Showing posts with label Boonana. Show all posts
Showing posts with label Boonana. Show all posts

Friday, July 8, 2011

Current Mac Malware, 2011-07:
Introduction

In order to help Mac users understand the current state of malware on the platform, I am providing a review  of each current form. This will not be an exhaustive review, but should help relieve much misunderstanding and concern about the ongoing, many years old, anti-Apple security FUD Fest.

I will be going through the malware in reverse chronological order, featuring the most current concerns first and the oldies but gnarlies last.

The first thing to know is that technically, ALL currently active Mac malware are Trojan horses. That means that they are entirely inert until such time as a user (or 'LUSER', in cynical terminology) inadvertently installs them.

I am NOT including any hacker tools or 'legal' spyware in my details articles. These require a third party to be able to physically access your computer and directly install them for their nefarious purposes. You won't personally be in any danger of installing them unless a hacker or IT administrator directs you to do so. They require hackers or administrators to access your computer in order for them to do any harm. I may address these forms of software at another time. I am more concerned about what YOU might mistakenly install.

THE LIST:

1) Trojan.OSX.MACDefender.A - O [15 strains]

2) Trojan.OSX.BlackHoleRAT.A - C [3 strains]

3) Trojan.OSX.Boonana.A

4) Trojan.OSX.OpinionSpy.A - B [2 strains]

5) Trojan.OSX.iServices.A - C [3 strains]

6) Trojan.OSX.PokerStealer.A

7) Trojan.OSX.RSPlug.A - Q [17 strains]

The total number of Mac malware species are 7.
The total number of Mac malware strains are 42.


The 'Malware' Hacker Tools I Am Leaving Out:

'Trojan'.OSX.Lamzev.A

'Trojan'.OSX.Hellraiser.A - D [4 strains]

There are a number of inert malware as well as 'Proof of Concept' malware of no concern which I have also left out of my list. You may find them on other lists but you won't find them infecting anyone with up-to-date computers, apart for test computers in a lab. (A famous example of 'Proof of Concept' malware is Trojan.OSX.Oomp.A, aka Trojan.OSX.Leap.A. It is of no consequence or importance).

If you'd like a list of current 'legal' spyware, I suggest the list kindly provided at the MacScan/SecureMac site.

Note that, due to the lack of adherence to standards within the anti-malware community, there are a lot of name variations for the exact same malware. In the case of the MAC Defender Trojan I discovered 15 different names. I am not including them here in my list as these alternative names are irrelevant and needlessly confusing. What I have listed here are the 'official' names from my point of view as well as those whom I consider to be professional experts and original malware discoverers in the field. However, I will be listing a number of the alternative names in my subsequent articles that provide details about each of the current malware species.

As ever, I request corrections to my information. If I have missed a malware species or strain, please let me know asap. Much appreciated!

Friday, November 5, 2010

Evercookie,
Koobface boonana worm Trojan,
Firesheep and MORE!
Oh My

--
There are four ongoing scary security monsters threatening ALL the popular computer platforms this month. But that I mean they affect Mac, Linux and Windows. At the moment, there is nothing dire or critical about them. But each of them is nasty in their own way.

I've been holding off tackling each of them in order to gather day-by-day new information and to wait for 'the other shoe' to drop from each of them. I expect they're all going to be annoying aspects of our computer lives for quite some time to come. I'll be devoting an article to each of them individually. But first I want to introduce you to our gang of circus animals:

I) A round of applause for the Black Hat creation known as the EVERCOOKIE. Essentially, it is a collective set of methods for spying on your web browser behavior, able to renew itself despite actions you take to prevent it. Stopping this monster can be annoying and complicated. I'll discuss the currently known tricks.

II) Next up in circus ring number 2 is the latest in Java insecurity. As per usual, the utterly chaotic computer security community can't agree upon a name for the thing. Having reviewed the data, I am going with the name Intego are using: Koobface. Because of its various activities, it can be called a worm, a Trojan horse, a root kit, a back door AND a bot. Because its primary interface to the user (or 'LUSER' in this case) is as a Trojan horse, I am unofficially going to refer to it as Trojan.OSX.Koobface.A. Apparently a second version has just been discovered, which I will call Trojan.OSX.Koobface.B. Meanwhile, you are bound to see the exact same thing also called the 'Boonana' Trojan. (o_0)

III) In the third ring of our circus of naughtiness is Firesheep, the Black Hat extension for Firefox that simplifies the long standing ability to spy on and doppelganger anyone connected within the same unencrypted WiFi connection. It's not just for hackers any more! This one piece of software has sparked an Internet encryption revolution, or so I'd like to believe.



IV) But wait! That's not all! Get a load of the latest idiotic idea from The Corporate Oligarchy! They want government access to ALL things encrypted. Say goodbye to Internet privacy! George Orwell's '1984' Big Brother has arrived and you're going to want to kick him in the balls! Anti-privacy efforts have become that invasive and deviant. The control freaks are out to run our lives.
(>_<) ACK!

So hang onto your propeller beanies while, during the next few days, I cover each of these gnarly subjects relevant to the future of Macintosh computer security.

Oh fracking my!
--