Skip to main content
Question

Worm for Macs -

  • October 4, 2014
  • 4 replies
  • 19 views

Forum|alt.badge.img+9

Guys, there is a worm out for macs. Here is a link to the article.
http://www.iclarified.com/44390/new-macbackdooriworm-threat-has-infected-over-18500-macs

I've just created an extension attr, and a smart group to monitor if this happens to one of ours.

4 replies

Forum|alt.badge.img+6
  • New Contributor
  • October 4, 2014

My extension attribute checks two places:

-d /Library/Application Support/JavaW
-f /private/var/root/.JavaW


Forum|alt.badge.img+33
  • Hall of Fame
  • October 4, 2014

It looks like the iWorm method of infection has been identified. The transmission is not automated and requires active human intervention and admin privileges for the Trojan to be installed:

http://www.thesafemac.com/iworm-method-of-infection-found/


mm2270
Forum|alt.badge.img+24
  • Legendary Contributor
  • October 4, 2014

Thanks for the link Rich. Good to hear its more a people problem than an actual flaw in the OS that's being exploited. Not that its that surprising. People being dumb is often the way things like this spread. Makes an excellent case against touching pirated software, that's for sure.


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • October 5, 2014