Apple Increases Mac OS X Malware Protection
Defenses against the HellRTS Trojan were included -- but not documented -- in the Mac OS X 10.6.4 update this week.According to antivirus vendor Sophos, Apple this week, in an undocumented move, tweaked its OS X malware defenses.
In particular, OS X 10.6.4 now provides better protection against a Trojan application called HellRTS, aka Pinhead-B, which has been turning up in fake iPhoto software being circulated by attackers.
More Hardware Insights
Webcasts
- SMB Server Guide: Meeting Email, Virtualization, and Business Application Challenges
- Protecting End Users Against Emerging Threats
White Papers
- How To Build a Mission-Critical Data Center
- ComputerWorld Tech Dossier: HP ProLiant DL360p & DL380p Gen8 Severs: Power, Flexibility & Serviceability
Reports
- How To Build a Mission-Critical Data Center
- Virtually Protected: Key Steps To Safeguarding Your VM Disk Files
"This Trojan can give hackers the green light to send spam e-mail from your computer, take screenshots of what you are doing, access your files and clipboard, and much, much more," said Graham Cluley, senior technology consultant at Sophos, in a statement. "But what's curious to me is why Apple didn't announce they were making this update in the release notes or security advisory that came with Mac OS X 10.6.4. It's almost as if they don't want to acknowledge that there could be a malware threat on Mac OS X."
Despite the existence of HellRTS, which first hit the scene in April, and is a variant of a Trojan first seen in 2004, is there really a clear and present malware threat to Apple's OS X?
Late last year, Symantec predicted that the amount of malware aimed at Mac OS X would continue to increase. In its report predicting security trends for 2010, Symantec wrote: "In 2009, we saw Macs and smartphones targeted more by malware authors, for example the Sexy Space botnet aimed at the Symbian mobile device operating system and the OSX.Iservice Trojan targeting Mac users. As Mac and smartphones continue to increase in popularity in 2010, more attackers will devote time to creating malware to exploit these devices."
But if the primary, if not sole, impetus for creating malware is to steal people's personal information for financial gain -- typically by selling that information to others or using purloined credentials to literally steal cash -- is an operating system with roughly 5% market share screaming "hack me" to potential attackers?
"It's true to say that there are far, far fewer malware threats for Mac than there are for Windows -- but that doesn't mean the problem is non-existent. Unfortunately, many Mac users seem oblivious to security threats which can run on their computers, even though Apple has now built in some elementary protection," said Cluley. "This lack of awareness isn't helped when Apple issues an anti-malware security update by stealth, rather than informing the public what it has done."
Black Hat USA 2010 presents a unique opportunity for members of the security industry to gather and discuss the latest in cutting-edge research. It happens July 24-29, in Las Vegas. Find out more and register.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- SMB Server Guide: Meeting Email, Virtualization, and Business Application Challenges
- Powering your Business with IBM's New 2s General Purpose Servers
- Protecting End Users Against Emerging Threats
- Best Practices in SMB Desktop Virtualization
- CTO to CTO: Scott Davies, VMware, and Jim Davies, Mitel, Give Voice to the Virtual Desktop
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
- Enterprise Strategy Group: The Next Wave of Data Deduplication
- Gartner Presentation: Data Center conference Real Fabrics for a Virtual World
- Nemertes Research PilotHouse Awards: Servers for Virtualization
- Virtualizing Tier 1 Applications: A Critical Step on the Journey Toward the Private Cloud
- The Hidden Truth About Virtualizing Business-Critical Applications
Featured Broadcast
In his book, The New Know: Innovation Powered by Analytics, Thornton May suggests that the key to business success is discovering truth and value from overwhelming amounts of data. This excerpt summarizes 10 fundamental realities for organizations moving forward.
Learn More












