New type of Mac malware in the wild, security experts warn

Nov 2, 2011 09:59 GMT  ·  By

Mac users looking to stay out of harm’s way may have taken notice of a new blog entry by Intego, "the Mac security specialist", whose VirusBarrier X6 has been trained to detect a new type of malware that’s doing the rounds as of late.

Although documented by several security companies already, of which Intego was one of the first to file a report, DevilRobber.A is described as a new type of malware that combines the traits of a Trojan horse with backdoor elements, and it’s also a ‘stealer’, according to their advisory.

“This malware, which has been found in several applications distributed via BitTorrent trackers, steals data and Bitcoin virtual money, and uses CPU and GPU time on infected Macs to perform ‘Bitcoin mining’, says the Austin, Texas-based security firm.

The advisory continues: “This malware is complex, and performs many operations. It is a combination of several types of malware: it is a Trojan horse, since it is hidden inside other applications; it is a backdoor, as it opens ports and can accept commands from command and control servers; it is a stealer, as it steals data and Bitcoin virtual money; and it is a spyware, as it sends personal data to remote servers.”

Intego also says the malware is spreading: “DevilRobber has been found in a small number of Mac applications that are distributed via BitTorrent trackers, including a popular graphic program.”

The lengthy advisory continues with details about the nefarious purpose of the malware, as well as its modus operandi. It ends with the usual piece of advice: install antivirus software.

Intego says its VirusBarrier X6 software has had its threat filters updated with the definitions to recognize this type of malware, therefore the program will keep you protected if you somehow manage to get infected.