Trojan targets Mac pirates

By on
Trojan targets Mac pirates
Mac users are being warned of a new malware attack circulating within pirated software for OS X.

Researchers from Intego and Symantec have reported the infections occurring within pirated copies of Apple's iWork productivity suite.

According to both companies, the malware is embedded within the iWork installer package and is executed as soon as the user begins installing the pirated copy of the program.

Once installed, the malicious software connects to a remote server, opening a 'back door' to the targeted system and potentially allowing an attacker to control any infected machine and access personal data.

"The malicious software connects to a remote server over the internet. This means that a malicious user will be alerted that this Trojan horse is installed on different Macs, and will have the ability to connect to them and perform various actions remotely," Intego said in its report.

The company also noted that additional components could be installed on infected systems, as the malware is given root access.

Symantec product manager Mike Romo said that, while the company has the Trojan classified as a low-level threat, a significant danger still exists.

"It is still significant because, with the current economic crisis, more and more people might be tempted to use pirated software instead of paying for it," Romo wrote.

"What's particularly vexing is that, unless users have some kind of security software, they would never know that their Mac was compromised because the iWork components themselves would work normally."

Intego and Symantec said that the latest updates of their respective Mac security products will detect the Trojan. However, users can simply avoid the attack by not downloading pirated versions of iWork.

Copyright ©

Most Read Articles

You must be a registered member of CRN to post a comment.
| Register


Does the government do enough to procure from local IT providers?
View poll archive

Log In

Username / Email:
  |  Forgot your password?