Apple admits Mac scareware infections, promises cleaning tool
After taking heat for not helping users, Apple takes major step by owning up to security problems in Mac OS, says expert
Computerworld - Apple on Tuesday promised an update for Mac OS X that will find and delete the MacDefender fake security software, and warn still-unaffected users when they download the bogus program.
The announcement -- part of a new support document that the company posted late Tuesday -- was the company's first public recognition of the threat posed by what security experts call "scareware" or "rogueware."
"In the coming days, Apple will deliver a Mac OS X software update that will automatically find and remove Mac Defender malware and its known variants," Apple said in the document. "The update will also help protect users by providing an explicit warning if they download this malware."
Apple also outlined steps that users with infected Macs can take to remove the scareware.
Andrew Storms, director of security operations with nCircle Security, was surprised that Apple said it would embed a malware cleaning tool in Mac OS X.
"That's new ground for Apple," Storms said, pointing out that the move is a first for the company, which until now has only offered a bare-bones malware detection mechanism in Mac OS X 10.6, aka Snow Leopard, and then only populated it with a handful of signatures.
"Not only is Apple going to help customers remove [Mac Defender], but by doing so, they're also admitting that there are security problems with Mac OS," Storms said.
MacDefender -- which also goes by names such as MacProtector and MacSecurity -- first popped up earlier this month when French security company Intego said it had found the scareware in the wild.
Scareware and rogueware are terms for bogus security software that claims a personal computer is heavily infected with worms, viruses and other malware. Once installed, such software nags users with pervasive pop-ups and fake alerts until they fork over a fee to purchase the worthless program.
MacDefender was the first piece of professional-looking scareware to target Macs.
Last week, Microsoft said it had found evidence in MacDefender that the fake program was created by the same group responsible for a fast-growing scareware family aimed at Windows users.
"That shouldn't have surprised anyone," Storms said today. "Why should the hackers reinvent the wheel?"
Apple has taken criticism for not publicly responding to the MacDefender threat.
In several posts over the last week, ZDNet blogger Ed Bott -- who usually covers Microsoft and Windows topics -- laid out information he had received from insiders at Apple support.
Those tech support representatives told Bott, and provided documents, that said Apple had told them not to help Mac users who had been duped into downloading and installing MacDefender.
Both Intego and U.K.-based Sophos have used the information Bott has published and his estimates of the number of Macs infected to also take Apple to task.
"Apple's famous PR savvy apparently doesn't apply to handling security incidents," Chet Wisniewski, a Sophos security researcher, said in a post on his company's blog on Tuesday. "It is genuinely tragic that such a large number of OS X users are falling victim to this scam, and Apple's response is less than helpful."
Intego sells Mac-specific security software, and Sophos offers a free Mac antivirus program.
"What this shows is that nobody is safe," Storms said. "The truth is that the vast majority of malware isn't on the Mac, it's not on the iPhone, it's specifically on Windows."
"I say that's because of Windows market share, but Mac users have long claimed that it's because Mac OS is more secure, or Mac users are more intelligent and don't fall for these ruses," he said. "Well, guess what, this proves the point that it doesn't matter what OS you're using. In the end, it all depends on the user to understand what's malware and what's not."
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is email@example.com.
- Apple hands stock worth $12.1M to top execs in retention deal
- Hands on: Apple's Mac Pro is the fastest Mac ever
- Apple CFO to retire in September after he cashes in $53M stock award
- Apple's CarPlay to spark mobile apps war in your car
- Apple retires Snow Leopard from support, leaves 1 in 5 Macs vulnerable to attacks
- Apple patches critical 'gotofail' bug with Mavericks update
- Why Apple needs a $700 MacBook Air
- Apple takes top spot in brand value computation
- Apple gets a patent for health-monitoring ear buds
- Apple shifts to hardware-first TV strategy with revamped set-top box
Read more about Endpoint Security in Computerworld's Endpoint Security Topic Center.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Review: Box beats Dropbox - and all the rest - for business Box trumps Dropbox, Engyte, Citrix ShareFile, EMC Syncplicity, and OwnCloud with rich mix of file sync, file sharing, user management, deep reporting and...
- Analyst Report-Mixed All Flash Arrays Delivers Safer Higher Performance What is the impact of an all-flash array with enterprise features and reliability on the mainstream data center? In the mainstream environment, storage...
- Embracing Flash Storage Exec Brief Flash storage can deliver impressive performance, especially for random I/O, by eliminating rotational and seek latencies that are common in all hard disk...
- Embracing Tiered Storage Exec Brief All data is not created equal and thus all data need not be treated the same by the storage system. IT executives must...
- Four Myths of High-Productivity App Dev Debunked Debunk the main myths surrounding high-productivity application development and how both platforms have overcome them.
On-Demand Webcast: 7 Reasons to Choose VoIP
Thinking about a new phone system for your business?
Be sure to watch this informative webcast. Steve Strauss, small business columnist for USA...
All Endpoint Security White Papers |