write to system files without being signed, because a backup file does not have that signature and therefore won't be checked.

In other words-- if there can be an insertion point into the time machine (which is not monitored and protected by OS X) then when the user initiated a backup it will have the rights to write to system files... that is what I have heard as a possible way to exploit a system when file protection is enabled. (this is a concept with Windows Backups)... because the backup runs as a user but the writing the back to the main system is ran as a Power User or Administrator. Based upon that theory it could theoretically affect OSX in the same way just like that of Linux.

This is *APPLE MAC OSX BASED* malware that is loaded onto the system via an exploit in Java. This malware and Flashback were written specifically for the Mac.

There are still some Apple faithful out there trying to pass this stuff off as NBD, and still see their holier than thou OS as bulletproof, and are quickly laying the blame on Java.

Apples approach to security is light years ahead of Microsoft, Mac OS can require apps to be signed, each app is broken up into separate parts with each part only able to do one thing, like with QuickTime, the Video Decoder, is ONLY allowed read from teh disk and decry pt the content of a video stream. I could go on, but Ars had a great line up in their OS X Lion review.

Apple can be slower than Microsoft to plug hole's though.

Apple can be slower than Microsoft to plug hole's though.

This is true though. I prefer Apple?s approach over Microsoft when it comes to security, but they could fix them faster. With MS, under 24-48 hours, it would be a thing of the past already. Took like 4-5 days with Apple.

Having what is described as a great approach to security, Apple wouldn't have Trojan Virus issues on their OS X platform, it would be virus free. But since the take the longest time to release patches to fix issues after a period of denial, it just shows that the os isn't as secure as people once thought. It does seem like OS X has now be come the main target for viruses and malware just like Windows XP was.

Having what is described as a great approach to security, Apple wouldn't have Trojan Virus issues on their OS X platform, it would be virus free. But since the take the longest time to release patches to fix issues after a period of denial, it just shows that the os isn't as secure as people once thought. It does seem like OS X has now be come the main target for viruses and malware just like Windows XP was.

That comparison is pretty ridiculous.

On a sidenote: Apple's current teams are new to malware fixing (not brand new, but MS sure have a lot more expertise).

To be honest, I can see Apple buying up an AV company easily.

It would stay in the background like Defender on W8 and get updates through a more appropriate and faster channel than Software Update...

Glassed Silver:mac

Having what is described as a great approach to security, Apple wouldn't have Trojan Virus issues on their OS X platform, it would be virus free. But since the take the longest time to release patches to fix issues after a period of denial, it just shows that the os isn't as secure as people once thought. It does seem like OS X has now be come the main target for viruses and malware just like Windows XP was.

Except there still isn't a single virus out in the wild for OS X. There were for Mac OS 9 (an OS with a much lower market share), but not OS X.

Except there still isn't a single virus out in the wild for OS X. There were for Mac OS 9 (an OS with a much lower market share), but not OS X.

There's also not many games in the wild for OS X. I guess that's one of the trade-offs.

There's also not many games in the wild for OS X. I guess that's one of the trade-offs.

But every year becomes the best year for Mac gaming.

With the App Store, with Steam and with ported games from the iPhone and iPad to Mac OS X, and with companies who now recognize the Mac as a gaming platform, this isn?t really a valid argument.

On the other hand, there will always be like less than 3-5 malware for OS X every year. This has remained stable.

  • Like 1
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • TeraCopy 4.0 Build 28 by Razvan Serea TeraCopy is a compact program designed to copy and move files at the maximum possible speed, also providing you with a lot of features. Copy files faster. TeraCopy uses dynamically adjusted buffers to reduce seek times. Asynchronous copy speeds up file transfer between two physical hard drives. Pause and resume transfers. Pause copy process at any time to free up system resources and continue with a single click. Error recovery. In case of copy error, TeraCopy will try several times and in the worse case just skips the file, not terminating the entire transfer. Interactive file list. TeraCopy shows failed file transfers and lets you fix the problem and recopy only problem files. Shell integration. TeraCopy can completely replace Explorer copy and move functions, allowing you work with files as usual. TeraCopy is free for non-commercial use only. For commercial use you need to buy a license. The paid version of the program includes the following features: Copy/move to your favorite folders. Save reports as HTML and CSV files. Select files with the same extension/folder. Remove the selected files from the copy queue. Features added since version 3.17: Enhanced speed graph. New multi-threaded copy engine. Support for copying to multiple targets. Queue system for managing multiple copy operations. Support for receiving files via the LocalSend protocol. TeraCopy entry in the modern Windows Explorer context menu. Integrated toolbar in the title bar. Why receive LocalSend transfers with TeraCopy? Handle file conflicts: Skip, overwrite, or rename files when a file with the same name already exists. LocalSend always creates another copy, which can waste time and disk space, especially when resuming an interrupted transfer. Filter unwanted files: Apply ignore lists or remove files manually before accepting a transfer, so unnecessary files are not downloaded. Better performance on fast networks: In tests over a 10 Gbps connection, TeraCopy received files several times faster than the standard LocalSend app on Windows. TeraCopy 4.0 Build 28 changelog: Fixed a bug where Overwrite behaved as Overwrite All during same-drive move operations. AdvancedInstaller fixed the installer’s security vulnerability: EXE Bootstrapper resolved the %appdata% location incorrectly for the System account. Download: TeraCopy 4.0 Build 28 | 14.6 MB (Freeware, paid upgrade available) View: TeraCopy Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • First exciting thing to come to Windows in a long time ! This is the kind of things they should focus on, instead of cramming as much AI as they can in everything.
    • New AMD graphics driver fixes install issues and FSR 4.1 crashes on RX 7000 GPUs by Taras Buria AMD is rolling out yet another graphics driver. Version 26.6.4 is now available for download, bringing two important fixes. One is for those still using Windows 10 and having trouble installing driver 26.6.2. In fact, this patch is coming from the recently released hotfix, so it is not new if you are already running version 26.6.3. The second fix is for RX 7000 owners. AMD recently brought FSR 4.1 support to the previous-gen graphics cards, but there was a bug with certain games crashing when using FSR 4.1. I experienced this issue with Forza Horizon 6, so today's driver should take care of that. Here is the official changelog: Intermittent install issue seen when installing AMD Software: Adrenalin Edition 26.6.2 on Windows® 10 systems for Radeon™ RX 7000 series and above graphics products. Intermittent application crash may be observed in some games with AMD FSR Upscaling 4.1 enabled on Radeon™ RX 7000 series graphics products. Known issues include the following: Intermittent application crash or driver timeout may be observed while playing Battlefield™ 6 on AMD Ryzen AI 9 HX 370. AMD is actively working on a resolution with the developer to be released as soon as possible. Texture flickering or corruption may appear while playing Battlefield™ 6 with AMD Record and Stream on some AMD graphics products. AMD FSR Upscaling and AMD FSR Frame Generation may show as inactive in AMD Software: Adrenalin Edition while playing Battlefield™ 6 when enabled on Radeon™ RX 9000 series graphics products. Failure to install may be observed while installing AI Bundle components in some regions with limited access to HuggingFace and GitHub. Model flickering or rendering failure may be observed in Maxon Cinema 4D and Blender on Radeon™ RX 7000 series and above graphics products. Users experiencing this issue are recommended to install AMD Software: Adrenalin Edition 26.3.1. Intermittent application crash may be observed on some models while running Blender on Radeon™ RX 7000 series and above graphics products. Users experiencing this issue are recommended to install AMD Software: Adrenalin Edition 26.3.1. You can download the AMD Radeon driver 26.6.4 from the official website here. Full release notes are available on the same page.
    • Amazon may use OpenAI and Nova models after Anthropic reportedly raises costs by Karthik Mudaliar Amazon is reportedly considering to use OpenAI models and even its own Nova family of AI models after Anthropic raised the cost of using Claude inside Amazon services. According to a report from The Information, Amazon is weighing its options to reduce costs under a new arrangement with Anthropic. But back in April, Amazon said it would invest $5 billion more in Anthropic, with the possibility of adding up to another $20 billion if certain commercial milestones are met. That investment actually came on top of another $8 billion Amazon had already put into the Claude maker. Anthropic, meanwhile, committed to spend more than $100 billion over 10 years on AWS technologies, including Amazon’s Trainium chips. Amazon isn't just a customer of Anthropic but also one of the most important backers and cloud partners. This is why it makes it interesting that Amazon is considering other alternatives to handle its internal workloads. Although Amazon has been building its own options for a while now. Its Nova family of AI models was announced in late 2024 for Amazon Bedrock, with models aimed at text, image, and video tasks. Amazon pitched the model around cost and latency at that time. With that said, OpenAI has also become a more realistic option recently for AWS customers as well as for Amazon itself. Earlier this year, OpenAI brought its latest models and Codex coding agent to Amazon Bedrock, after changes to its previously more restrictive Microsoft cloud arrangement. This allowed AWS to serve even those customers who wanted other alternatives from Claude, without having to move workloads out of Amazon's cloud. Evaluating alternatives could also be due to commercial pressure and not necessarily a sign of a damaged partnership between Amazon and Anthropic. Whether or not Amazon is actually considering switching entirely to OpenAI's models or its own Nova models remains unknown at this moment.
    • Samsung introduces new AI classroom tools and interactive displays at ISTELive 2026 by Fiza Ali Samsung has announced several new education-focused software features and interactive displays for schools during ISTELive 2026, taking place in Orlando, Florida, from 28 June to 1 July. The focus of these updates is on making shared classroom displays easier to use for teachers while giving IT administrators more control over managing devices. One of the key additions is the Samsung Account Management Solution (AMS). In many schools, multiple teachers share the same interactive display throughout the day, which means signing in and setting everything up can become repetitive. With AMS, teachers can log in by scanning a QR code or tapping an NFC-enabled ID card. Once signed in, their personalised workspace, including wallpapers, bookmarks, app shortcuts, and files, can be instantly accessed through Home Personalisation. Samsung has also included a screen lock feature, allowing teachers to lock the display if they need to step away briefly. Furthermore, the company is also updating its Education Portal with new tools designed for school IT administrators. The portal will allow IT administrators to register teachers, enrol devices, and manage user access from a central dashboard. Administrators can also link NFC cards to teacher accounts, making sign-ins quicker across shared displays. Another addition is a Tags feature that lets schools organise displays by building or classroom. Those tags can also be used to send emergency notifications to selected Samsung Interactive Displays through compatible platforms such as InformaCast and Raptor. Moreover, the tech giant's AI Assistant is gaining several new features aimed at supporting everyday classroom tasks such as lesson planning and classroom engagement. One of the features is Circle to Search, which lets teachers circle text or images on the display to quickly find related information, videos, or web results without interrupting the lesson. The content can then be brought into Samsung Whiteboard. Another feature, Live Transcript, converts spoken lessons into real-time captions, which could be useful for students with hearing impairments or those in multilingual classrooms. The AI Assistant also introduces AI Summary and AI Quiz. The summary tool creates summaries of recorded lessons, while AI Quiz generates questions based on lesson content so teachers can quickly check how well students are following along. Teachers signed in through Samsung AMS can also return to their previous AI-generated lesson materials without logging in again. Alongside the software updates, Samsung has expanded its Android-based Interactive Display range with three new models: the WAF-S, WAFX-PS, and WAHX-M. The WAF-S and WAFX-PS ship with Android 16, bringing updates to security, accessibility, and overall usability while maintaining compatibility with Google's education services including Google Classroom and Google Drive through EDLA certification. Meanwhile, the new WAHX-M is the biggest addition to the lineup, introducing a 98-inch display for larger spaces such as lecture halls and conference rooms. It will also be available in 65-inch, 75-inch and 86-inch sizes. Samsung says the WAHX-M further includes on-device AI features such as voice commands, text-to-speech, and an AI calculator, alongside support for Samsung AMS and AI Assistant. Samsung AI Assistant has been available since April, while Samsung AMS and the updated Education Portal will begin rolling out in July.
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      536
    2. 2
      +Edouard
      269
    3. 3
      PsYcHoKiLLa
      150
    4. 4
      Steven P.
      97
    5. 5
      macoman
      61
  • Tell a friend

    Love Neowin? Tell a friend!