Feeds

'Mac worm' hacker in death threat farce

Much ado about malware

Internet Security Threat Report 2014

Claims by an anonymous author that he was paid to create a worm targeting Mac OS X systems are turning into a soap opera-style farce. Infosec Sellout said his 'Rape-OSX' worm uses an undisclosed vulnerability in the mDNSResponder component of Mac OS X to spread.

Low-threat malware targeting Mac OS X systems is unusual, but far from unprecedented. Claims that the supposed author of the worm is being paid to create proof-of-concept malware lack credibility or rationale, aside from creating mischief.

The original 15 July post on Infosec Sellout's blog, which has since been stripped of detail, said: "I wrote this for my own purposes and it will be demonstrated to those who asked me to engage in this work. Yes, I am being compensated for this (Hi, Joanna)."

The information security community is a small, almost exclusively male clique. The only Joanna of note is Joanna Rutkowska, founder of Invisible Things Lab, a noted security researcher who developed the Blue Pill rootkit to illustrate the security shortcoming of Windows Vista's anti-malware defences.

Rutkowska told eWeek that she doesn't know Infosec Sellout and certainly hasn't paid anybody to write worms.

Infosec Sellout was "identified" as LMH, someone associated with the Phrack High Council (PHC), on Cutaway Security's blog on 17 July, based on an anonymous chat-room conversation. PHC aims to cause grief to responsible white-hat hackers.

Whether this is true or not remains unclear, but soon after this Infosec Sellout's blog was "hacked", renamed "Security Information", and stripped of almost all its posts. One of the two posts left on the blog provides a link to information on the alleged worm, but none of them detail of the original post.

IDG reports that death threats were posted on the blog prior to the hack, adding further spice to an already heady mix.

Rape-OSX is looking more and more a work of mischief rather than mayhem. Perhaps we should thank Infosec Sellout for enlivening an otherwise dull week in information security with his gonzo-style pranks? ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
You dirty RAT! Hong Kong protesters infected by iOS, Android spyware
Did China fling remote access Trojan at Occupy Central?
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.