New Mac OS X backdoor Trojan, Sabpab, discovered


Recommended Posts

Hot off the heels of the Flashback malware, Sophos has announced the discovery of a new Mac OSX Trojan, Sabpab, which uses the same Java vulnerability Flashback used, and just like Flashback, doesn't need or require any user interaction to be installed.

The newly discovered Sabpab malware is in many ways a basic backdoor Trojan horse. It connects to a control server using HTTP, receiving commands from remote hackers as to what it should do. The criminals behind the attack can grab screenshots from infected Macs, upload and download files, and execute commands remotely.

The Trojan creates the files

/Users/<user>/Library/Preferences/com.apple.PubSabAgent.pfile

/Users/<user>/Library/LaunchAgents/com.apple.PubSabAGent.plist

Encrypted logs are sent back to the control server, so the hackers can monitor activity.

The potential for abuse of compromised Macs should be obvious, given the Trojan's functionality.

Source: SOPHOS

Apple needs to hand over the maintenance of Java over to its main company. Days of Macs being virus proof are over.

seriously, I can't understand why Apple wants to be in control of when java updates get pushed (aka almost never)

The coffee is opening holes in the apple :p

Anyway since they already fixed that Java issue, this trojan won't affect patched systems, right?

Maybe Apple can buy an anti-virus company and create Apple Security Essentials :p

Apples approach to security is light years ahead of Microsoft, Mac OS can require apps to be signed, each app is broken up into separate parts with each part only able to do one thing, like with QuickTime, the Video Decoder, is ONLY allowed read from teh disk and decry pt the content of a video stream. I could go on, but Ars had a great line up in their OS X Lion review.

Apples approach to security is light years ahead of Microsoft

Don't think I've laughed so hard in a long time, my chest hurts! When it comes to security, the only thing Apple is light years ahead of Microsoft on is denial.

  • Like 3

Part of me wishes Steve was still alive to declare war on Java just like he did Flash. :/

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.

Agreed. I hate the fact I get a prompt to install Java when I'm launching Adobe Photoshop the first time. :pinch:

Java needs to go away. I'm sorry to all the Minecraft players out there, but Java needs to die a quick death.

I'm a Minecraft player and even I think Java needs to die
  • Like 3

Best advice I can give is to just keep Java disabled in your browser of choice. It's already disabled by default in Safari on Lion (even if you have Java installed like Adobe has forced me to do).

Apples approach to security is light years ahead of Microsoft, Mac OS can require apps to be signed, each app is broken up into separate parts with each part only able to do one thing, like with QuickTime, the Video Decoder, is ONLY allowed read from teh disk and decry pt the content of a video stream. I could go on, but Ars had a great line up in their OS X Lion review.

I assume you mean the other way around. Microsoft has always had a huge head start on the security front and they've had the infrastructure and teams established within the company to deal with threats for considerably longer. Your example is great, but IE has had protected mode since Vista AND that can be used by any other apps to switch threads or processes to low IL.

Haven't even touched on ASLR, DEP, and other technologies (I have a larger list in a notebook at home).

Windows 8 will bring even more improvements for intra process security and doing the same application signing requirements for Metro apps.

Apple just released two updates to address this issue and a removal tool for Macs without Java installed.

That's the point I don't understand. Flashback and this new supposed one are Java exploits....so if my Mac doesn't have Java installed how can my machine get infected and thus need this removal tool? Isn't the best defense on this just not to have Java installed along with a good a/v scanner?

That's the point I don't understand. Flashback and this new supposed one are Java exploits....so if my Mac doesn't have Java installed how can my machine get infected and thus need this removal tool? Isn't the best defense on this just not to have Java installed along with a good a/v scanner?

Yes.

I'm glad I upgraded all my Macs to Windows 7 in time.

Yupp.

Zero vulnerabilities. :rolleyes: :laugh:

Glassed Silver:mac

  • Like 3

And did you ditch OS X completely ? If so, I don?t understand your point. If anything, your Macs are a couple of times more vulnerable than ever before. It?s your call, man.

I still have OS X but I have no real reason to use it anymore. The question then becomes, why did I get a Mac in the first place? I didn't know Windows 7 was so good. If I did at the time, I would have saved myself some money and built my own PC.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Didn’t Dbrand once complain that Casetify was ripping off their designs a well? seems pretty bad of them to try and get around Valve’s copyright this way with that in mind.
    • Dbrand thought they could get away with this Steam Machine case, Valve disagreed by David Uzondu Image via Dbrand Dbrand has cancelled its highly anticipated Companion Cube enclosure for the Valve Steam Machine, which it teased back in November of last year with a concept render and sign-up page, because it did not ask Valve for permission first before manufacturing the case. According to Dbrand, it took the "backwards approach" of building the product first before asking for permission from the copyright holder. Seven months of work went into the project, requiring over a thousand engineering hours from the design team. Workers developed forty-four sets of injection molding tools, making a unique mold for each sub-component of the crate. When the Companion Cube went live on Monday last week, it, according to Dbrand, quickly became the second-fastest-selling product in the company's fifteen-year history, racking up orders for hundreds of thousands of units. Customers eagerly bought the $129.95 deluxe edition or the bare-bones $99.95 version, which the manufacturer cheekily branded as the "Poverty Cube". It was around this time that the legal eagles at Valve descended on the accessory maker with a formal demand. The developer pointed out that the iconic block design remains protected intellectual property from the game Portal, so unlicensed sales had to stop. Dbrand said that all its pleas to salvage the project with the Valve team, including proposals to run a properly licensed release under official terms "with their blessing", fell on deaf ears, so it had no choice but to obey and remove every trace of the product from the internet. If you bought the enclosure, the company said that banks will process your refund by the end of this week, but if it still hasn't arrived in your account by then, you should not hesitate to contact support. The Steam Machine itself is a high-performance console that Valve designed directly to bring PC gaming into the living room. It was announced on 12th November 2025 (the same day Dbrand announced the Cube) and runs on the Linux-based SteamOS, the same OS that powers the Steam Deck. As for the price, due to the shortage of memory and storage chips, the hardware cost landed much higher than people were expecting, starting at $1,049 for the 512 model (without a controller) or $1,128 with the new gamepad. The premium 2 TB model pushes those prices even higher, selling at $1,349 for the standalone console and hitting $1,428 if you want the bundle.
    • It's listed #399.99 on Amazon, per your link. It's not $299.99.
  • Recent Achievements

    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      534
    2. 2
      +Edouard
      263
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      97
    5. 5
      macoman
      58
  • Tell a friend

    Love Neowin? Tell a friend!