Friday, September 30, 2011

OS X flashback.A - Malware Targetting Mac OS X Lion

Mac malware?? Not again!!

If you are thinking the names like Malware, virus, Trojan horses is only made for windows then stop you need to think again!  In a single year, intruders target Mac world twice.  First time (Read about  Mac Defender) they tried to hack your credit card information and this time they are trying to get unique ID of your Mac! HOW? Just recall for a second have you installed Adobe flash in recently? If yes read every single line written here:-

(Image Credit: Appleinsider.com)


This first screen of malware appears exactly similar to Adobe flash player. It is reported to present in malicious websites which on landing invites users to install flash player telling that some content present at the page need flash player. Since it is known to everyone that flash player is not pre-installed in Mac OS X Lion that user need to install manually. So chances are very bright to  get click from user. Giving no room to think, intruders made its interface exactly similar to the original adobe flash player including design & logo. This name of malware is – OS X/flashback.A!

Soon after downloading, a installer will appears and it proceed to disable network security first. It install a DLL (dynamic link library) & an auto launch code which allow to inject code the applications launched by the user.  As soon as user launch the application this code start connection with remote server and whole information provided by the user to that application would send to remote server. Just imagine if user has launched that application to pay credit card bill,  what this “OSX/flashback.A” is going to do? Right, it will send whole information to the remote server. Not only single application whenever you launch any application this script would send whole information.

How to prevent your Mac from Malware

Handle All File Manually: Apple provide some options in Safari such as it always considers all file as safe. So it automatically open those files. But unfortunately, all files are not safe. So set the following permission as follows:
  • Launch Safari
  • Select preferences->General
  • Uncheck the Open 'safe' files after downloading" box
This will ask you every time before downloading any file. DO NOT ALLOW ANY UNKNOWN APPLICATION access your Mac.

Install Application from trusted source only: Make this habit of installing application from trusted source or directly from official website.

Check Whether Your Mac is infected or not:

If you have downloaded Adobe flash player recently, check whether you are infected or not by looking for file “~/Library/Preferences/Preferences.dylib"

No comments:

Post a Comment