Nov17
10:05 pm (UTC-7)   |   by Jake Soriano (Technical Communications)

Trend Micro Advanced Threats Researcher Ivan Macalintal reports of a new malware affecting Mac OS. Detected as OSX_LAMZEV.A, this malicious file could allow hackers to take control of an infected system.

Mac users may be infected when they access remote websites hosting this backdoor. The backdoor may also be disguised as a legitimate application and may be installed and executed on systems.

When executed, OSX_LAMZEV.A prompts users to select an application and a port above 1024. These are Internet Assigned Numbers Authority (IANA) registered ports and are used by vendors for proprietary applications.

The backdoor creates the file /tmp/com.apple.DockSettings and copies this file in the location ~/Library/LaunchAgents. This file is then deleted once it has been loaded to allow this backdoor to execute everytime the system starts up. The application selected by the infected user is copied by this backdoor to a certain location too. It then creates another backdoor component that executes whenever the said Mac application is executed.

These malware routines compromise security, as remote malicious users may gain access to an affected system. OSX_LAMZEV.A also has autostart features, so turning one’s infected Mac on automatically runs the backdoor.

Interestingly in November last year, another notable Mac malware hit users. Detected by Trend Micro as OSX_DNSCHAN.A, this older Trojan dropped malicious script files and came in two versions, one for Windows and another for Mac, depending on the Web browser and operating system used to download it.

There are not many but their number keeps growing. Other Mac threats are documented in the following blog entries:

The Trend Micro Smart Protection Network already detects OSX_LAMZEV.A and provides solutions for its cleanup and removal.

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




20 Responses to “New Malware Threatens Mac Users”

Trackbacks

  1. Malware threatens MAC OS X | Marcos Christodonte II - Information Security Blog
  2. Lame Mac Trojan limps into view - Computer Forums
  3. MIKOWHY pe.el » Na Maca Lamzev-A
  4. Nuevo malware detectado en Mac OS X - AppleHOY
  5. New Mac OS X malware - OSX_LAMZEV.A
  6. New Mac OS X malware - OSX_LAMZEV.A | IPHONE NEWS
  7. rcapote (Ryan C)
  8. nth_degree (Evan)
  9. New Mac OS X malware - OSX_LAMZEV.A | Apple News
  10. New Mac OS X malware - OSX_LAMZEV.A | iphone-zone.co.cc
  11. Mac Malware Sighting « Macs4Madison’s Weblog
  12. A Mac no le entran virus « Macoreo
  13. Neue Schadsoftware für Mac OS X | sevenmac
  14. Lamzev.A: Yeni Mac OS X trojanımız - Mac Dünyası
  15. Sosyal İm - Teknoloji haberleri » Lamzev.A: Yeni Mac OS X trojanımız » Blog Arşivi » Lamzev.A: Yeni Mac OS X trojanımız
  16. Tryboi blog» Архив блога » Новая вредоносная программа для Mac OS X
  17. TidBITS Email: ExtraBITS for 01-Dec-08
  18. Apple quita página de soporte para virus - AppleHOY
  19. Trend Micro detalha novo malware que afeta o Mac OS X
  20. Macoreo » Archivados » A Mac no le entran virus

Leave a Reply



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice