Mac Botnet Now 600,000 Infected Machines Strong

  /     /     /  
Publicated : 22/11/2024   Category : security


Mac Botnet Now 600,000 Infected Machines Strong


Apple has issued a patch for its version of Java, but critics say it should have acted sooner to contain a trojan variant called Flashback, which has infected an estimated 1% of all Macs.



10 Key Steve Jobs Moments and Innovations (click image for larger view and for slideshow)
Apple earlier this week released
an update
for its version of Oracles Java software to limit the spread of a Flashback trojan variant that has already infected over 600,000 Macs.
Russian security company Dr. Web said on Wednesday that it estimates
over 600,000 Macs have been hijacked
by the malware and joined in a
botnet
. About half of the infected computers are located in the U.S., the company said, and about 20% are located in Canada.
F-Secure chief research offiicer Mikko Hypponen via Twitter observed that with an installed base of about 45 million Macs, Flashback appears to have infected about 1% of the Macs out there, making it comparable in terms of reach to the Conficker malware in the Windows world.
The Flashback trojan is able to take over computers by exploiting vulnerabilities in Java. Visiting or being directed to a compromised website might allow the malware to take over your Mac. The malware relies on JavaScript code to load a malicious Java applet. Disabling Java--via ones Web browser security settings or via the Java Preferences file likely to be found in Applications/Utilities/--should protect against this particular threat.
[ Read
Apple Investigating New iPad Wi-Fi Problem
. ]
Dr. Web
says
that attackers first began using the CVE-2011-3544 and CVE-2008-5353 vulnerabilities in February, and then moved to another vulnerability, CVE-2012-0507, in March.
Apple often has been criticized for not responding fast enough to security vulnerabilities and this incident shows the tradition continues. Security reporter Brian Krebs
notes
that [Apples] lackadaisical (and often plain puzzling) response to patching dangerous security holes perpetuates the harmful myth that Mac users dont need to be concerned about malware attacks.
Oracle
patched CVE-2012-0507
in February. However, Apple distributes its own version of Java, previously bundled with OS X and presently as an optional download in Lion (OS X 10.7).
Apple
used to claim
, Mac OS X isnt plagued by constant attacks from viruses and malware because the operating system was designed with security in mind. It has since qualified its assertions about security and
now states
, A Mac isnt susceptible to the thousands of viruses plaguing Windows-based computers.
Even that statement appears to be questionable given that software such as Oracles Java, Adobes Flash, and Apples own iTunes--all of which have had publicly exploited vulnerabilities--can be found on both Mac and Windows machines.
Most external hacks of databases occur because of flaws in Web applications that link to those databases. In this report,
Protecting Databases From Web Applications
, well discuss how security teams, database administrators, and application developers can work together to improve the defenses of both front-end Web applications and back-end databases to prevent these attacks from succeeding. (Free registration required.)

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Mac Botnet Now 600,000 Infected Machines Strong