Feeds

New Mac scareware variant installs without password

Welcome to the world, fanbois

Designing a Defense for Mobile Applications

Scammers have developed a strain of Mac scareware that avoids the need to trick a mark into entering an administrative password.

Earlier rogue anti-virus strains, such as MacDefender, need permission to run, a hurdle MacGuard neatly sidesteps. MacGuard works on the premise that home users have administrator rights, meaning they don't need to enter the administrator password to install software in the Applications folder.

MacGuard downloads itself into this folder rather than the default download folder. This downloader connects to malicious IP addresses hidden in its own resources folder. The appearance of the malware means that advice to treat all unexpected requests for the administrator password with suspicion becomes moot. "This is not the sky falling, but it does change the game somewhat," writes anti-malware researcher David Harley.

Mac security specialist Intego reports that MacGuard, which it describes as a variant of MacDefender, is being distributed via various portals offering fake security scans. These portals are getting promoted through search engine manipulation. Intego has a write-up of the scam here.

After advising support staff not to help users who might be infected by MacDefender for at least a fortnight, Apple rethought its position and posted an advisory on dealing with the malware on Tuesday. Part of its advice – to cancel the installation process and not to enter admin passwords – has been rendered redundant by the arrival of MacGuard.

Sophos has charted the evolution of Mac-specific malware which it reckons is "advancing fast and taking many cues from the Windows malware scene" in a blog post here. ®

Boost IT visibility and business value

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Chrome browser has been DRAINING PC batteries for YEARS
Google is only now fixing ancient, energy-sapping bug
Do YOU work at Microsoft? Um. Are you SURE about that?
Nokia and marketing types first to get the bullet, says report
Microsoft takes on Chromebook with low-cost Windows laptops
Redmond's chief salesman: We're taking 'hard' decisions
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
EU dons gloves, pokes Google's deals with Android mobe makers
El Reg cops a squint at investigatory letters
Big Blue Apple: IBM to sell iPads, iPhones to enterprises
iOS/2 gear loaded with apps for big biz ... uh oh BlackBerry
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.