New Mac Trojan installs silently, no password required


Recommended Posts

A new Mac OS X Trojan has been discovered that drops different components depending on whether or not it is executed on a user account with Admin permissions. The threat installs itself silently (no user interaction required) and also does not need your user password to infect your Apple Mac. The backdoor component calls home to the IP address 176.58.100.37 every five minutes, awaiting instructions.

Intego, which had to update its anti-malware signatures upon discovering the threat, refers to it as "OSX/Crisis." The good news is that the security firm has yet to find OSX/Crisis in the wild; the company only stumbled upon it over at VirusTotal, a service for analyzing suspicious files and URLs.

This Trojan is like most: when run, it installs silently to create a backdoor. What makes this threat particularly worrying is that depending on whether or not it runs on a user account with Admin permissions, it will install different components, which use low-level system calls to hide their activities. Either way, it will always create a number of files and folders to complete its tasks.

If the dropper runs on a system with Admin permissions, it will drop a rootkit to hide itself. The malware creates 17 files when it's run with Admin permissions, 14 files when it's run without. Many of these are randomly named, but there are some that are consistent.

With or without Admin permissions, this folder is created: /Library/ScriptingAdditions/appleHID/

Only with Admin permissions, this folder is created: /System/Library/Frameworks/Foundation.framework/XPCServices/

Here's where it gets interesting. "The file is created in a way that is intended to make reverse engineering tools more difficult to use when analyzing the file," an Intego spokesperson said in a statement. "This sort of anti-analysis technique is common in Windows malware, but is relatively uncommon for OS X malware."

Curiously, this particular malware only affects OS X 10.6 Snow Leopard and OS X 10.7 Lion. The latest threat further underlines the importance of protecting Macs against malware with an updated antivirus program as well as the latest security updates. That means you should start by getting OS X 10.8 Mountain Lion when it comes out Wednesday (although it's currently unclear whether OSX/Crisis or Mac security software will work on it).

Source:

http://www.zdnet.com/new-mac-trojan-installs-silently-no-password-required-7000001519/

Unless of course you're running GateKeeper settings to only allow app store and identified developer installs; keeps it off your system ;)

Where does it say that? Gatekeeper isn't going to prevent exploits in signed software. I don't see how it's being installed detailed.

I just Have to LoL, all the people "But Mac's Dont Get Viri"

Its an OS built by Humans, it will get hit, just a matter if time

edit - Stupid iPad and these Text box's

On Topic - I do feel that Very Few people run OSX as a Non-Admin User account, and surprised the infection doesn't need credentials at all

I just Have to LoL, all the people "But Mac's Dont Get Viri"

Its an OS built by Humans, it will get hit, just a matter if time

edit - Stupid iPad and these Text box's

On Topic - I do feel that Very Few people run OSX as a Non-Admin User account, and surprised the infection doesn't need credentials at all

What people? i don't think anyone says that these days, maybe before, but back then it was pretty much the case.. it didn't have viruses, and even now it's hardly anything to worry about. Anyone with half a brain can prevent or easily spot changes in the system. I didn't run a virus scanner for all the years of running Windows and never got a virus, malware, or trojans so i wont be needing it for the Mac either, for those that do worry have virus software available to them.

I don't know why windows use get so giddy when this sort of news appears.

Just FYI if gatekeeper has a 'only run signed packages' option then it's also got an equilivent in windows for XP and newer, via the GPO you can set it to only run signed executables using the certificates you provide, though I've never actually seen anyone/any company use it.

And yes exploits can/will be discovered but the more protection you have, the more % of people that'd give up before getting it cracked.

I don't know why windows use get so giddy when this sort of news appears.

I don't either but they've been wetting their pants for 10 years now since I switched....it's coming, it's coming....yeah...here I am unbitten.

  • Like 2

What people? i don't think anyone says that these days, maybe before, but back then it was pretty much the case.. it didn't have viruses, and even now it's hardly anything to worry about. Anyone with half a brain can prevent or easily spot changes in the system. I didn't run a virus scanner for all the years of running Windows and never got a virus, malware, or trojans so i wont be needing it for the Mac either, for those that do worry have virus software available to them.

I don't know why windows use get so giddy when this sort of news appears.

because the reality distortion field is getting weaker...

Where does it say that? Gatekeeper isn't going to prevent exploits in signed software. I don't see how it's being installed detailed.

IF it is signed, Apple can revoke the certificate and ALL macs running gatekeeper will stop executing the file (plus in ML they beefed up their built in AV so they could delete it from your system very quickly too)

What people? i don't think anyone says that these days, maybe before, but back then it was pretty much the case...

I get alot of people in the repair shop talking about switching to a mac after their computer got hit with an infection, thinking they wont have problems..

I don't either but they've been wetting their pants for 10 years now since I switched....it's coming, it's coming....yeah...here I am unbitten.

I always said, if market share for Macs gets to big, then they will start getting attacked more. Right now, Mac users are safe but I still advise work and others that I know who have Macs to have proper protection.

This will probably be patched soon so no big deal.

I don't know why windows use get so giddy when this sort of news appears.

I'm not giddy...tho I have no sympathy for people who think they are untouchable and do not have the proper protection in place. Especially when its people who I warn and recommend products to to keep them safe.

Im so glad that macs have increased in popularity so much that they now have to worry about viruses, spyware and trojans just like the rest of us :-). Now the days of the snobby mac user attitue of saying how they dont need antivirus those days are now over :-). Plus this will create many new jobs as tech companies can now make and sell antivirus/spyware products or mac users now. As the popularity of apple becomes more and more its OS will have so many viruses and junked up just like Windows lol.

This new trojan installs silently. I laugh when all the mac users I see in person say how they cant get viruses or how secure the OS is. This proves how blinded they are.

At least Linux is still fairly free from all of this :-)

It personally makes me laugh because Mac advocates like to constantly remind us of how much better a mac is, when in reality they're just as easy if not more so than Windows computers to exploit.

What people? i don't think anyone says that these days, maybe before, but back then it was pretty much the case.. it didn't have viruses, and even now it's hardly anything to worry about. Anyone with half a brain can prevent or easily spot changes in the system. I didn't run a virus scanner for all the years of running Windows and never got a virus, malware, or trojans so i wont be needing it for the Mac either, for those that do worry have virus software available to them.

I don't know why windows use get so giddy when this sort of news appears.

You are correct when it comes to the users here... but out in the real world the attitude "macs don't get viruses" is still very prevalent.

I have ML which to my understanding GateKeeper is an anti-virus of sorts... That said I think that the FUD is starting to get to me because I feel the need to get an anti-virus program. idk... I think the anti-virus software makers the ones that get the giddiest about this news because they want nothing more than to tap into the Mac market.

It personally makes me laugh because Mac advocates like to constantly remind us of how much better a mac is, when in reality they're just as easy if not more so than Windows computers to exploit.

What really makes me laugh is PC advocates like to pretend the lack of viruses is the soul reason. That while in reality many Mac users have vastly different reasons for having made the switch.

Funny, I've been unbitten on windows for almost 20...

Let me send a BIG...HUGE happy birthday shout out to my fellow neowinian, HawkMan! Happy birthday, HAWK-MAN....(sings the HB song) (Y)

IF it is signed, Apple can revoke the certificate and ALL macs running gatekeeper will stop executing the file (plus in ML they beefed up their built in AV so they could delete it from your system very quickly too)

While Gatekeeper is indeed good feature to have, it doesn't make you free from exploits, attacks and vulnerabilities. It's not its purpose, I would say. If it was, it's a **** poor job. Getekeeper's whole point is to prevent you (as in you and your mouse pointer) running bad things, and to whitelist the good stuff from the bad. It's literally just signing, you (and the developer) knowing that the file isn't altered.

Let's start from the fact that Gatekeeper and code signing as a whole (i.e. from system) only applies to executable files. It doesn't prevent you from running malicious code on the system, just opening executables (as in application packages and installers). Also note that Gatekeeper only quarantines executables downloaded using applications that support and flag the files as downloaded. It doesn't care about drive-bys or files coming from applications that do not specifically mark files as downloaded. For instance file coming via file sharing protocol, syncing service or drive-by are handled as other seemingly existing, old files.

Also its up to the caller of the executable to decide whether they validate or require signatures. For instance a platform installed on the system can run the platform specific plugins, scripts etc. without verifying any signatures.

What really makes me laugh is PC advocates like to pretend the lack of viruses is the soul reason. That while in reality many Mac users have vastly different reasons for having made the switch.

I don't care what makes people switch. Apple fans seem to make out that OSX is immune to being hacked or virused, when in fact evidence suggests that if anything it's easier than Windows to exploit (Vista onwards anyway, with XP it's about a draw)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Segra 1.6.2 by Razvan Serea Segra is a free, open-source OBS-powered game recorder offering fast gameplay capture, instant clips, AI highlights, deep game integration, and seamless uploads—perfect for gamers, streamers, and content creators. Lightweight, fast, zero bloat. Segra key features: Automatic Game Recording: Begin capturing gameplay the moment your game launches, with zero manual setup. Instant Clipping: Save important moments instantly using a customizable hotkey—perfect for highlights, montages, or quick shares. Segra AI Highlights: Let Segra automatically detect kills, assists, deaths, and key events to generate polished highlight reels without manual editing. Gameplay Uploads: Upload recordings and clips directly to Segra.tv for fast sharing and cloud access. Deep Game Integration: Enjoy advanced game-data tracking across hundreds of supported titles, enabling smart highlight generation and stat-informed clipping. High-Performance Capture: Record up to 4K at 144 FPS using OBS-powered technology with minimal performance impact, supporting NVENC, AMD VCE, and custom quality controls. Segra Editor: Edit recordings easily with timeline controls, segment management, and event-based navigation to build the perfect clip. Customization Options: Adjust hotkeys, output formats, storage paths, codecs, capture quality, and performance settings for a tailored recording experience. Segra 1.6.2 changelog: UI: Improved the transition from the loading skeleton to the real content card. Security: Added Segra.dll code signing and automatic VirusTotal upload. Settings: Fixed the settings header to highlight Account when scrolled to the top. Recording: Updated OBSKit.NET to 1.4.1. Download: Segra 1.6.2 | 74.5 MB (Open Source) View: Segra Homepage | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Hey Google, these are the Gemini features I want in 2026 by Aditya Tiwari Google Gemini has been around for over three years. The AI chatbot started its journey back in 2023 (as Bard) when ChatGPT was already a talk of the town. However, it quickly attracted criticism after misrepresenting facts about the James Webb Space Telescope. The search giant spent a year fine-tuning Bard before rebranding the chatbot and its underlying generative AI model to Gemini, drawing inspiration from NASA's first human spaceflight program. Note that Bard was initially powered by LaMDA and PaLM 2; Google has since added several new features and integrations to Gemini. That said, there is scope for improvement and a gap for new features. I have been using Gemini for a while now and have realized that the chatbot lacks several features, making it harder for me to research across topics. These are mostly function-over-form updates that can improve the overall experience. Delete individual messages from a conversation Image via DepositPhotos.com One good thing about Gemini is that it can maintain context throughout the conversation. But things might get chaotic when you want to ask a related question, but don't want it to be part of your conversation in the long run. You can't ask that related question in a fresh chat because Gemini will lose the active conversation context of what you're trying to research. If Google allowed you to delete individual question/answer pairs, you could simply ask about a sub-topic and remove it from the conversation to create a smooth flow of important stuff. Offline mode Image via DepositPhotos.com A big pain of using Gemini daily is that everything loads from the cloud. It takes time for your chats to appear, and you can't view your conversation history while offline. To get a better idea, you can open the Gemini app and see how it looks without an internet connection. While Gemini models run in the cloud, it wouldn't hurt if Google could store chats (at least the text part) on the device so we can refer to them when offline. Google can also offer a lightweight version of its AI model to help with basic drafting, summarization, and other tasks. It has the Gemini Nano model, which can perform on-device processing on Google Pixel, Samsung, and some other Android brands, but it's a system feature and not related to the cloud-based Gemini app. Make temporary chats permanent I can't thank Google enough for taking the time and effort to add incognito mode or temporary chat mode to the Gemini app. It lets you have conversations without worrying that the topics will end up in your chat history or used for model training (at least on paper). Google claims that it doesn't use your temporary chats to "personalize your Gemini experience or train Google’s AI models." However, the data is stored "up to 72 hours to respond to you and to process any feedback you choose to provide." That said, I often start researching something in a temporary chat, only to realize the chatbot's answer is good enough to refer to later. Sadly, Gemini doesn't have an option to make such temporary chats permanent. In other words, I won't be able to follow up on it if I close the temporary chat. I'm left with alternatives like copying the answers into notes or another app. My digital life will get a lot better if Gemini gets a button to make temporary chats permanent. Collapse answers for a cleaner view You're heavily invested in your research game and suddenly feel the need to go up in the chat to recall something. This is when the conversation thread starts to feel like an overwhelming, unending wall of questions and answers. What if Google added a way to collapse Q&A pairs in the Gemini chat thread? It would look quite clean and easy to navigate. You'll quickly get an overview of everything you have discussed with the chatbot. Add buttons to jump between messages Suggested mockup of the feature. This reminds me of a small but useful Gemini feature that Google could add to its chatbot: the ability to hop between prompts in a conversation. Just add simple up- and down-arrow buttons, similar to YouTube Shorts, so people can quickly scroll through the messages. A table of contents or Chat Overview It's hard to get a bird's-eye view of everything you have discussed with the chatbot during a lengthy conversation. This is where a table of contents, or Chat Overview, displayed at the top of the screen, possibly in a drop-down button, might come in handy. You'll be able to get an overview of the chat and jump between messages, serving as an alternative to the up/down arrow buttons. Temporary mode for Gemini Live Image: Google You can use Gemini Live to have real-time conversations with the chatbot, which feels like you're talking to someone in the same room. However, a downside is that Gemini Live doesn't work in Temporary Chat mode, so all your conversations end up in the chat history. Google should consider expanding the temporary chat mode to include Gemini Live. Default to a specific chat One thing that feels somewhat annoying to me is that Gemini always opens in a new chat, whether on web or mobile. Sometimes, you want to return to your last chat. Google can take cues from web browsers, which let you choose whether you want to go to a new tab or a specific web page(s). Gemini can also have options to default to a specific chat when reopened. That said, generative AI chatbots have endless possibilities given the vagueness of their work. You can mold them the way you want by attaching different connectors, adding custom instructions, and including source files. It remains to be seen what Google has in store for future updates and whether anything from this wishlist gets the green light. The search giant released a stream of new Gemini updates in recent months, including Gemini 3.5 Flash and Gemini Omni Spark, adding that it now has 13 products with more than a billion users each. What do you want to see in the Gemini app? Tell us in the comments.
    • Thank you for the post. Just a FYI that links to an outside site or promoting specific software is considered spamming here. Asking general questions is fine.
    • I have been thinking about AI detector tools as a software workflow rather than a single "AI score" widget. When someone pastes text or uploads a document, the UI can return a report with a probability-style score, sentence highlights, reliability notes, and limitations. The useful part is that it can point a reviewer toward passages worth reading again. The risky part is that a polished score can look more certain than it really is. For people who build or review web apps, what should happen before the user copies or exports that kind of report? The minimum I would expect is: A clear input boundary for pasted text versus document files. Limits shown near the workflow, including minimum text length and maximum file size. A report label that says the result is a signal, not proof of who wrote the text. Sentence highlights and evidence notes alongside the global score. Reliability notes when the sample is too short or lacks enough sentence variety. False-positive and false-negative caveats that remain visible in copied/exported summaries. I am trying to avoid the pattern where a clean report card becomes the whole product story. For AI detection, "review this evidence in context" seems more honest than "trust this score." Would you keep the warning text visible on every report, or make it collapsible so the main result stays easier to scan? Disclosure: I work on a small AI detector/reporting workflow, but I am intentionally not linking it here. I am asking about software and report design, not promoting a site.
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      181
    3. 3
      PsYcHoKiLLa
      86
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      76
  • Tell a friend

    Love Neowin? Tell a friend!