Showing posts with label malware list. Show all posts
Showing posts with label malware list. Show all posts

Sunday, May 17, 2009

Current List of Mac OS X Active Malware

--
This evening I was busy over at the ClamXav forum. In response to a suggestion there, I provided a current list of Mac OS X active malware. I decided to cross-post the list here as well:

Below is a list of all the Mac OS X active malware I am aware of. I've been attempting to keep up to date on this subject since 2005. I have a blog where I share all my knowledge of Mac security:

http://mac-security.blogspot.com

As far as I am able to ascertain, the only active Mac OS X malware ClamAV is able to detect is Trojan.OSX.RSPlug.A (aka DNSChanger.A). In a previous thread I have asked for help trying to determine if any further Mac OS X malware are detected.

Note that there is only one official standard name for each of the 11 malware. This is what I use to name each family. However, anti-malware providers call them anything they choose. This is why I provide alternative names. There are four families of Trojans listed below with various strains/versions/variants designated by "A" through however many exist for the family. In the case of RSPlug I list A through G specifically because the PCTools site lists that many. Most other sites list only A through F.

If anyone knows of further names for these malware, or of any further ACTIVE malware (please not inert or proof-of-concept malware) please let me know at my blog.

The current list of active Mac OS X malware as of 2009-05-17:

I) Trojan.OSX.RSPlug family, aka DNSChanger or Jahlav.
01) Trojan.OSX.RSPlug.A
02) Trojan.OSX.RSPlug.B
03) Trojan.OSX.RSPlug.C
04) Trojan.OSX.RSPlug.D
05) Trojan.OSX.RSPlug.E
06) Trojan.OSX.RSPlug.F
07) Trojan.OSX.RSPlug.G

II) Trojan.OSX.Lamzev family, aka Malez.
08) Trojan.OSX.Lamzev.A

III) Trojan.OSX.PokerStealer family, aka Corpref.
09) Trojan.OSX.PokerStealer.A

IV) Trojan.OSX.iServices family.
10) Trojan.OSX.iServices.A
11) Trojan.OSX.iServices.B

Sources of these malware:

The RSPlug family are all offered by websites that tell you that you must install their file or program in order to access specific media they are offering. Originally these Trojans showed up on porn sites where you were told to download a video codec in order to view their videos. These days the websites could be telling you anything. The basic idea is to use 'Social Engineering' to fool you into installing their Trojan. The most recent of these Trojans can potentially zombie your computer and use it in a botnet.

Lamzev is a hacker tool used to create backdoor access into a computer. The only way to 'catch' it is if a hacker has physical access to your computer and hand-installs it. Note that there are plenty of other hacker tools around, but this is the only one listed as a Trojan because of the potential damage it can do to a victim computer.

PokerStealer originally called itself "PokerGame". You download it, install it and are infected. The original version put up a bogus warning message that a corrupt preference file had been detected and that your administrative password was required to repair it. It then sends your ID, password and IP address to crackers who can then access your computer via SSH and do whatever they like with it. Theoretically this Trojan can be named anything.

iServices showed up earlier this year in pirated programs, buried inside their installer. The original A and B variants were buried in pirated versions of iWorks 09 and Photoshop CS4. You install the pirated program and get infected. There are reports that the installers actually fail to install the listed program and only install the Trojan. In any case, iServices zombies your computer and makes it part of a botnet. This Trojan formed the first officially verified Mac botnet back in February. It apparently consists of thousands of computers. It has so far been used in a DDOS attack. Note that once a Mac is zombied, the 'bot wranger' or cracker-in-charge can do anything they like with the computer. This particular zombie botnet is so far is being used for money making ventures over the Internet.

If/when further Mac OS X active malware is discovered I'll list it in my blog.
--

Wednesday, April 15, 2009

Derek's Minor Intego Adventure

--
Intego VirusBarrier remains my favorite Mac anti-malware application. Yeah, like many of it's competitors, it's named incorrectly, (should be 'MalwareBarrier'). And yeah, they don't publish a list of their malware definitions, but I still... WHAT? No malware list?!

So I contacted Intego and had an email chat with a nice fellow at their Support Team. My question: Where is your malware list? Their reply:
We do not provide a list of every virus that VirusBarrier X5 protects against. If you have a question about a particular virus threat, please let us know and we will be more than happy to answer the question for you. You can also find information on our security blog about new threats:

The Mac Security Blog
This is actually a very good blog. However, it does not cover all Mac malware. So I persisted in my conversation with Intego. It turns out that there is a disconnect between their blog and their news releases; Therefore, you have to keep track of both:
Intego Press Releases
I found it is indeed possible to scavenge together a list of Mac OS X malware detected by VirusBarrier. I was also pleased to find the list is complete.

(The possible exception is Trojan.OSX.RSPlug.G, which for all I know is mythological. Only PCTools' iAntiVirus program notes it having been found in the wild. Or, on the other hand, Intego may include the G variant with the F variant. It's hard to tell thanks to the industry's insistent lack of conformity to malware description and naming standards).

So why doesn't Intego provide a simple list of detected malware with descriptions of each malware family and variant, like you know, everyone else does? I call it disorganization, which is a shame since they easily have the most organized and best written anti-malware program for Mac.

Until Intego get better organized, I suggest keeping track of the Mac OS X Threat List provided at the PCTools iAntiVirus site page. It contains a lot of baloney proof-of-concept, inert and ancient Mac OS (not X) malware. Otherwise I find it very useful. Yes, it has the same old problem of not adhering to malware naming standards resulting in the same old comprehension chaos. And yeah, this list has some incomprehensible duplication of malware, like DNSChanger and RSPlug being listed separately when in fact they are the same thing. *rolling eyes* But so far, it's the most complete, literate and up-to-date list I have found:
iAntiVirus Threat List
[I continue to ask: Why do I have to write this blog? Why isn't there a nice, up-to-date, simple, complete, sane, standards compliant site dedicated to Mac OS X malware? Until one appears, I'll continue trying to fill the void.]
--