VIA Root
VIARoot Security News Security alerts Business IT security Services Security Tools About VIARoot
Spyware distributed on Mac Web sites
Search
Security News
security
Mathew J. Schwartz, InformationWeek
2010-08-27 14:11:17
Email and peer-to-peer networks also rank as significant venues for malware attacks, which have increased slightly in the U.S. but declined in Europe, according to Panda Security.
intel
Hugo Jean, Heptacube Inc.
2010-08-24 14:51:53
The motivation behind the $7.68 billion deal is unclear, but Intel says it wants to integrate computer security into its hardware.
IT Directory
Wiseleap Solutions Inc.
Founded in 2005, Wiseleap Solutions Inc.'s mission consists in providing companies with the information necessary to make cri [...]
IT Ration Consulting Inc.
IT-Ration Consulting inc has been a NetSuite Partner since 2005 and helps your enterprise grow by aligning your Information T [...]
HumanWare
Empowering People Focused on enhancing the lives of people with visual and learning disabilities, HumanWare provide [...]
By Hugo Jean, Heptacube Inc.
Apple
2010-06-04 11:54:55

In a memo dated from June 1st, 2010, security firm Intego warns that a spyware application, which they detect as OSX/OpinionSpy, has been spotted and is being "installed by a number of freely distributed Mac applications and screen savers found on a variety of websites." The said Web sites include MacUpdate, VersionTracker and Softpedia.

The spyware is not contained in the files themselves, so scanning them before installation will not help protect one's computer. During the installation process, the user is told that a "market research" program will also be installed. OSX/OpinionSpy is then downloaded and installed. According to Intego, "the malware, a version of which has existed for Windows since 2008, claims to collect browsing and purchasing information that is used in market reports."

However, they warn that the malware goes much further by taking other potentially damageable actions. OSX/OpinionSpy opens a backdoor through port 8254; harvest data from the infected computer and sends it to its server; injects code into Safari, Firefox and iChat and gathers personal information from the applications; and more. In addition, some of that potentially sensitive information could be used in a matter that is harmful to the user's privacy.

This is rated as a "very serious security threat". Also, OSX/OpinionSpy is able to upgrade itself and a variant, known as PermissionResearch, has already been spotted in the wild by Intego.








Tags
Apple Intego Mac MacUpdate OSX screensaver Softpedia spyware VersionTracker