Newest MacDefender scareware installs without a password
Criminals 'give Apple the finger,' says security researcher, by releasing new version just hours after Apple warned of fake AV software
Computerworld - Hours after Apple owned up to a fake security software scam campaign, the "scareware" gang released a new variant, with a new name and a streamlined installation process that doesn't prompt victims for their password, a French antivirus firm said today.
"Given the timing, and the new name, it does seem like this was their reaction to Apple's support document," said Peter James, a spokesman for Intego, a maker of Mac-specific security software.
On Tuesday, Apple acknowledged the threat posed by what security experts call "scareware" or "rogueware." bogus security software that claims a computer is heavily infected with worms, viruses and other malware. Once installed, such software nags users with pervasive pop-ups and fake alerts until they fork over a fee to purchase the worthless program.
Apple also said it would update Mac OS X, adding the ability of the operating system to detect and delete the MacDefender scareware.
The group responsible for MacDefender -- and other earlier variants named MacProtector and MacSecurity -- must have read the news, said James.
"They changed the name to MacGuard, and released it today, maybe just to give Apple the finger," James said.
The cyber criminals also changed the way they distribute the fake security program, breaking it into two parts: a small downloader, dubbed "avRunner," which once on a Mac reaches out to a hacker-controlled site to download the phony MacGuard security software.
But the new version also includes a more important twist.
"Unlike the previous variants, no administrator password is required to install the downloader," said James. "People will still see an installer screen -- [the attackers] haven't gotten to the point where they're completely avoiding that yet -- but all one needs to do to install is click 'OK' a couple of times. So it's one less hurdle."
avRunner sidesteps the need for an administrator password by putting itself directly in the Applications folder of a victimized Mac. Unlike a legitimate installer package -- or an illegitimate one for that matter -- putting an executable in the Applications folder doesn't require a password when the user is the administrator.
With avRunner safely added to the Applications folder, it then grabs MacGuard from a remote server.
"A lot of the comments on blogs said 'Stupid Apple users, it's their own fault' because they were entering their [administrator] password," said James. "[The hackers] are now saying, 'Well, we don't even need to get a password.'"
James said that clues in the scareware point to Eastern European or Russian hackers as behind the MacDefender/MacGuard campaign. Last week, Microsoft's malware engineers found links between the Mac scam and a fast-growing one that targets Windows users, and concluded that the same gang is responsible for both.
"These are smart people," said James. "There's nothing new here that Windows users haven't seen, but this group has a couple of very good Mac developers."
Mac users running Safari can stop avRunner from automatically opening its installer screen by unchecking the box marked "Open 'safe' files after downloading" at the bottom of the General tab in the browser's Preferences screen.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is firstname.lastname@example.org.
- Apple hands stock worth $12.1M to top execs in retention deal
- Hands on: Apple's Mac Pro is the fastest Mac ever
- Apple CFO to retire in September after he cashes in $53M stock award
- Apple's CarPlay to spark mobile apps war in your car
- Apple retires Snow Leopard from support, leaves 1 in 5 Macs vulnerable to attacks
- Apple patches critical 'gotofail' bug with Mavericks update
- Why Apple needs a $700 MacBook Air
- Apple takes top spot in brand value computation
- Apple gets a patent for health-monitoring ear buds
- Apple shifts to hardware-first TV strategy with revamped set-top box
Read more about Security in Computerworld's Security Topic Center.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
Red Hat Enterprise Linux - The Original Cloud Operating System
Linux adoption is growing against a number of measures, such as the
number of supercomputers that run Linux and the size of the contributing...
- What Datapipe customers need to know about the new PCI DSS 3.0 compliance standard This handy quick reference outlines what PCI DSS 3.0 is, who needs to be compliant and how Alert Logic solutions address the new...
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Partners in Mobile Device Management: AirWatch & CDW When it comes to Mobile Device Management, it's not just what you know. It's who you know. That's why CDW partners with industry...
- Four Myths of High-Productivity App Dev Debunked Debunk the main myths surrounding high-productivity application development and how both platforms have overcome them.
- Redefine Your IT Operations: Remote Office IT Has Never Been Simpler Join us to see why PC Pro named Dell PowerEdge VRTX the "2013 Server of the Year." PowerEdge VRTX may be just what... All Operating Systems White Papers | Webcasts