[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

Beware The 'Omniwar': Catherine Austin Fitts Fears 'Weaponization Of Everything'

Roger Stone: AG Pam Bondi Must Answer For 14 Terabytes Claim Of Child Torture Videos!

'Hit Us, Please' - America's Left Issues A 'Broken Arrow' Signal To Europe

Cash Jordan Trump Deports ‘Thousands of Migrants’ to Africa… on Purpose

Gunman Ambushes Border Patrol Agents In Texas Amid Anti-ICE Rhetoric From Democrats

Texas Flood

Why America Built A Forest From Canada To Texas

Tucker Carlson Interviews President of Iran Mosoud Pezeshkian

PROOF Netanyahu Wants US To Fight His Wars

RAPID CRUSTAL MOVEMENT DETECTED- Are the Unusual Earthquakes TRIGGER for MORE (in Japan and Italy) ?

Google Bets Big On Nuclear Fusion

Iran sets a world record by deporting 300,000 illegal refugees in 14 days

Brazilian Women Soccer Players (in Bikinis) Incredible Skills

Watch: Mexico City Protest Against American Ex-Pat 'Invasion' Turns Viole

Kazakhstan Just BETRAYED Russia - Takes gunpowder out of Putin’s Hands

Why CNN & Fareed Zakaria are Wrong About Iran and Trump

Something Is Going Deeply WRONG In Russia

329 Rivers in China Exceed Flood Warnings, With 75,000 Dams in Critical Condition

Command Of Russian Army 'Undermined' After 16 Of Putin's Generals Killed At War, UK Says

Rickards: Superintelligence Will Never Arrive

Which Countries Invest In The US The Most?

The History of Barbecue

‘Pathetic’: Joe Biden tells another ‘tall tale’ during rare public appearance

Lawsuit Reveals CDC Has ZERO Evidence Proving Vaccines Don't Cause Autism

Trumps DOJ Reportedly Quietly Looking Into Criminal Charges Against Election Officials

Volcanic Risk and Phreatic (Groundwater) eruptions at Campi Flegrei in Italy

Russia Upgrades AGS-17 Automatic Grenade Launcher!

They told us the chickenpox vaccine was no big deal—just a routine jab to “protect” kids from a mild childhood illness

Pentagon creates new military border zone in Arizona

For over 200 years neurological damage from vaccines has been noted and documented


Science/Tech
See other Science/Tech Articles

Title: 17,000 Macs infected with botnet controlled via Reddit
Source: [None]
URL Source: [None]
Published: Oct 4, 2014
Author: staff
Post Date: 2014-10-04 06:08:31 by Tatarewicz
Keywords: None
Views: 45

RT...

Russian security company Dr. Web has discovered a flaw in the Mac OS X, which enables hackers to control infected computers using a search service at Reddit. The company says at least 17,000 unique IPs have been hacked, mostly in the US.

Dr. Web security experts discovered several threats to the MAC OS X after conducting a check in September, the Russian company said in a statement on its website.

“One of them turned out to be a complex multi-purpose backdoor that entered the virus database as Mac.BackDoor.iWorm,” the statement reads.

It has not yet been determined how the malware spreads, but Russian experts say that once a Mac has been infected, the software establishes a connection with the command server.

“It is worth mentioning that in order to acquire a control server address list, the bot uses the search service at reddit.com, and – as a search query – specifies hexadecimal values of the first 8 bytes of the MD5 hash of the current date,” the security company said.

“The reddit.com search returns a web page containing a list of botnet C&C servers and ports published by criminals in comments to the post minecraftserverlists under the account vtnhiaovyd.”

image from http://st.drweb.com

"Criminals developed this malware using C++ and Lua. It should also be noted that the backdoor makes extensive use of encryption in its routines. During installation it is extracted into /Library/Application Support/JavaW, after which the dropper generates a p-list file so that the backdoor is launched automatically," the company added.

The Mac.BackDoor.iWorm is likely to send spam emails, flood websites with traffic, or mine bitcoins.

Dr. Web says 17,000 Macs were compromised by the botnet malware as of September 26. Most of them (4,610) were in the United States. Canada ranked second, with 1,235 comprised addresses, followed by the United Kingdom with 1,227 addresses.

Post Comment   Private Reply   Ignore Thread  



[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]