Nov17 |
10:05 pm (UTC-7) | by
Jake Soriano (Technical Communications) |
Trend Micro Advanced Threats Researcher Ivan Macalintal reports of a new malware affecting Mac OS. Detected as OSX_LAMZEV.A, this malicious file could allow hackers to take control of an infected system.
Mac users may be infected when they access remote websites hosting this backdoor. The backdoor may also be disguised as a legitimate application and may be installed and executed on systems.
When executed, OSX_LAMZEV.A prompts users to select an application and a port above 1024. These are Internet Assigned Numbers Authority (IANA) registered ports and are used by vendors for proprietary applications.
The backdoor creates the file /tmp/com.apple.DockSettings and copies this file in the location ~/Library/LaunchAgents. This file is then deleted once it has been loaded to allow this backdoor to execute everytime the system starts up. The application selected by the infected user is copied by this backdoor to a certain location too. It then creates another backdoor component that executes whenever the said Mac application is executed.
These malware routines compromise security, as remote malicious users may gain access to an affected system. OSX_LAMZEV.A also has autostart features, so turning one’s infected Mac on automatically runs the backdoor.
Interestingly in November last year, another notable Mac malware hit users. Detected by Trend Micro as OSX_DNSCHAN.A, this older Trojan dropped malicious script files and came in two versions, one for Windows and another for Mac, depending on the Web browser and operating system used to download it.
There are not many but their number keeps growing. Other Mac threats are documented in the following blog entries:
The Trend Micro Smart Protection Network already detects OSX_LAMZEV.A and provides solutions for its cleanup and removal.
Share this article |
|





Pingback: Macoreo » Archivados » A Mac no le entran virus
Pingback: Trend Micro detalha novo malware que afeta o Mac OS X
Pingback: Apple quita página de soporte para virus - AppleHOY
Pingback: TidBITS Email: ExtraBITS for 01-Dec-08
Pingback: Tryboi blog» Архив блога » Новая вредоносная программа для Mac OS X
Pingback: Sosyal İm - Teknoloji haberleri » Lamzev.A: Yeni Mac OS X trojanımız » Blog Arşivi » Lamzev.A: Yeni Mac OS X trojanımız
Pingback: Lamzev.A: Yeni Mac OS X trojanımız - Mac Dünyası
Pingback: Neue Schadsoftware für Mac OS X | sevenmac
Pingback: A Mac no le entran virus « Macoreo
Pingback: Mac Malware Sighting « Macs4Madison’s Weblog
Pingback: New Mac OS X malware - OSX_LAMZEV.A | iphone-zone.co.cc
Pingback: New Mac OS X malware - OSX_LAMZEV.A | Apple News
Pingback: New Mac OS X malware - OSX_LAMZEV.A | IPHONE NEWS
Pingback: New Mac OS X malware - OSX_LAMZEV.A
Pingback: Nuevo malware detectado en Mac OS X - AppleHOY
Pingback: MIKOWHY pe.el » Na Maca Lamzev-A
Pingback: Lame Mac Trojan limps into view - Computer Forums
Pingback: Malware threatens MAC OS X | Marcos Christodonte II - Information Security Blog