Saturday, September 24, 2011

OSX/Revir.A Trojan Horse Targeting Mac OS X in Order to … Do Nothing?

Revir.A Trojan Horse Doesn't Do MuchWith more and more users adopting Macs these days, cybercooks may be growing tempted to switch from developing malware and other nasty bugs for Windows to creating them for Macs instead.

Unfortunately for the creator of the Revir.A trojan (but fortunately for Mac users), it seems like their efforts aren’t proving to be so fruitful.

Meet Trojan-Dropper:OSX/Revir.A


The Revir.A Trojan comes disguised as a PDF file, written in Chinese and covering the long-heated debate between China and Japan over who controls a group of islands in the East China Sea, known as the Diaoyu Islands in China and the Senkaku Islands in Japan.

As some of you may be well aware, spreading malware via malicious PDF files is nothing new and is a common technique used by Windows malware authors, so it’s no real surprise that it’s being used to deliver OS X malware as well.

Similar to Windows malware attacks, the PDF is merely to provide the bug easy entry into the PC (as nobody thinks PDFs harbor any threat to their computer's security!) and serve as a distraction for the user while the malware does its thing in the background, which in this case is installing a backdoor named OSX/Imuler.A.

Fortunately, it appears that the malware is incapable of communicating with any remote command-and-control servers (which would give cybercrooks remote control of your Mac), so the threat level is relatively low at this point.

Either way, if you get an email with a PDF attachment, don’t download it. There’s no telling when the malware author will wise up and release a fully-functional version.

As recommended to Windows users, you should always run antivirus software on your PC and proceed with caution when downloading files from the internet. While their may not be as many threats targeting Apple's OS as there are Windows, there are threats out there that are capable of destructive behavior. Better to be safe than sorry!

Photo Credit: Britrob
[Altered by Marquisa]

No comments:

Post a Comment