{"id":17690,"date":"2012-10-16T22:25:55","date_gmt":"2012-10-17T02:25:55","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-08-08T16:59:40","modified_gmt":"2021-08-08T20:59:40","slug":"a-history-of-mac-malware-part-2","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/a-history-of-mac-malware-part-2\/","title":{"rendered":"A History of Mac Malware: Part 2"},"content":{"rendered":"<p><a href=\"https:\/\/web.archive.org\/web\/20150131151730\/http:\/\/www.tuaw.com\/2012\/07\/11\/malware-affecting-macs-running-older-versions-of-os-x\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-101648\" title=\"A History of Mac Malware: Part 2\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/mac_sick.jpg?resize=110%2C145&#038;ssl=1\" alt=\"A History of Mac Malware: Part 2\" width=\"110\" height=\"145\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/mac_sick.jpg?resize=114%2C150&amp;ssl=1 114w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/mac_sick.jpg?resize=57%2C75&amp;ssl=1 57w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/mac_sick.jpg?w=220&amp;ssl=1 220w\" sizes=\"auto, (max-width: 110px) 100vw, 110px\" \/><\/a><a title=\"Graham Cluley\" href=\"http:\/\/nakedsecurity.sophos.com\/author\/gcluley\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Graham Cluley<\/strong><\/a> at <a title=\"Sophos\" href=\"https:\/\/www.sophos.com\" target=\"_blank\" rel=\"noopener noreferrer\">Sophos<\/a> recently <a title=\"The short history of Mac malware: 1982 - 2011\" href=\"https:\/\/nakedsecurity.sophos.com\/2011\/10\/03\/mac-malware-history\/\" target=\"_blank\" rel=\"noopener noreferrer\">wrote<\/a> an excellent <strong>history of Apple Macintosh<\/strong> malware. He points out that Mac malware is a subject that raises strong emotions. There are some who believe that the problem is over-hyped and others who believe that the malware problem on Macs is underestimated by the Apple-loving community. The author writes that hopefully, this short history will go some way to present the facts and encourage sensible debate. <em>(rb- We have just taken on a new customer which is 85% Mac and 15% PC. I have had this very conversation with my Apple certified tech who does the field support.)<\/em><\/p>\n<p><em><a title=\"A History of Mac Malware: Part 1\" href=\"https:\/\/wp.me\/p2wgaW-2Kk\" target=\"_blank\" rel=\"noopener\">Click here<\/a> to read part 1 of the History of Mac Malware.<\/em> <em><a title=\"First PC Virus Creators Found\" href=\"https:\/\/wp.me\/p2wgaW-1VJ\" target=\"_blank\" rel=\"noopener noreferrer\">Click here<\/a> to read my recent series commemorating the 25th anniversary of the computer virus.<\/em><\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20240415214827\/https:\/\/www.sophos.com\/en-us\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101650 size-full\" title=\"Sophos logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Sophos_Logo-1.gif?resize=120%2C49&#038;ssl=1\" alt=\"Sophos logo\" width=\"120\" height=\"49\" \/><\/a>Big changes to the Mac malware scene arrived with the release of Mac OS X &#8211; a whole new version of the operating system which would mean that much of the old malware would no longer run. All future, Mac-specific malware would have to be written with a new OS in mind.<\/p>\n<p><strong>2004<\/strong> &#8211; The <a title=\"SH\/Renepo-A\" href=\"https:\/\/web.archive.org\/web\/20201030082801\/https:\/\/www.sophos.com\/en-us\/threat-center\/threat-analyses\/viruses-and-spyware\/SH~Renepo-A\/detailed-analysis.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Renepo script worm<\/a> (also known as &#8220;Opener&#8221;) attempted to disable Mac OS X security including the Mac OS X firewall. The author reports that the Renepo worm would download and install hacker tools for password-sniffing and cracking, make key system directories world-writable, and create an admin-level user for hackers to later abuse.<\/p>\n<p><a href=\"https:\/\/www.facebook.com\/AccessComputing\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-113771\" title=\"Renepo script worm\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/malware4-1.jpg?resize=100%2C96&#038;ssl=1\" alt=\"Renepo script worm\" width=\"100\" height=\"96\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/malware4-1.jpg?resize=150%2C144&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/malware4-1.jpg?resize=75%2C72&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/malware4-1.jpg?w=300&amp;ssl=1 300w\" sizes=\"auto, (max-width: 100px) 100vw, 100px\" \/><\/a>In 2004, hackers also wrote a proof-of-concept program called Amphimix which demonstrated how executable code could be disguised as an MP3 music file on an\u00a0<a title=\"Apple Computers\" href=\"http:\/\/www.apple.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Apple<\/a> (<a title=\"NASDAQ : AAPL\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-AAPL\/\" target=\"_blank\" rel=\"noopener noreferrer\">AAPL<\/a>) Mac. Amphimix appeared to been written as a proof-of-concept highlighting a vulnerability in <a title=\"Apple Inc.\" href=\"http:\/\/en.wikipedia.org\/wiki\/Apple_Inc.\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">Apple&#8217;s<\/a> software.<\/p>\n<p><strong>2006 &#8211; <\/strong>The first virus for Mac OS X was discovered in 2006. <a title=\"Leap-A malware: what you need to know\" href=\"http:\/\/web.archive.org\/web\/20130303122543\/http:\/\/www.macworld.com:80\/article\/1049459\/leapafaq.html\" target=\"_blank\" rel=\"noopener noreferrer\">OSX\/Leap-A<\/a> was designed to use the <a title=\"Apple\" href=\"http:\/\/www.forbes.com\/companies\/apple\/\" target=\"_blank\" rel=\"noopener noreferrer\">Apple<\/a> <a title=\"IChat\" href=\"http:\/\/www.apple.com\/macosx\/what-is-macosx\/ichat.html\" target=\"_blank\" rel=\"homepage noopener noreferrer\">iChat<\/a> instant messaging system to spread itself to other users. As such, it was comparable to an email or instant messaging worm on the Windows platform.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20150130192013\/http:\/\/www.tuaw.com\/2005\/05\/13\/jason-snell-chats-up-ichat\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101653 \" title=\"iChat\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/apple_ichat_icon.jpg?resize=65%2C65&#038;ssl=1\" alt=\"iChat\" width=\"65\" height=\"65\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/apple_ichat_icon.jpg?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/apple_ichat_icon.jpg?w=127&amp;ssl=1 127w\" sizes=\"auto, (max-width: 65px) 100vw, 65px\" \/><\/a>The author concludes that it was correct to call OSX\/Leap-A a virus or a worm. It was not correct to call OSX\/Leap-A a <a title=\"Trojan horse (computing)\" href=\"http:\/\/en.wikipedia.org\/wiki\/Trojan_horse_%28computing%29\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">Trojan horse<\/a>. Not that that stopped many in the Mac community claiming it wasn&#8217;t a real virus.<\/p>\n<p title=\"Badbunny (computer worm)\"><strong>2007 &#8211; <\/strong> Sophos discovered an <a title=\"OpenOffice.org\" href=\"http:\/\/www.openoffice.org\" target=\"_blank\" rel=\"homepage noopener noreferrer\">OpenOffice<\/a> multi-platform macro worm capable of running on Windows, Linux, and <a title=\"Macintosh\" href=\"http:\/\/www.apple.com\/mac\/\" target=\"_blank\" rel=\"homepage noopener noreferrer\">Mac computers<\/a>. The\u00a0<a title=\"Badbunny (computer worm)\" href=\"http:\/\/en.wikipedia.org\/wiki\/Badbunny_%28computer_worm%29\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">BadBunny<\/a> worm dropped Ruby script viruses on Mac OS X systems and displayed an indecent JPEG image of a man wearing a rabbit costume.<\/p>\n<p title=\"Badbunny (computer worm)\"><a href=\"https:\/\/web.archive.org\/web\/20210216202120\/https:\/\/www.sophos.com\/en-us\/press-office\/press-releases\/2007\/05\/badbunny.aspx\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101656 size-thumbnail\" title=\"BadBunny worm\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/badbunny_malware.gif?resize=75%2C75&#038;ssl=1\" alt=\"BadBunny worm\" width=\"75\" height=\"75\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/badbunny_malware.gif?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/badbunny_malware.gif?resize=150%2C150&amp;ssl=1 150w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/><\/a>The first financial malware for Mac appeared\u00a0in 2007. The OSX\/<a title=\"RSPlug\" href=\"http:\/\/en.wikipedia.org\/wiki\/RSPlug\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">RSPlug<\/a>-A Trojan horse <a title=\"Mac OS malware targets porn surfers\" href=\"https:\/\/web.archive.org\/web\/20130808145920\/http:\/\/news.cnet.com\/8301-13579_3-9808489-37.html\" target=\"_blank\" rel=\"noopener noreferrer\">was first detected <\/a>by researchers at <a title=\"Intego\" href=\"http:\/\/www.intego.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Intego<\/a>. Mac users infected themselves by downloading and running a fake codec that claimed to help users view pornographic videos. Once on a victim\u2019s Mac, RSPlug changed that machine\u2019s DNS settings so that, while browsing the web, users would redirect to phishing sites or sites containing advertisements for other pornographic sites.<\/p>\n<p title=\"Badbunny (computer worm)\"><a title=\"First financial malware for Mac \u2013 RSPlug-A\" href=\"https:\/\/web.archive.org\/web\/20120726044756\/http:\/\/threatpost.com\/en_us\/slideshow\/Bad%20Apples%3A%20Mac%20Malware%20through%20the%20Years?page=7\" target=\"_blank\" rel=\"noopener noreferrer\">According<\/a> to <a title=\"Kaspersky\" href=\"http:\/\/usa.kaspersky.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Kasperskey&#8217;s<\/a> <a title=\"Threat Poat\" href=\"https:\/\/threatpost.com\/en_us\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Threat Post<\/em><\/a>, RSPlug\u2019s various incarnations are all forms of the DNSChanger malware. DNSChanger featured prominently as the target of the FBI\u2019s 2011 take-down of the malware network, dubbed <a title=\"Two Million Requests from Infected Systems In Week After Ghost Click Takedown\" href=\"http:\/\/threatpost.com\/en_us\/blogs\/two-million-requests-infected-systems-week-after-ghost-click-takedown-120111\" target=\"_blank\" rel=\"noopener noreferrer\">Operation Ghost Click<\/a>.<\/p>\n<p><strong>2008<\/strong> &#8211; Apple malware became more sophisticated in 2008. Cybercriminals targeted Mac and PC users in equal measure, by planting poisoned ads on TV-related websites. If accessed via an Apple Mac, surfers would be attacked by a piece of Macintosh scareware called <a title=\"MacSweeper\" href=\"http:\/\/en.wikipedia.org\/wiki\/MacSweeper\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">MacSweeper<\/a>. Close relatives of MacSweeper including <a title=\"Sophos warns against iMunizator \u2018scareware\u2019\" href=\"https:\/\/web.archive.org\/web\/20130529094652\/http:\/\/www.macworld.com\/article\/1132800\/imunizator.html\" target=\"_blank\" rel=\"noopener noreferrer\">Imunizator<\/a>, claimed to find privacy issues on the user&#8217;s computer.<\/p>\n<p>The author details the growing sophistication of Mac malware in 2008.<\/p>\n<ul>\n<li><a href=\"https:\/\/web.archive.org\/web\/20140328231528\/http:\/\/www.wired.com:80\/magazine\/2011\/09\/mf_scareware\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101659\" title=\"Mac scareware\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/mac_scareware.jpg?resize=111%2C100&#038;ssl=1\" alt=\"Mac scareware\" width=\"111\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/mac_scareware.jpg?resize=150%2C135&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/mac_scareware.jpg?resize=75%2C68&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/mac_scareware.jpg?w=660&amp;ssl=1 660w\" sizes=\"auto, (max-width: 111px) 100vw, 111px\" \/><\/a>The <a title=\"OSX\/Hovdy-A\" href=\"https:\/\/web.archive.org\/web\/20201029114508\/https:\/\/www.sophos.com\/en-us\/threat-center\/threat-analyses\/viruses-and-spyware\/OSX~Hovdy-A.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">OSX\/Hovdy-A<\/a> Trojan horse would steal passwords from Mac OS X users, open the firewall to give access to hackers, and disable security settings.<\/li>\n<li><a title=\"Troj\/RKOSX-A\" href=\"https:\/\/web.archive.org\/web\/20200412083055\/https:\/\/www.sophos.com\/en-us\/threat-center\/threat-analyses\/viruses-and-spyware\/Troj~RKOSX-A.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Troj\/RKOSX-A<\/a> a Trojan horse is a Mac OS X tool to assist hackers to create backdoor Trojans, which can give them access and control over your Apple Mac computer.<\/li>\n<li>The <a title=\"OSX\/Jahlav-C\" href=\"https:\/\/web.archive.org\/web\/20130409215003\/http:\/\/www.sophos.com\/en-us\/threat-center\/threat-analyses\/viruses-and-spyware\/OSX~Jahlav-C.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Jahlav Trojan<\/a> was similar to other malware campaigns, cybercriminals created a bogus webpage claiming to contain a video. Visiting the site produces a message saying that you don&#8217;t have the correct codec installed to watch the video whereupon the site offers you a DMG file for Apple Macs.<\/li>\n<\/ul>\n<p>Ironically Apple issued a support advisory in 2008 urging customers to run anti-virus software &#8211; but after media interest, rapidly deleted the page from their website.<\/p>\n<p><strong><a href=\"https:\/\/web.archive.org\/web\/20160825044413\/http:\/\/lifehacker.com\/5223499\/mac-trojan-horse-used-in-denial-of-service-attacks\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright\" title=\"OSX\/iWorkS-A Trojan horse\" src=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/s--GlclveBT--\/18fc5k1ft9p0xpng\" alt=\"OSX\/iWorkS-A Trojan horse\" width=\"90\" height=\"103\" \/><\/a>2009 &#8211; <\/strong><em>ThreatPost<\/em> reports that in 2009 Symantec found the <a title=\"OSX\/iWorkS-A Trojan horse\" href=\"https:\/\/web.archive.org\/web\/20160207031457\/http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2009-012216-4245-99\" target=\"_blank\" rel=\"noopener noreferrer\">OSX\/iWorkS-A Trojan horse<\/a>. The malware was <a title=\"New Trojan Attacks Pirates\" href=\"https:\/\/web.archive.org\/web\/20140727023143\/http:\/\/community.norton.com\/t5\/Norton-Protection-Blog\/New-Trojan-Attacks-Pirates\/ba-p\/59431\" target=\"_blank\" rel=\"noopener noreferrer\">added<\/a> to a version of Apple&#8217;s <a title=\"iWork\" href=\"http:\/\/www.apple.com\/iwork\/\" target=\"_blank\" rel=\"homepage noopener noreferrer\">iWork &#8217;09<\/a> software suite that popped up on BitTorrent file sharing sites. The incident was noteworthy because the trojan was packaged with the actual iWork application, so the Mac users, many of which do not use an antivirus solution, would have no reason to suspect that their machines were infected because of the download. The trojan itself communicated with a remote server and was intended to scan machines for data and track Internet history and keystrokes. A new variant of the Trojan was distributed in a pirated version of\u00a0<a title=\"Adobe\" href=\"https:\/\/www.adobe.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Adobe<\/a> (<a title=\"NASDAQ : ADBE\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-ADBE\/\" target=\"_blank\" rel=\"noopener noreferrer\">ADBE<\/a>) <a title=\"Adobe Photoshop\" href=\"https:\/\/adobe.com\/photoshop\" target=\"_blank\" rel=\"homepage noopener noreferrer\">Photoshop CS4<\/a>.<\/p>\n<p>Online video was a major conduit for Mac malware in 2009.<\/p>\n<ul>\n<li>Sophos reported on how hackers were planting versions of the RSPlug Trojan horse on websites, posing as an HDTV program called MacCinema.<\/li>\n<li>Hackers planted a version of the Jahlav Mac Trojan horse on a website posing as a portal for hardcore porn videos.<\/li>\n<li>The <a title=\"Twitter\" href=\"https:\/\/www.Twitter.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a> account of celebrity blogger <a title=\"Guy Kawasaki\" href=\"https:\/\/web.archive.org\/web\/20140222012537\/http:\/\/www.guykawasaki.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Guy Kawasaki<\/a> had a malicious link posted onto it, claiming to point to a sex video of Gossip Girl actress <a title=\"Leighton Meester \" href=\"http:\/\/www.imdb.com\/name\/nm1015262\/\" target=\"_blank\" rel=\"noopener noreferrer\">Leighton Meester<\/a>. In reality, however, the link leads unsuspecting users to malware that could infect Mac users.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/nakedsecurity.sophos.com\/2009\/06\/24\/leighton-meeter-sex-tape-lure-spread-malware-twitter-users\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101664\" title=\"Leighton Meeter\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Leighton-Meester-13.jpg?resize=100%2C120&#038;ssl=1\" alt=\"Leighton Meeter\" width=\"100\" height=\"120\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Leighton-Meester-13.jpg?resize=125%2C150&amp;ssl=1 125w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Leighton-Meester-13.jpg?resize=63%2C75&amp;ssl=1 63w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Leighton-Meester-13.jpg?w=500&amp;ssl=1 500w\" sizes=\"auto, (max-width: 100px) 100vw, 100px\" \/><\/a>In 2009 Apple finally began to build some rudimentary anti-malware protection into Mac OS X. Although it wasn&#8217;t really equal to a true anti-virus product (it only protected against a handful of Mac malware, doesn&#8217;t defend you if you try to copy an infected file from a USB stick for instance, and doesn&#8217;t offer clean-up facilities), it was still encouraging to see some attempt to offer more protection for Mac users.<\/p>\n<p><strong>2010 &#8211;<\/strong> Throughout 2010 Mac malware was distributed disguised as a legitimate application.<\/p>\n<ul>\n<li>The <a title=\"OSX\/Pinhead Trojan\" href=\"https:\/\/web.archive.org\/web\/20131111170852\/http:\/\/www.sophos.com\/en-us\/\/threat-center\/threat-analyses\/viruses-and-spyware\/OSX~Pinhead-B.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">OSX\/Pinhead Trojan<\/a> (aka <a title=\"HellRTS\" href=\"https:\/\/www.securemac.com\/osx\/trojan-horse-alert-hellraiser-aka-osxhellrts-d\" target=\"_blank\" rel=\"noopener noreferrer\">HellRTS<\/a>) was disguised as <a title=\"iPhoto\" href=\"https:\/\/www.apple.com\/ilife\/iphoto\/\" target=\"_blank\" rel=\"noopener noreferrer\">iPhoto<\/a>, the photo application which ships on modern Macs. The backdoor Trojan horse can allow hackers to gain remote control over your iMac or MacBook.<\/li>\n<\/ul>\n<ul>\n<li><a href=\"http:\/\/nakedsecurity.sophos.com\/2010\/11\/04\/new-variant-of-cross-platform-boonana-malware-discovered\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-115976\" title=\"Boonana cross-platform worm\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/virus_boona.jpg?resize=99%2C100&#038;ssl=1\" alt=\"Boonana cross-platform worm\" width=\"99\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/virus_boona.jpg?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/virus_boona.jpg?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/virus_boona.jpg?w=170&amp;ssl=1 170w\" sizes=\"auto, (max-width: 99px) 100vw, 99px\" \/><\/a>A Java applet distributed via\u00a0<a title=\"Facebook\" href=\"https:\/\/www.facebook.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a> (<a title=\"NASDAQ : FB\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-FB\/\" target=\"_blank\" rel=\"noopener noreferrer\">FB<\/a>) was used to target not just Windows computers but Mac OS X and Linux too. The <a title=\"Boonana\" href=\"https:\/\/web.archive.org\/web\/20131206171202\/http:\/\/reviews.cnet.com\/8301-13727_7-20020892-263.html\" target=\"_blank\" rel=\"noopener noreferrer\">Boonana<\/a> cross-platform worm appeared, disguised as a video and runs in the background, and reports system information to servers on the Internet, which can be a big breach of personal information. The Trojan also attempts to spread itself by sending messages from the user account to other people through spam.<\/li>\n<\/ul>\n<ul>\n<li>A piece of Mac spyware called <a title=\"Security firm discovers spyware in Mac software\" href=\"http:\/\/web.archive.org\/web\/20130602071257\/http:\/\/www.macworld.com\/article\/1151667\/mac_shareware_spyware.html\" target=\"_blank\" rel=\"noopener noreferrer\">Spynion<\/a> (also known as OpinionSpy or PremierOpinion) came to light, attached to screen savers and other add-ons for users&#8217; Macs. it\u2019s a variant of Windows spyware that has existed since 2008. Spynion would take advantage of users not properly reading End User License Agreements (EULAs), allowing it to spy on browsing habits and search behavior.<\/li>\n<\/ul>\n<p>In late 2010, Sophos issued a free anti-virus for Mac home users. Early reports indicated that there are plenty of Mac users with malware on their computers &#8211; some of it Windows malware, some Mac OS X, and some cross-platform. The author states that there&#8217;s no doubt that the Windows malware problem is much larger than the Mac threat, but that doesn&#8217;t mean that the danger of malware infection on Mac OS X is non-existent.<\/p>\n<p>The events of 2011 would make it clearer to Mac users than ever before that the malware threat was real..<\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"https:\/\/web.archive.org\/web\/20160730105545\/http:\/\/onecoolsitebloggingtips.com\/2012\/10\/02\/malware-targets-macs-and-windows-pcs\/\" target=\"_blank\" rel=\"noopener noreferrer\">Malware Targets Macs and Windows PCs<\/a> (onecoolsitebloggingtips.com)<\/li>\n<\/ul>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mac Malware is a subject that raises strong emotions among Apple supporters<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[2197,420,101,1397,1289,1135,782,23,82,421,4,1214,810,97],"class_list":["post-17690","post","type-post","status-publish","format-standard","hentry","category-security","tag-2197","tag-aapl","tag-apple","tag-badbunny","tag-history","tag-ios","tag-macintosh","tag-malware","tag-microsoft","tag-msft","tag-security","tag-trojan-horse","tag-virus","tag-worm"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/17690","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=17690"}],"version-history":[{"count":41,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/17690\/revisions"}],"predecessor-version":[{"id":132800,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/17690\/revisions\/132800"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=17690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=17690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=17690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}