New Mac Trojan installs silently, no password required


Recommended Posts

A new Mac OS X Trojan has been discovered that drops different components depending on whether or not it is executed on a user account with Admin permissions. The threat installs itself silently (no user interaction required) and also does not need your user password to infect your Apple Mac. The backdoor component calls home to the IP address 176.58.100.37 every five minutes, awaiting instructions.

Intego, which had to update its anti-malware signatures upon discovering the threat, refers to it as "OSX/Crisis." The good news is that the security firm has yet to find OSX/Crisis in the wild; the company only stumbled upon it over at VirusTotal, a service for analyzing suspicious files and URLs.

This Trojan is like most: when run, it installs silently to create a backdoor. What makes this threat particularly worrying is that depending on whether or not it runs on a user account with Admin permissions, it will install different components, which use low-level system calls to hide their activities. Either way, it will always create a number of files and folders to complete its tasks.

If the dropper runs on a system with Admin permissions, it will drop a rootkit to hide itself. The malware creates 17 files when it's run with Admin permissions, 14 files when it's run without. Many of these are randomly named, but there are some that are consistent.

With or without Admin permissions, this folder is created: /Library/ScriptingAdditions/appleHID/

Only with Admin permissions, this folder is created: /System/Library/Frameworks/Foundation.framework/XPCServices/

Here's where it gets interesting. "The file is created in a way that is intended to make reverse engineering tools more difficult to use when analyzing the file," an Intego spokesperson said in a statement. "This sort of anti-analysis technique is common in Windows malware, but is relatively uncommon for OS X malware."

Curiously, this particular malware only affects OS X 10.6 Snow Leopard and OS X 10.7 Lion. The latest threat further underlines the importance of protecting Macs against malware with an updated antivirus program as well as the latest security updates. That means you should start by getting OS X 10.8 Mountain Lion when it comes out Wednesday (although it's currently unclear whether OSX/Crisis or Mac security software will work on it).

Source:

http://www.zdnet.com/new-mac-trojan-installs-silently-no-password-required-7000001519/

Unless of course you're running GateKeeper settings to only allow app store and identified developer installs; keeps it off your system ;)

Where does it say that? Gatekeeper isn't going to prevent exploits in signed software. I don't see how it's being installed detailed.

I just Have to LoL, all the people "But Mac's Dont Get Viri"

Its an OS built by Humans, it will get hit, just a matter if time

edit - Stupid iPad and these Text box's

On Topic - I do feel that Very Few people run OSX as a Non-Admin User account, and surprised the infection doesn't need credentials at all

I just Have to LoL, all the people "But Mac's Dont Get Viri"

Its an OS built by Humans, it will get hit, just a matter if time

edit - Stupid iPad and these Text box's

On Topic - I do feel that Very Few people run OSX as a Non-Admin User account, and surprised the infection doesn't need credentials at all

What people? i don't think anyone says that these days, maybe before, but back then it was pretty much the case.. it didn't have viruses, and even now it's hardly anything to worry about. Anyone with half a brain can prevent or easily spot changes in the system. I didn't run a virus scanner for all the years of running Windows and never got a virus, malware, or trojans so i wont be needing it for the Mac either, for those that do worry have virus software available to them.

I don't know why windows use get so giddy when this sort of news appears.

Just FYI if gatekeeper has a 'only run signed packages' option then it's also got an equilivent in windows for XP and newer, via the GPO you can set it to only run signed executables using the certificates you provide, though I've never actually seen anyone/any company use it.

And yes exploits can/will be discovered but the more protection you have, the more % of people that'd give up before getting it cracked.

I don't know why windows use get so giddy when this sort of news appears.

I don't either but they've been wetting their pants for 10 years now since I switched....it's coming, it's coming....yeah...here I am unbitten.

  • Like 2

What people? i don't think anyone says that these days, maybe before, but back then it was pretty much the case.. it didn't have viruses, and even now it's hardly anything to worry about. Anyone with half a brain can prevent or easily spot changes in the system. I didn't run a virus scanner for all the years of running Windows and never got a virus, malware, or trojans so i wont be needing it for the Mac either, for those that do worry have virus software available to them.

I don't know why windows use get so giddy when this sort of news appears.

because the reality distortion field is getting weaker...

Where does it say that? Gatekeeper isn't going to prevent exploits in signed software. I don't see how it's being installed detailed.

IF it is signed, Apple can revoke the certificate and ALL macs running gatekeeper will stop executing the file (plus in ML they beefed up their built in AV so they could delete it from your system very quickly too)

What people? i don't think anyone says that these days, maybe before, but back then it was pretty much the case...

I get alot of people in the repair shop talking about switching to a mac after their computer got hit with an infection, thinking they wont have problems..

I don't either but they've been wetting their pants for 10 years now since I switched....it's coming, it's coming....yeah...here I am unbitten.

I always said, if market share for Macs gets to big, then they will start getting attacked more. Right now, Mac users are safe but I still advise work and others that I know who have Macs to have proper protection.

This will probably be patched soon so no big deal.

I don't know why windows use get so giddy when this sort of news appears.

I'm not giddy...tho I have no sympathy for people who think they are untouchable and do not have the proper protection in place. Especially when its people who I warn and recommend products to to keep them safe.

Im so glad that macs have increased in popularity so much that they now have to worry about viruses, spyware and trojans just like the rest of us :-). Now the days of the snobby mac user attitue of saying how they dont need antivirus those days are now over :-). Plus this will create many new jobs as tech companies can now make and sell antivirus/spyware products or mac users now. As the popularity of apple becomes more and more its OS will have so many viruses and junked up just like Windows lol.

This new trojan installs silently. I laugh when all the mac users I see in person say how they cant get viruses or how secure the OS is. This proves how blinded they are.

At least Linux is still fairly free from all of this :-)

It personally makes me laugh because Mac advocates like to constantly remind us of how much better a mac is, when in reality they're just as easy if not more so than Windows computers to exploit.

What people? i don't think anyone says that these days, maybe before, but back then it was pretty much the case.. it didn't have viruses, and even now it's hardly anything to worry about. Anyone with half a brain can prevent or easily spot changes in the system. I didn't run a virus scanner for all the years of running Windows and never got a virus, malware, or trojans so i wont be needing it for the Mac either, for those that do worry have virus software available to them.

I don't know why windows use get so giddy when this sort of news appears.

You are correct when it comes to the users here... but out in the real world the attitude "macs don't get viruses" is still very prevalent.

I have ML which to my understanding GateKeeper is an anti-virus of sorts... That said I think that the FUD is starting to get to me because I feel the need to get an anti-virus program. idk... I think the anti-virus software makers the ones that get the giddiest about this news because they want nothing more than to tap into the Mac market.

It personally makes me laugh because Mac advocates like to constantly remind us of how much better a mac is, when in reality they're just as easy if not more so than Windows computers to exploit.

What really makes me laugh is PC advocates like to pretend the lack of viruses is the soul reason. That while in reality many Mac users have vastly different reasons for having made the switch.

Funny, I've been unbitten on windows for almost 20...

Let me send a BIG...HUGE happy birthday shout out to my fellow neowinian, HawkMan! Happy birthday, HAWK-MAN....(sings the HB song) (Y)

IF it is signed, Apple can revoke the certificate and ALL macs running gatekeeper will stop executing the file (plus in ML they beefed up their built in AV so they could delete it from your system very quickly too)

While Gatekeeper is indeed good feature to have, it doesn't make you free from exploits, attacks and vulnerabilities. It's not its purpose, I would say. If it was, it's a **** poor job. Getekeeper's whole point is to prevent you (as in you and your mouse pointer) running bad things, and to whitelist the good stuff from the bad. It's literally just signing, you (and the developer) knowing that the file isn't altered.

Let's start from the fact that Gatekeeper and code signing as a whole (i.e. from system) only applies to executable files. It doesn't prevent you from running malicious code on the system, just opening executables (as in application packages and installers). Also note that Gatekeeper only quarantines executables downloaded using applications that support and flag the files as downloaded. It doesn't care about drive-bys or files coming from applications that do not specifically mark files as downloaded. For instance file coming via file sharing protocol, syncing service or drive-by are handled as other seemingly existing, old files.

Also its up to the caller of the executable to decide whether they validate or require signatures. For instance a platform installed on the system can run the platform specific plugins, scripts etc. without verifying any signatures.

What really makes me laugh is PC advocates like to pretend the lack of viruses is the soul reason. That while in reality many Mac users have vastly different reasons for having made the switch.

I don't care what makes people switch. Apple fans seem to make out that OSX is immune to being hacked or virused, when in fact evidence suggests that if anything it's easier than Windows to exploit (Vista onwards anyway, with XP it's about a draw)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • See if this article I wrote the other day works for you.
    • We could disable web results as far back as Windows 10 everywhere.
    • No, it wasn't "huge", it is lame, and it was lame back then.
    • 7 Days: SPECS for $2,195, Firefox Nova 2026, first AI arts museum, and iPhone price hike by Aditya Tiwari 7 Days is a weekly roundup of picks of what's been happening in the world of technology - written with a dash of humor, a hint of exasperation, and an endless supply of (black) coffee. This week's highlights include Linux 7.1 stable release, Samsung pulling the plug on its VPN, and Microsoft Edge bringing the sign-in with Google experience. Let's get started. You can check out the recent issues of the 7 Days weekly roundup. Mozilla highlights Firefox Nova Mozilla showed off a new Firefox roadmap highlighting the browser's upcoming features and the Nova 2026 redesign. Interested users and enthusiasts can check out what's cooking and share feedback on the upcoming additions. Besides this, Firefox 152 brought Tab Groups to Android as one of its biggest additions, along with a redesigned Settings experience. World's first AI arts museum Image: Google Google opened the world's first AI arts museum in Los Angeles on June 20, which it named Dataland. The museum, spanning 25,000 square feet, was built in collaboration with media artist Refik Anadol, who has worked with Google since 2016. It will have real-time visuals and react dynamically to visitors. Salesforce shopping bag In the latest acquisition news, Salesforce is buying the customer support software company Fin (formerly Intercom) for $3.6 billion to strengthen its AI customer service ambitions and Agentforce platform. The transaction is expected to close in the fourth quarter of its fiscal year 2027. UK follows Australia Prime Minister Keir Starmer announced that the country will ban social media for kids under 16, which is happening after a six-week trial involving 300 teenagers, stating that social media is making them unhappy and easier for bullies to harass and abuse them. Starmer continued that social media is addictive and uses an infinite scroll designed to lock users in for hours. The UK government plans to take action on gaming services and livestreaming platforms. Meanwhile, its age verification rules have also become a hot topic and a point of criticism. Our Features Our coffee-powered team publishes a platter of editorials, opinion posts, and guides. Check them out: Microsoft hides these secret Windows 11 performance boost settings available on every PC Microsoft Paint used to be my favorite Windows app as a kid, and it's still pretty good Why you need to take back control of your synced passwords and how to go about doing that The Microsoft Office feature that time forgot This week in software news Catch up on some of the latest software news updates that arrived throughout the week: Another Samsung shutdown: The South Korean giant is pulling the plug on the Samsung Max VPN app, which is used by more than 50 million users. The app has stopped working since June 15, and Samsung didn't provide a reason for the unexpected move. Photoshop power-up: The popular image editing app is getting a big 20% performance boost on x86-64 (AMD64) systems and a 13% bump-up on Arm devices. Here, the credit goes to a new performance boost added to Windows 11 following a combined effort between Microsoft and Adobe. Linux 7.1 arrives: Linus Torvalds released the stable Linux 7.1 kernel this week, which brings critical driver updates and a rewritten storage driver. You should look out for the new NTFS driver, Intel FRED for improved performance on Panther Lake and future CPUs. Ads in your games: Electronic Arts is launching a new advertising platform to serve in-game ads and enable brands to feature their products in titles like EA Sports FC, Madden, NHL, Skate, or The Sims. With EA Advertising, brands will be able to inject their products into games in real-time via dynamic placement, in places like stadium signage in sports games. Sign in with Google: Microsoft Edge browser is finally getting direct Google account sign-in support from the profile menu and the Edge sign-in screen, allowing users to sync browser data without an MSA. Rufus 4.15 beta: The latest Rufus update is out with important fixes for "silent" Windows 11 installation, patches for ARM-based PCs, and more. Rufus 4.15 beta is now available to download from its official GitHub repository. NVIDIA 610.62: GeForce hardware owners can get their hands on the new WHQL-certified 610.62 Game Ready driver, which carries a lot of bug fixes and support for the fast-paced 6v6 movement shooter Empulse. Zed 1.7.2: The latest update adds "/compact" AI chat summarization, new models, settings kill management, git graph commands, and UI improvements. This week in hardware news Image: Snap Inc. Catch up on some of the latest software news updates that arrived throughout the week: SPECS for $2,195: Snap Inc. launched its new AR-powered wearable computer. SPECS are now available for pre-order and will start shipping in the US, UK, and France later this year. No CMF phone in 2026: The global memory shortage has also knocked Nothing's door and it has decided to hold the launch of CMF Phone 2 Pro's successor this year. That said, Nothing still has planned several new products under the CMF brand. 12th Gen Surface Pro: It's been two years since the original pair of Copilot+ PCs arrived. Now, Microsoft upgraded the lineup with Snapdragon X2-based devices for the 12th-gen Surface Pro, which promises up to 53% faster graphics. New Surface Laptop: The refreshed Surface Laptop is also powered by the Snapdragon X2 Plus and X2 Elite, offering up to 58% faster graphics performance, 80 TOPS Neural Processing Units (NPUs), and up to 20 hours of battery life. HONOR Robot Phone: The Chinese smartphone maker demoed its mobile photography capabilities by capturing its first cinematic video using the Robot Phone concept, which features a 3-axis, 4DoF gimbal that extends from the phone's body for stable recording and real-time subject tracking. Snapdragon Reality Elite Platform: Qualcomm's new platform is a massive leap forward for mixed reality and spatial computing devices. It can power both all-in-one video-see-through headsets and lightweight, tethered optical-see-through glasses, offering better visuals, improved power efficiency, and deeper on-device AI integration compared to the previous generation. Galaxy XR: Samsung's extended-reality handset arrived in the UK months after its launch. It's available for pre-order now and will go on sale on July 8. The hardware remains unchanged, but Samsung has pushed several new updates in recent months. HONOR Watch 6: HONOR also launched its new smartwatch with an incredible 35-day battery life without breaking your bank. The device is made from recyclable aluminum alloy and weighs just 41 grams. Where are the foldables? If you're waiting for Samsung's fresh lineup of foldable devices, you can read Hamid's detailed post about the Galaxy Z Fold8, Flip8, and Z Fold Wide, a passport-style device expected to rival the foldable iPhone. This week in Google News Image: Google Catch up on some of the latest Google and Alphabet news updates that arrived throughout the week: Gemini co-lead departs: Noam Shazeer, who served as VP of engineering and technical co-lead for Gemini, is leaving the search giant for OpenAI. Shazeer is best known as one of the co-authors of the 2017 "Attention Is All You Need" paper, which introduced the Transformer architecture that now powers most LLMs. Waymo recall: The Alphabet-owned self-driving car maker recalled its fifth-generation Automated Driving Systems (ADS) after multiple cars drove through closed construction zones. The NHTSA website said Waymo is currently working on a fix, and freeway driving is being restricted. This week in Apple News Image: Apple Catch up on some of the latest Apple news updates that arrived throughout the week: Tim Cook confirms price hike: The departing Apple CEO confirmed the looming price hikes for Apple's future products without naming any, adding that “Unfortunately, price increases are unavoidable.” Despite having cash and silicon expertise, Apple has no plans to build its own memory and storage factories. An educated estimate suggests customers could end up paying around $1,299-1,399 for the base iPhone 18 Pro. iPhone Air isn't dead: If you were thinking the iPhone Air has lived its life, a new report claims otherwise. The next iPhone Air (codenamed V62) is expected to arrive in the spring of 2027, featuring an additional rear camera for ultrawide photography and improved battery life to address its biggest drawbacks. This week in Meta news Catch up on some of the latest Meta, WhatsApp, and Instagram updates that arrived throughout the week: A long-requested feature: Instagram has finally enabled users to write individual captions for each image or video in a carousel. Rolling out to all users, you can select "Multiple Captions" option from the dropdown while creating a carousel in the app. Threads reaches new milestone: Meta's text-first social media platform crossed 500 million monthly active users. It's now expanding the Communities feature beyond beta, adding a new set of tools to make participation easier and more engaging. This week in AI news Image via DepositPhotos.com Catch up on the latest artificial intelligence news updates that arrived throughout the week: Unreal Engine 6: Epic Games' upcoming engine brings changes to the programming model, portability improvements, and generative AI integration. It focuses on the use of generative AI models and tools like Claude and Codex to play a central role in helping developers "build content faster." Americans and AI: New research suggests that about 49% of American adults use AI chatbots such as Gemini and ChatGPT. However, many are skeptical about the impact of AI on both the personal and societal levels, believing it may be harmful in the long run. Mainframe exit vendors might exit: Gartner predicts in its new report that 75% of mainframe exit vendors, which help companies migrate their legacy mainframe systems to modern cloud environments, will either pivot or cease operations as the market realities take hold by 2030. This week in Microsoft News Microsoft announced Windows 11 version 26H2; confirmed a new bug where the Recycle Bin delete prompts display internal file names instead of actual ones; the latest Patch Tuesday updates seemingly broke some third-party Office integrations. You can check out Taras's freshly baked Microsoft Weekly roundup to catch up on all the interesting stories this week. This week in science news Image by Steve Johnson via Pexels Catch up on some of the latest science and out-of-this-world updates that arrived throughout the week: The end of the universe: A new Cornell study suggests the universe will not expand forever. Because of the negative dark energy, it could stop expanding and collapse into a "big crunch" in 20 billion years. The impact of traffic: Researchers found that urban traffic pollution, specifically nitrogen oxides and fine particles, quickly alters the atmospheric electric field measurably in urban areas. This indicates that atmospheric electricity could become a valuable tool to monitor urban air quality and activity. The light of life: A study revealed that living organisms emit a faint, invisible glow called ultraweek photon emission. This natural light significantly decreases after death and increases during stress, offering a highly promising new method for noninvasive medical health diagnosis. Mysteries of time: A new study suggests that the direction of time is not fixed in certain quantum systems. Standard equations of energy loss remain time-symmetric, which means laws can theoretically run backward or forward. This week in gaming The latest issue of Pulasthi's Weekend PC Game Deals curates several exciting games on sale this week. Epic Games Store is now hosting Robobeat and Citizen Sleeper as free-to-claim titles this week, which you can add to your library. Latest issue of Xbox Free Play Days features four new games: PGA TOUR 2K25, Two Point Museum, Assetto Corsa, and Dead by Daylight. Meanwhile, Xbox Game Pass got another Call of Duty addition, the latest soccer game from EA, an indie road trip hit from last year, and more. Summer sales have made NVIDIA's gaming service cheaper, and it has added support for seven new titles. That said, here are some more stories from the gaming world: Rockstar gives last-gen GTA V players free upgrades tomorrow Major Xbox layoffs may claim South of Midnight developer Compulsion entirely Steam Next Fest returns with thousands of new demos to try out Forza Horizon 6 gets another hotfix for one of the game's online modes Major Xbox layoffs may claim South of Midnight developer Compulsion entirely From the review corner This week, Steven got his hands on the Creative Sound Blaster AE-X internal PCIe sound card, primarily intended for headphone wearers. In the list of pros, it comes with a high-quality headphone amp, low-latency communication enhancements via ASIO v2.3, offers 256-times the audio quality of CDs via DSD256, and has great build quality. On the other hand, it's a bit on the pricier side, only offers stereo output over speakers, and has no EMI shielding. More price drops! We got you covered with some hot tech deals all week. For some reason, if you missed out on a great discount, here is a summary of some recent deals that are still alive: GEEKOM X16 Pro at GEEKOM - $1,119.67 (17% off) Acer 4K Webcam for PC/Mac with All-Metal Unibody Sculpted - $59.99 (14% off) Samsung 990 PRO SSD 2TB - $369.99 (42% off) Nothing Ear Wireless Earbuds Bluetooth - $73.15 (51% off) PowerColor Reaper AMD Radeon RX 9070 16GB - $579.99 (17% off) To view all of our recent deals, click here. So, these were some of the biggest tech news and other updates from this week. There will be more issues of our 7 Days series in the coming weeks and months, so stay tuned. You can also support Neowin by registering for a free member account or subscribing to extra member benefits, along with an ad-free tier option. Have a great weekend!
    • It certainly is a waste of time clicking it if you're not interested in Windows 11's development. If that were the case for you, you could easily ignore the headline and move on given the headline makes it clear that's what the article is about. Instead, you're contradicting yourself here calling it a waste of time yet clicking on the headline and commenting... If it were a totally different topic being presented than what's stated in the headline, then you'd certainly have a point, 'cause that's totally deceptive and unavoidable if not actually interested. On the contrary, here you can totally avoid it if you're truly not interested.
  • Recent Achievements

    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
    • Reacting Well
      DrWankel earned a badge
      Reacting Well
    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      185
    3. 3
      PsYcHoKiLLa
      84
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      75
  • Tell a friend

    Love Neowin? Tell a friend!