Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

November 6th, 2010, 11:29 GMT · By

Cross-Platform Boonana Trojan Gets New Version

SHARE:

Adjust text size:


Boonana trojan authors put out new versions
Enlarge picture
A new version of the Boonana trojan, which infects Windows and Mac OS computers alike, has been detected in the wild, suggesting that the malware is being actively developed and improved.

The trojan was discovered last week and functions as a Java applet. It was particularly designed to target Windows and Mac OS X users and gives attackers control over the compromised computers.

Boonana spreads through Facebook, where it uses social engineering to direct users to a fake YouTube page and trick them into running the Java applet.

"As you are on my friends list I thought I would let you know I have decided to end my life. For reasons that will be clear please visit my video on this site. Thanks for being by friend. :(" one of the used spam messages reads.

The trojan has multiple components. The propagation module hijacks Facebook session cookies from the local computer and uses them to send rogue messages from the associated accounts.

The comand and control component opens a connection to an IRC channel and allows attackers to perform various actions, such as launching DDoS, taking a screenshot from the compromised computer or downloading and executeing remote files.

Meanwhile, the main module connects to a remote server and downloads all of the other components, including an encrypted list of backup domains in case the main one goes down.

According to Graham Cluley, a senior technology consultant at Sophos, there have been several new Boonana variants detected since the trojan first came out, but they don't bring any new functionality.

What they do, is obfuscate the code in different ways in order to avoid detection. However, Mr. Cluley notes that the free Sophos Anti-Virus for Mac Home Edition is capable of blocking all of them.

Because of the cross-platform nature of Java, the trojan is also capable of running on other operating systems like Linux, Solaris or BSD.

However, on OSs other than Windows and Mac OS X, it's inoffensive, because the malicious code was not designed for these platforms.

TELL US WHAT YOU THINK:

1,709 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Linux Java-Based Trojan Might Have Been an Accident

New Koobface Variant Infects Linux Systems

Cross-Platform Attack Installs Trojan on Windows and Mac

READER COMMENTS:


Comment #1 by: sailor on 06 Nov 2010, 13:58 UTC reply to this comment

A couple of days ago I was suckered by the "...end my life..." story; and last evening and over-night during my routine weekly anti-malware scans (I use 4 programs) found 2 Trojans. I cannot too strongly recommend the use of multiple anti-malware software, since the first two missed the offending files.


Comment #2 by: Owen on 06 Nov 2010, 16:31 UTC reply to this comment

LOL "actively developed and improved."

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM