A Mac OS X trojan was found obfuscated as a PDF file, according to researchers at F-Secure.
A trojan dropper installed a backdoor program which could give attackers full control of Mac systems.
The remote command-and-control (C&C) server used to connect with infected machines was a bare Apache installation, F-Secure found.
The malware embedded PDF tactic was new for Mac malware, according to Sophos senior security adviser Chet Wisniewski.
"The PDF lure is a good trick to get people to install the trojan," he said. "You think you're opening a document, when you're installing malware."
"This exploit could be a one-off, but our suspicion is that the model has been established, and we will see more criminal gang activity," he said.
Windows was still the preferred target of cybercriminals because there were more machines to attack.
This article originally appeared at scmagazineus.com
Copyright © SC Magazine, US edition
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED GOES EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @itnews.com.au to your white-listed senders.