Mac OS X Spyware Sample Spotted

By Ryan Naraine  |  Posted 2006-11-27 Email Print this article Print
 
 
 
 
 
 
 

WEBINAR: Event Date: Tues, December 5, 2017 at 1:00 p.m. ET/10:00 a.m. PT

How Real-World Numbers Make the Case for SSDs in the Data Center REGISTER >

Anti-virus researchers have spotted the first signs of an adware/spyware program capable of launching browser windows on Apple Computer's Mac OS X.

Anti-virus researchers have spotted the first signs of an adware/spyware program capable of launching browser windows on Apple Computer's Mac OS X.

According to a warning from F-Secure, a security vendor in Helsinki, Finland, the proof-of-concept program could be silently installed on a Mac's User account and hooked to each application used by that account.

The company said the sample, named iAdware, successfully launched the Mac's built-in Safari Web browser whenever applications were being used.

"We won't disclose the exact technique used here," F-Secure said, noting that the program was manipulating a feature in Mac OS X. "It's a feature, not a bug, but let's just say that installing a System Library shouldn't be allowed without prompting the user," the company added.

The F-Secure notice said the adware program does not require administrator rights.

"An admin could install this globally to all users," the company said. "This is easier to do than with Windows. After all, it's a Mac."

Security experts have long warned that the Mac platform is not immune to malware attacks, and the appearance of a Mac-specific adware sample suggests that online scammers are tinkering with ways to target Apple's user base.

Check out eWEEK.com's Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at Ryan Naraine's eWEEK Security Watch blog.

 
 
 
 
 
 
 
 
 
























 
 
 
 
 
 

Submit a Comment

Loading Comments...
























 
 
 
 
 
 
 
 
 
Thanks for your registration, follow us on our social networks to keep up-to-date