OFFICIAL SECURITY BLOG

We’ve moved! You can now read the latest and greatest on Mac adware and malware at Malwarebytes.

Search results for: Little snitch

e-biohazard iWorm method of infection found!

Posted on October 4th, 2014 at 7:29 AM EDT

On Thursday, I wrote about new malware called iWorm. This morning I awoke to find an e-mail waiting for me in my Inbox from someone who wished to remain anonymous. This person indicated that he had found installers for the new iWorm malware. He pointed me to the downloads offered by a user named “aceprog” on PirateBay.
Read the rest of this entry »

48 Comments

e-biohazard ChatZum adware added to VLC on Softonic

Posted on April 16th, 2013 at 4:44 PM EDT

It was brought to my attention today by an astute reader that there is a copy of VLC, currently being hosted on Softonic, which has had adware added to it. Of course, I had to investigate, and what I found is very concerning. That report turns out to be completely true, and worse, the adware installs components on your system even when you opt out of installing it!
Read the rest of this entry »

44 Comments

e-biohazard Has GetShell been trojanized?

Posted on March 11th, 2013 at 7:44 PM EDT

An interesting file was posted to VirusTotal today: a Mac disk image file containing what appeared to be a copy of Adium. This file was recognized by a small handful of anti-virus engines as the GetShell malware, however. This surprised me a bit, as GetShell had previously (as far as I know) only been installed as a drive-by download through Java vulnerabilities. So I decided to do a little investigation.
Read the rest of this entry »

22 Comments

About the Flashback malware

Posted on April 7th, 2012 at 2:37 PM EDT

What is Flashback?

Flashback first appeared back in September of 2011, as a simple trojan.  It would be downloaded from web sites that displayed a warning that your Adobe Flash player had crashed and needed to be updated.  Of course, the “update” would actually be malware, which would install some code that would be inserted into applications like Safari, with the purpose of sniffing out data you transmit, such as credit card numbers or financial site passwords.  It wasn’t to big a threat to the wary web surfer, though…  especially English-speaking folks, who would be tipped off immediately by text like “Update fix a crush of Adobe Flash player.”
Read the rest of this entry »

Leave a comment

A new Flash Player trojan

Posted on September 26th, 2011 at 2:34 PM EDT

Earlier today, Intego announced their discovery of a new Flash Player trojan, which they have named OSX/flashback.A.  Earlier this summer, another Flash Player trojan (BASH/QHost.WB) was announced by F-Secure, masquerading (as this one does) as a Flash Player installer.  However, unlike the last trojan, which never really worked, this new trojan is functional (though different)!
Read the rest of this entry »

2 Comments

More broken Mac malware

Posted on September 26th, 2011 at 10:00 AM EDT

There hasn’t been much to say about Mac malware lately.  Since the folks behind the MacDefender trojans got caught and put into Russian prison, things have been quiet.  The last two things I’ve written about since then were a trojan that was Windows-only and a broken Mac trojan.  This weekend, however, changes that streak.  On Friday, F-Secure discovered a new Mac trojan masquerading as a PDF file.
Read the rest of this entry »

2 Comments

Do I need a firewall?

Posted on June 5th, 2011 at 4:24 PM EDT

Firewalls have always been poorly understood, even by knowledgeable people. With the recent upsurge in Mac malware, there has been a lot of questionable advice circulating, some of which related to firewalls. People are recommending firewalls for avoiding malware, blocking hackers, preventing spam and any number of other things.  Some of these recommendations have some validity and some do not…  but how is the average user to know the difference?
Read the rest of this entry »

This post is more than 30 days old and has been locked. No further comments are allowed.

MacGuard details

Posted on May 26th, 2011 at 10:32 PM EDT

I managed to get my hands on a copy of MacGuard this evening, and ran it through some tests to try to clarify some of the rumors floating around.  The good news is that, in all, this is just another boring old variant in the MacDefender malware line.  The same old removal instructions still apply, and the application itself does not appear to have developed any new features.  However, when it comes to the installation, there are some notable differences!
Read the rest of this entry »

6 Comments

Further analysis of MacProtector

Posted on May 10th, 2011 at 8:53 PM EDT

There have been reports circulating that MacDefender/MacSecurity/MacProtector may be doing nasty things like scanning the hard drive and sending data home.  If this is true, it would be a more serious problem.  The behavior that has been documented to date is less dangerous because it is entirely under your control.  You choose whether to proceed with the installation, and you choose whether to give a credit card number.  Many people have accepted the installation, but balked at the credit card…  but that could be a problem if the trojan is doing other things behind the scenes.  So, are these rumors true?  Here’s what I found.
Read the rest of this entry »

3 Comments