The malicious code is being distributed from a hacker Web site, where there have been discussions on distributing the Trojan through iChat and LimeWire, said SecureMac, which has given the Trojan a "critical" security rating. The program can infect Mac OS X 10.4 and 10.5 machines.
Besides offering a hacker remote access to the system, the Trojan discovered by SecureMac can transmit system and user passwords. Additionally, the application can log keystrokes, take pictures with the built-in camera on a Mac, take screenshots, and turn on file sharing.
The program takes advantage of a flaw within the Apple Remote Desktop Agent. The program avoids detection by opening ports in the firewall and turning off system logging.
The Trojan is distributed as AppleScript called Asthtv05 or as an application bundle called Astht_v06. The filed must be downloaded and opened in order to infect a machine.
Malicious code targeting the Mac isn't new. Apple in May released a patch for a serious vulnerability within its iCal calendar application. The flaw made it possible for an attacker to exploit the vulnerability by adding or modifying files on a CalDAV server. The code is distributed as an .ics calendar file in an e-mail attachment, or through a malicious Web site.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.