Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

June 1st, 2011, 16:59 GMT · By

Apple's Scareware Defense Already Bypased

SHARE:

Adjust text size:


New Mac Defender variant evades Apple's detection
Enlarge picture
The defense Apple has put in place against the latest scareware attacks targeting Mac users has already been bypassed by a modified version of the rogue software.

Since a few weeks ago, Mac users are being targeted by scammers who use scare tactics to convince them to install fake antivirus programs.

This type of applications have been around the Windows malware ecosystem for years and are collectively known as scareware or rogueware.

Because a lot of Mac users are not familiar enough with the techniques used by attackers, the number of victims for this sustained scareware campaign is pretty high.

While keeping silent about the incident at first, Apple eventually posted manual removal instructions for the rogue applications and released a security update which added detection for them to Mac OS X's XProtect feature.

The company also modified the update frequency for XProtect to daily in order to respond quicker to new variants. However, for experienced malware writers 24 hours is more than enough to adapt.

It only took the people behind this scareware campaign eight hours to make a variant of the rogue application that is not detected by Apple's XProtect signatures.

ZDNet reports that for the new variant the name of the installer was changed to Mdinstall.pkg and that just as with previous versions, it doesn't require an admin password to install itself.

It's always a cat and mouse game between malware writers and antivirus vendors and there will always be ways to temporarily evade detection. Because of this, user education is the best way to prevent infections.

Unfortunately, Apple not only has failed to educate users about malware threats, but even told them that Macs are virus-free. Users are strongly advised against downloading and installing software offered by websites they don't know and trust, regardless of what they claim.

TELL US WHAT YOU THINK:

1,470 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


AVAST Launches Beta Version of Free Mac Antivirus Product

Apple's Mac Anti-Scareware Update Is Insufficient

Mac Scareware Pushers Begin Targeting Facebook Users

Largest Russian Payment Processor Might Be Behind Recent Mac Scareware

New Mac Defender Variant Doesn't Require Admin Password

READER COMMENTS:


Comment #1 by: Eric on 01 Jun 2011, 19:11 UTC reply to this comment

I've always laughed at Mac's claim that their software is virus-free because anyone could see it was only a matter of time before virus writers started to invest in this fertile ground. Now Apple has shot themselves in the foot with what was simply a lie to begin with. The only thing that surprises me is that attacks on macs aren't already more popular. Hopefully Apple changes its stance and either includes some anti-virus software or encourages its users to get some basic protections...I doubt they will though, due to marketing...

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM