New variant of RSPlug Mac trojan

A new variant of the RSPlug trojan, which targets Apple machines, was recently discovered in the wild.

According to Jamz Yaneza, a threat researcher with anti-malware firm Trend Micro, the latest incarnation of the trojan was distributed through websites offering “warez” -- hacker-speak for pirated software. It would have caused an infected user's browser to redirect to a phishing or malware-serving site. It had less functionality than older variants though, indicating that it was likely the work of copycat hackers.

The first variant of the RSPlug trojan dates back to October 2007, then distributed through pornography sites. Users were told they needed to download a codec to view a video, which was actually the trojan – a DNS changer used to hijack search results and divert web traffic.

Last month, a separate attack targeting Mac users was distributed through pirated versions of Apple iWorks 2009 and Adobe's Photoshop for Macintosh, Yaneza said. These attacks should deter users from attempting to get free key generators [a small program to generate a valid cryptographic key for data encryption], cracks and serial numbers for Mac applications.

In addition, the incidence of this new trojan variant highlights the fact that cybercriminals increasingly are targeting the Mac OS, Yaneza said.

“There are many out there that still believe Macs are impervious to attacks,” Yaneza said.

See original article on scmagazineus.com

Copyright © SC Magazine, US edition
New variant of RSPlug Mac trojan

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read