Spyware that targets Mac applications still lingering

Distributor denies wrong-doing.

A spyware application bundled with roughly 30 Mac third-party screensavers is once again active after its maker temporarily stopped distributing it.

The software, dubbed OSX/OpinionSpy by Mac security firm Intego, is rated high-risk because it scans files, records user activity and sends that information back to remote servers via a backdoor. Officially known as PremierOpinion,  the software is not initially contained in the screensavers but downloaded during installation.

"The malware, a version of which has existed for Windows since 2008, claims to collect browsing and purchasing information that is used in market reports," an Intego blog post said. "However, this program goes much further, performing a number of insidious actions, which have led Intego to classify it as spyware."

Intego said the software runs as root and asks for the administrator's password, opens a backdoor on the victim machine, scans the entire computer, sends data back to servers and upgrades itself automatically, without any user intervention.

"Users have no way of knowing exactly what data is collected and sent to remote servers," the Intego post said. "Such data may include usernames, passwords, credit card numbers and more. The risk of this data being collected and used without users' permission makes this spyware particularly dangerous to users' privacy."

Roman Rusavsky of 7art-screensavers.com, which distributes the screensavers, denied that the company was distributing spyware and said Intego is simply looking to market its anti-virus offerings.

"It [does] analyse some browsing behavior as clearly mentioned in [its] privacy policy and licence agreement," Rusavsky said of the software in an email to SCMagazineUS.com. "But it's not spyware and not malware. It's just a marketing tool of [a] big respected company. A lot of people need information about some internet trends, and it's actually the only way to get it."

Users can still get the screensaver without installing PremierOpinion, Rusavsky said. The company temporarily removed the software while its disclosure screen was updated to include a link to the license agreement of Premier Opinion, a subsidiary of comScore, a marketing research company.

Intego officials weren't happy to see it return.

"This is especially dishonest," the company said in a blog. "In the first place, distributing spyware is reprehensible, but then pretending to want to placate Mac users by claiming to remove the spyware is doubly so."

See original article on scmagazineus.com

Copyright © SC Magazine, US edition

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read