140,000 Flashback-infected computers remain

By Dan Kaplan on Apr 19, 2012 8:01 AM
Filed under Security

Researchers find trojan uses Twitter to stay alive.

Some 140,000 machines remain infected with the Flashback trojan, according to estimates from Symantec, despite Apple releasing three security updates to vanquish the data-stealing malware.

Symantec, which "sinkholed" the botnet so compromised computers would communicate with servers under its control, said in a blog post Tuesday it expected numbers to have diminished more by now, considering Apple released a detection and removal capability as part of its latest update to Java for Mac OS X.

Still, the botnet's size has declined by close to 75 percent in a short stretch of time, from an initial high of some 600,000 nodes on April 9.

Symantec's analysis also turned up another interesting tidbit regarding the trojan, which so far doesn't seem to be performing any information-stealing actions. Researchers found it can receive updated information via Twitter about which command-and-control servers to contact for additional instructions.

This is accomplished "by searching for specific hashtags generated by the [Flashback] hashtag algorithm," according to the post. But this wouldn't be the first time Twitter has been used to send botnet commands.

Despite the hoopla surrounding the large infection rate, Apple's slowness to patch and many users' unwillingness to install anti-virus protection, some experts prefer to keep the Mac threat in perspective, considering the platform's market share hovers just above 10 percent.

“As the Mac becomes an increasingly popular computing platform, we will naturally see an increase in attacks geared toward the OS X platform," said Michael Sutton, vice president of security research at Zscaler. "That said, today, Mac OS X targets remain a small sliver of total malware currently in the wild."

This article originally appeared at scmagazineus.com

 
Follow us on Facebook and Twitter
 

Copyright © SC Magazine, US edition

140,000 Flashback-infected computers remain
 
 
 
 
 
Top Stories
Data#3 scoops global Microsoft award
Driving Windows 8 adoption.
 
 
Govt clueless about mobile program costs
Smart enough not to develop in-house.
 
Sign up to receive CRN email bulletins
   FOLLOW US...
Latest Comments
Polls
Is your business doing as well now as it was at this time last year?


   |   View results
Yes
  32%
 
No
  53%
 
The same
  15%
TOTAL VOTES: 379

Vote now
CRN Magazine

Issue: 315 | May 2013

CRN Magazine looks in-depth at the emerging issues and developments for the channel, and provides insight, analysis and strategic information to help resellers better run their businesses.