Posted on 10-03-2014 11:07 AM
I'm following this with interest:
http://9to5mac.com/2014/10/02/new-mac-botnet-malware-uses-reddit-to-find-out-what-servers-to-connect...
I made an extension attribute to detect the existence of the telltale /Library/Application Support/JavaW folder:
https://gist.github.com/homebysix/5f1e09b7a3e75c229ef1
Anybody seen this in the wild yet?
Posted on 10-03-2014 11:23 AM
No. Hopefully one of the security companies tracks down the infection vector soon.
http://www.intego.com/mac-security-blog/iworm-botnet-uses-reddit-as-command-and-control-center/
Posted on 10-03-2014 12:07 PM
I have not seen it yet but will be watching closely
( i did test the EA. It works well with my test environment so I will be monitoring my smart group.)
@elliotjordan Thanks for the post!!!!
Posted on 10-03-2014 12:56 PM
@elliotjordan Thanks for posting this! I was looking closely at how to detect it. I was thinking about putting in a Software Restriction, but since the malware masquerades as a legitimate process, I'm worried about killing it. Anyone else thought of a way to put a software restriction in place to keep the process from running?
Posted on 10-03-2014 01:14 PM
Maybe use the little script in the EA and only run the kill command on a positive result.
Posted on 10-03-2014 01:35 PM
Sophos released a threat signature, so folks using Sophos Anti-Virus should be okay: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/OSX~iWorm-A.aspx
Posted on 10-03-2014 01:52 PM
Thank you for posting this.
We use Sophos AV - I'll make sure the Sophos security team here gets this.
@elliotjordan, thank you for posting too.
Posted on 10-04-2014 07:45 AM
EA and smart group work perfectly, thx @elliotjordan][/url. So far just my test machine reports positive. I'd be interested to hear what get placed in that javaw folder once someone sees an infection.
Posted on 10-04-2014 12:16 PM
Currently using this EA. Thanks Elliot!
Posted on 10-06-2014 11:26 AM
Looks like Apple released an XProtect update for this.
http://www.mactech.com/2014/10/06/apple-updates-xprotect-malware-list