Windows Trojan re-configured for MacOS

Powered by SC Magazine
 

Rare find: Backdoor BlackHole RAT.

Security vendor Sophos has found an old Windows backdoor Trojan that has been reconfigured for MacOS X systems.

The trojan, called Blackhole Remote Access Trojan (RAT), appeared to be an early experiment, according to Sophos security advisor Chester Wisniewski.

“As even the malware itself admits, it is not yet finished, but it could be indicative of more underground programmers taking note of Apple's increasing market share,” the researcher said.

The Trojan relies on social engineering to attempt to slip past Apple’s application signing process, prompting a user to type in their Administrator Password in order to install it.

Wisniewski said the Trojan’s functions include placing text files on the desktop, sending commands to restart, shutdown or sleep, running arbitrary shell commands, creating a window that forces a user to reboot, and sending viewed URLs to an open website. 

Security vendors have long talked of the impending rise of malware for Macs, but so far the platform has failed to attract malware writers en masse.

Security giant McAfee had avoided releasing a MacOS X security product but last year released one.

Apple last year reportedly issued a patch that dealt with another Trojan, HellRTS.

Copyright © iTnews.com.au . All rights reserved.


Windows Trojan re-configured for MacOS
 
 
 
Top Stories
Meet FABACUS, Westpac's first computer
GE225 operators celebrate gold anniversary.
 
NSW Govt gets ready to throw out the floppy disks
[Opinion] Dominic Perrottet says its time for government to catch up.
 
iiNet facing new copyright battle with Hollywood
Fighting to protect customer details.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  26%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  21%
 
End user computing (desktops, mobiles, apps)
  15%
 
Software development
  26%
TOTAL VOTES: 335

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  57%
 
No
  43%
TOTAL VOTES: 139

Vote