Monday, March 30, 2009

Apple Mac malware: caught on camera

"Pob in our analysis labs blogged earlier this week about a new variant of the RSPlug Trojan horse for Mac OS X that he had written protection against. One of the ways in which the OSX/RSPlug-F Mac Trojan horse is being distributed by hackers is in the form of a poisoned HDTV/DTV program called MacCinema.

Oh, and Windows users shouldn't feel too smug about this either. If you visit the site on a Windows computer, it will serve up a malicious Windows executable from the Zlob family of malware rather than a Mac OS X Trojan horse."

This attack does not depend on any browser vulnerabilities - it works by the user being convinced via social engineering that this is a program that they would like to run on their computer.

