New Mac botnet malware uses Reddit to find out what servers to connect to?

Hi all,
I have come across these warnings over the last few days regarding a Mac botnet malware? The Independent published it
17,000 Macs recruited into malware botnet, with a little help from Reddit
Researchers at Russian anti-virus company Dr Web believe that they have uncovered a new botnet, which has recruited thousands of Mac computers. According to their report, the sophisticated malware – which they have dubbed Mac.BackDoor.iWorm – has infected more than 17,000 computers running OS X. Unfortunately, what isn’t presently documented is how the malware spreads – but the consequences can clearly be serious.Like any computers that have been recruited into a botnet, Macs that have been hijacked in this attack could have information stolen from them, further malware planted upon them, or be used to spread more malware or launch spam campaigns and denial-of-service attacks.Fascinatingly, compromised computers receive commands from servers under the control of botmasters, using information posted in messages on Reddit as a navigational aid:Then Mac.BackDoor.iWorm opens a port on an infected computer and awaits an incoming connection. It sends a request to a remote site to acquire a list of control servers, and then connects to the remote servers and waits for instructions.It is worth mentioning that in order to acquire a control server address list, the bot uses the search service at reddit.com, and — as a search query — specifies hexadecimal values of the first 8 bytes of the MD5 hash of the current date. The reddit.com search returns a web page containing a list of botnet C&C servers and ports published by criminals in comments to the post minecraftserverlists under the account vtnhiaovyd.
this is what one forum member on Reddit said.
'Basically, the worm installs itself to look like an application to the operating system and hooks into the automatic startup so that it will launch each time the computer is started.
Once it's running, it does an inventory of what applications you have installed.
It then goes out to reddit to find out where the current botnet command and control servers are located. It then connects to the command and control server to ask for instructions.
The likely reason it looks at the applications that are installed is so that it can use those applications to carry out the botnet's commands (e.g., use Mail to send spam as you.)'
another said
'it is a Trojan packed in a minecraft expansion or custom server or client. Exploiting the same flaw as the flashback worm from 2012."
'another saidUnfortunately, the security analysts fail to mention (or simply don’t know) how the virus is spreading into users’ Macs. Hopefully, this information comes to light soon so Mac users can know what to look out for. Once identified, Apple can add the virus to its security blacklists (which are refreshed nightly) to give some automatic protection to its user base.'
Anyone know about this and is there a way to detect it and then if it is present get rid?
http://9to5mac.com/2014/10/02/new-mac-botnet-malware-uses-reddit-to-find-out-wha t-servers-to-connect-to/
http://www.independent.co.uk/life-style/gadgets-and-tech/hackers-are-using-reddi t-to-control-17000-apple-computers-9773032.html
http://grahamcluley.com/2014/10/mac-malware-botnet-reddit/

seems it has been solved... found this on Mac Rumours
'In an effort to address the threat, Apple has now updated its "Xprotect" anti-malware system to recognize two different variants of the iWorm malware and prevent them from being installed on users' machines. '
'It has been discovered how the botnet is installed. You have to download a pirated app, such as Photoshop, and then give the pirated installer administrator privileges.
No amount of malware security can fix stupid.'
EDIT: Link to evidence: http://www.thesafemac.com/iworm-method-of-infection-found/ (http://www.thesafemac.com/iworm-method-of-infection-found/)'

Similar Messages

  • Using sar to find out what maxed cpu at 4am?

    Is it possible to use sar to find out what process maxed out a solaris 10 t5140 at 4am? Would I use sar for this or some other application such at dtrace? We have a few spikes that happened between 1am and 4am and I need to know what caused it.
    Any help is appreciated!
    thanks,
    Lucas

    I don't see sar doing this well.
    You could run a cron job to grab a 'ps' list at that time, or you could use 'dtrace' to give you a list of every program that executes during a period of time. Either might be good information.
    Darren

  • Mac Air 11" - how do I find out what files are showing up in "About this MAC" Storage "other" category?

    Hi - I am having storage trouble with my storage.  When I go into About this Mac, Storage, the category "Other" has a very large amount of gigs stored.  I have already dumped my email, downloads when in to Trahs, emptied secure trash, etc.  How do I find out what is included in the "other" category?

    First, empty the Trash if you haven't already done so.
    Use a tool such as OmniDiskSweeper (ODS) to explore your volume and find out what's taking up the space. You can delete files with it, but don't do that unless you're sure that you know what you're deleting and that all data is safely backed up. That means you have multiple backups, not just one.
    Proceed further only if the problem hasn't been solved.
    ODS can't see the whole filesystem when you run it just by double-clicking; it only sees files that you have permission to read. To see everything, you have to run it as root.
    Back up all data now.
    Install ODS in the Applications folder as usual.
    Triple-click the line of text below to select it, then copy the selected text to the Clipboard (command-C):sudo /Applications/OmniDiskSweeper.app/Contents/MacOS/OmniDiskSweeper
    Launch the Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Paste (command-V) into the Terminal window. You'll be prompted for your login password, which won't be displayed when you type it. You may get a one-time warning not to screw up. If you see a message that your username "is not in the sudoers file," then you're not logged in as an administrator.
    I don't recommend that you make a habit of doing this. Don't delete anything while running ODS as root. If something needs to be deleted, make sure you know what it is and how it got there, and then delete it by other, safer, means.
    When you're done with ODS, quit it and also quit Terminal.

  • Finding out what IP is connected to my network

    I set up a wireless device network from my mac and connected another wireless device to it.
    Is there a way, through my OSX that I can find out what IP the device is using on my mac's custom network?

    In terminal you can try:
    ifconfig en0 inet
    or:
    curl -s "http://www.whatismyip.com/automation/n09230945.asp"

  • How do I find out what app is connecting to the internet

    Something on my iPhone 4 (fully updated) is constantly trying to connect to the internet via 3G, costing me a lot of money when I am not connected via WLAN! I can't work out what it is, but presume it is an app. How can I find out what is doing it?
    I have tried deleting the cache, resetting the phone, etc. Nothing has worked. I even turned off 3G, cellular data, etc. and it STILL connected. How does that work?!
    Can anyone help?
    thank you!
    kind regards, Gordon

    thanks for the reply but are you sure about this? What difference would it make? Why 5 apps?
    Even if it does work, which I doubt, at some point, I will have to resync ALL my apps again and surely the same thing will happen again, and I will be none the wiser. I still won't know which app it is. There must be a way of finding this out.
    Any ideas?
    What is really freaking me out is how it is connecting to my carrier (who is charging me) with Cellular data switched off.......?
    Thanks again.

  • HT1918 how to use email to find out what u recently downloaded

    i used to get emails saying what i recently bought and downloaded and now i don't anymore. Is there any way i can change that?

    If you still cannot solve problem, call Apple account security department.
    http://support.apple.com/kb/HT5699

  • How can I use syslog to find out what websites my kids visit?

    I want to review what sites my kids have been visiting on their computers, from my computer. I know that the AirPort Extreme has a logging feature.
    First, at what level of logging do I set it so I can determine the sites they visit (5-Notice, 6-Informational, 7-Debug)?
    Second, How can I easily view the log from my MBP?
    I have already set up a DHCP reservation for my MAC address and applied that IP/MAC address reservation in the "Syslog Destination Address" box, under Logging & Statistics. I have already determined what MAC addresses are for each machine in our home. I'm guessing that the logs will show each MAC address and what sites it has visited, yes?
    Thanks in advance, c

    Thanks, we will read your articles.
    Hi,
    You might want to look at jhat/jmap - in particular
    jmap -histo might help you.
    More info here:
    http://weblogs.java.net/blog/mandychung/archive/2006/1
    2/java_se_6_monit.html
    Cheers,
    -- daniel
    JMX, SNMP, Java, etc...
    http://blogs.sun.com/jmxetc

  • How do I find out what application is  connected to my Nano (2nd Gen.)

    When I try to eject it it says "The iPod cannot be ejected because it contains files that are in use by another application."
    Does this happen to anybody else, and how do I find the other application so I can eject me iPod Nano (2nd Generation)?

    Are you playing a song in iTunes that listed in contents of iPod while it is connected. Try going to your music lib and play a song and disconnect your iPod.
    Also, make sure you are not located in some sub dir that utililizes iTunes.
    You can also hit 'ctrl,alt,delete' to see what applications are running on your PC.

  • How can I find out what email is connected to my apple ID account

    Trying to download an app onto my iphone but can't remember my password. tried to retrieve my password but nothing has been sent to my email. tried several times. is there anyway to see what email is connected to my apple ID account?
    I've tried all of them but my wife set up my phone and I'm lost. (it's not going to her email address either)
    help? I can't do anything with my phone without my apple ID password!
    (PS. Posting this from my son's account. As I cannot create one without my apple ID password. lol)

    None of my email addresses. Which makes me think it was entered incorrectly originally.
    When I tried to answer the security questions it asks my birthdate and then asks "answer your secret question"
    I have no idea what that question is. Lol. Like I said, my wide set this up with me and neither of us can remember what question was asked. It was a year ago.
    If I knew what email they sent my password to I could figure tho out and re set the password.

  • How can I find out what symbols are connected to any key+option combination?

    More speciffcaly, is there a way to get the greek letter alpha? I do a lot of work in higher education and this symbol keeps eluding me.

    In many apps, Edit > Special Characters will bring up the Character Viewer.  Click on the gear wheel at the top left and choose Customize to add categories if you do not see what you want at first.  Drag/drop or double-click to input.
    I don't think you can input α from the keyboard unless you activate a Greek keyboard layout, which is probably not worth the trouble.

  • How do i find out what cabinet im connected to?

    Is there a website where I can enter my postcode or house no. and post code? And get a google maps view?

    You can e-mail [email protected], they will sometimes provide your cabinet number for you. They did for me though they haven't for some people, the mods will also be able to get the information for you.
    If this helped you please click the Star beside my name.
    If this answered your question please click "Mark as Accepted Solution" below.

  • Find out what servers have a SCOM agent installed

    Hello, 
    With a list of approx 1400 servers, I am after a quick way to see which ones have SCOM agent installed on them? 
    This is over one domain . 
    Thanks in advance
    Tubble with Microsoft

    You can get all servers with SCOM agents and export to a CSV fileGet-Agent | select-object PrincipalName,ComputerName,Domain | export-csv c:\allServerlist.csv
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical

  • I transferred excell spreadsheet from my old pc to my new mac. I used it last fortnight but now cannot find it. Any Help please.

    I transferred excell spreadsheet from my old pc to my new mac. I used it last fortnight but now cannot find it. Any Help please.
    I have tried Spotlight but to no avail I have an Imac.
    gp140

    The file should still be listed by name under, "Open Recent."

  • Data transfer: ext hard drive to new Mac with Mavericks using Time Machine

    Data from old computer is on ext hard drive. I delayed transfer to new Mac. Now using Migration Assistant bit I don't know if it is working or just hung up. It shows 'looking for other sources' for over an hour. Please advise.

    In general, most people will recommend Carbon Copy Cloner or SuperDuper! You can find either one easily enough with a web search.
    However, in your case, I imagine you are going to have a hard disk returned to you all by itself, and you will need to install it in an enclosure. Don't let that bother you as this is easy to do and the enclosures are not expensive ($40 or so).
    Once that is done, I would recommend you set up your brand new Mac by answering all the questions during initial setup as usual. Be sure to use your correct Apple ID - probably the same one you used to log into this support forum. When you reach the point in which it asks you if you would like to transfer your old documents and settings, connect the old hard disk and select it as the source. It will take some time as it copies all its contents to your new Mac. All your familiar items will be exactly as they were on the failed Mac.
    After that, you can use the old hard disk as a Time Machine backup. When you are satisfied everything on your new Mac is running as it should, go ahead and erase the old disk. Then, tell Time Machine to designate it as a backup, and the rest is automatic.

  • I am trying to connect my old mac desktop and my mac book pro to my new mac desktop to use as monitor but it will not work??

    I am trying to connect my old mac desktop and my mac book pro to my new mac desktop to use as monitor but it will not work??

    Hi ashleydanc588,
    If you are interested in more information on using an iMac in Target Display Mode, including what machines are compatible, you may find the following article helpful:
    Target Display Mode: Frequently Asked Questions (FAQ)
    http://support.apple.com/kb/ht3924
    Regards,
    - Brenden

Maybe you are looking for

  • Qosmio G20: Media Centre Receiver issue - Recovery question

    As abvoe really, I usually leave my computer running overnight and yesterday I went on it to find that I had 80mb of hard drive space left (60 gig hard drive). Error messages had been popping up and a record of these was saved in the pchealth folder,

  • FS10N transaction

    Hi , i did XREF1, XREF2 and XREF3 available (GL account available ) in the system in the Transactions OB32, OB41 , OBC4 and also in Define special fields for line item display. But actually i was trying to display it in transaction FBL3n changing the

  • Is it possible to trigger an interface automatically based on an event?

    Hi,    What are the settings needed to make sure that an outbound interface will be triggered automatically whenver an event occurs? In my case, whenever an invoice gets fully paid, an outbound interface should be triggered automatically. Is it possi

  • Bought a TV season and only some episodes downloaded where remaining had "download error" on iPad 1

    Bought a TV season and only some episodes downloaded where remaining had "download error" on iPad 1? Tried many times for few days with no use. Tried restarting too. Device has enough memory too!

  • Problem report with no problem

    I've made an additional discovery about this problem and I've amended my original post below: For some unknown reason, after I save my Premiere Pro CC project and "Quit", I get a "Problem Report" that "Adobe Premiere Pro CC has quit unexpectedly." Th