Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

June 8th, 2011, 13:58 GMT · By

New MacShield Variants Spotted in the Wild

SHARE:

Adjust text size:


The Mac scareware development continues
Enlarge picture
Three new variants of the MacShield scareware were identified today, suggesting that Apple's efforts so far haven't discouraged Mac malware development.

"F-Secure Labs located three new samples today, and added detection for today's in-the-wild versions of MacShield," Sean Sullivan, security advisor at the Finnish antivirus vendor announced on Twitter.

The volume of new Mac scareware has increased and so has the number of distribution vectors.

At first, there were Google Images black hat search engine optimization campaigns. Then the malware distributors switched to Facebook.

It's not certain if the new variants bypass Apple's XProtect blacklist, but that that's a very likely possibility given the technology works by comparing hashes.

This goes to show that reactive solutions like XProtect, even if updated daily, are not enough to keep users safe.

Scareware applications ask users to acquire a license key in order to resolve fictitious problems on their computers, usually malware infections. In other words, they use scare tactics to achieve their goal.

In most cases, until Apple has a chance to update XProtect in order to deal with new variants, cyber criminals already have their victims' money.

Users need a full-featured security product that offers layered protection. For example, antivirus programs contain web filters that block users from accessing scareware distribution sites in the first place.

But if a site is very new and the web filter doesn't know about it, an antivirus product can still leverage heuristic signatures to identify new variants of a certain threat.

"Our original 'MacDefender' detection was generic enough to catch Friday's 'MacShield' variant w/out needing an update," said Sean Sullivan, referring to a variant that appeared last week.

"Although someone may say that MacDefender itself is not a dangerous threat, it's a good reminder about the need to keep attention to security matters - which a lot users have forgotten about.

"Definitely simple checksum matching, which Apple use, is not a full substitute for a quality AV product," Ondrej Vlcek, chief technology officer at AVAST Software said. His company is currently beta testing a free Mac antivirus product which is expected to ship soon, but there are already other free solutions on the market as well.

TELL US WHAT YOU THINK:

2,051 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Apple's Cat-and-Mouse Game with Scareware Authors Continues

Apple's Scareware Defense Already Bypased

Apple's Mac Anti-Scareware Update Is Insufficient

Mac Scareware Pushers Begin Targeting Facebook Users

New Mac Defender Variant Doesn't Require Admin Password

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM