Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

DNS malware roots Macs

Beware of the codec.

Article comments

A new Trojan horse malware called OSX.RSPlug.A specifically targets Mac users, according to security firm Intego.

The Trojan is a form of DNSChanger that changes the Mac's Domain Name Server (DNS) address. According to Intego, the Trojan has been found on several pornographic websites. When trying to view a movie, the user is told that "Quicktime Player is unable to play movie file. Please click here to download new version of codec."

When the user clicks the link a disk image (.dmg) is downloaded to the desktop. When the user installs the software, they are actually installing the Trojan, not a free video codec. The Trojan is installed with full root privileges, which means it has access to all files and commands on the system.

When the malicious DNS server is active, it hijacks some web requests, leading users to phishing sites (for sites such as eBay, PayPal and some banks) or to pages displaying ads for other pornographic sites, according to Intego.

The Trojan also installs a root crontab which checks every minute to ensure that its DNS server is still active, the company said. Since changing a network location could change the DNS server, this cron job ensures that, in such a case, the malicious DNS server remains the active server.

Intego said that using Mac OS X 10.4, there is no way to see the changed DNS server in the operating system's interface. Under Mac OS X 10.5, this can be seen in the Advanced Network preferences; the added DNS servers are dimmed, and cannot be removed manually.


More from Techworld

More relevant IT news


ShootnHooton said: The danger to Mac users is that the Mac OS is so hidden that getting rid of any virus is nigh an impossibility

dev said: about time they targeted mac users - maybe all us PC users will get a bit of slack now eh

Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *