I'm following this with interest:
http://9to5mac.com/2014/10/02/new-mac-botnet-malware-uses-reddit-to-find-out-what-servers-to-connect-to/
I made an extension attribute to detect the existence of the telltale /Library/Application Support/JavaW folder:
https://gist.github.com/homebysix/5f1e09b7a3e75c229ef1
Anybody seen this in the wild yet?
