New Mac OS X trojan poses as malicious PDF file
Summary: Security researchers from Sophos and F-Secure have spotted a currently circulating Mac OS X trojan.
Security researchers from Sophos and F-Secure have spotted a currently circulating Mac OS X trojan.
Trojan-Dropper:OSX/Revir.A disguises as a malicious PDF file for spreading purposes. When users attempt to open the Chinese-language PDF file, it installs additional backdoor dubbed Imuler.A, which would give malicious hackers remote access to your Apple Mac computer:
"The malware then proceeds to install a backdoor, Backdoor:OSX/Imuler.A, in the background. As of this writing, the C&C of the malware is just a bare Apache installation and is not capable of communicating with the backdoor yet. The domain was registered on March 21, 2011 and was last updated on May 21, 2011.
Since this malware sample was received from VirusTotal, we cannot exactly be sure about the method it uses to spread. The most probable way is sending via e-mail attachment. The author could be just testing the water to see if the sample is detected by different AV vendors."
Users are advised to avoid interacting with suspicious files, or follow the mitigation advice offered here.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback
Linux is safe
RE: New Mac OS X trojan poses as malicious PDF file
He is trolling
Please don't feed him.
RE: New Mac OS X trojan poses as malicious PDF file
That's my opinion anyway. No way is the wrong way.
RE: New Mac OS X trojan poses as malicious PDF file
You forgot to include the screenshot of the
RE: New Mac OS X trojan poses as malicious PDF file
According to the full write-up from Magmatic, the credentials dialog may or may not show up:
[i]"It is important to realize that a developer can bypass the need for the user to enter the Administrator Password when creating an installer Package."[/i]
Only if files are installed in the user-writeable areas...
RE: New Mac OS X trojan poses as malicious PDF file
Exactly, and that will prevent it from running on your computer in what way? :|
RE: New Mac OS X trojan poses as malicious PDF file
RE: New Mac OS X trojan poses as malicious PDF file
I was about to make the same point, glad someone else is paying attention.
RE: New Mac OS X trojan poses as malicious PDF file
Would that be the malware...