Attacks/Breaches
4/20/2012
10:23 AM
Connect Directly
RSS
E-Mail
50%
50%

Apple Mac Attack Began With Infected WordPress Sites

Security researchers watch for a possible Flashback comeback by the botnet operators.

The massive Flashback botnet of Mac machines originated from hacked and malware-rigged WordPress blog sites, researchers revealed Thursday.

There were between 30,000 and 100,000 WordPress sites infected in late February and early March, 85% of which are in the United States, said Vicente Diaz, senior security analyst for Kaspersky Lab, in a briefing.

Kaspersky Lab researchers say the infected WordPress blog sites were rigged with code that silently redirected visitors to a malicious server. "When the connection was made to the malicious server, that server would determine which OS was running and serve exploits accordingly," says Roel Schouwenberg, senior researcher for Kaspersky. It was a pay-per-install scheme to spread malware, including the Flashback Trojan.

Most researchers say a gradual decline in machines infected by the Trojan is still underway: As of Thursday, there were about 140,000 infected Macs still out there, according to Symantec, and Kaspersky says it sees only about 30,629 Flashback-infected bots in its sinkhole.

Still on the horizon, too, is the possibility of a Flashback comeback, with the command-and-control servers sending their bots updates. "We are watching the command-and-control domains used to control this botnet for any updates ... We haven't seen any new updates being delivered," said Liam O Murchu, manager of operations for Symantec Security Response. "Flashback generates new domains every day, which shows us the attackers have probably written malicious code before. They are aware that their botnet could be taken down with a single domain, so they generate a new one every day."

Flashback may be the largest known botnet made up of Apple Macintosh computers, and the outbreak of infections, mainly in the United States, appears to have ushered in the beginning of the end of the age of innocence for Mac users. While attacks on the Mac aren't new, this one was high-profile and widespread.

Word spread rapidly earlier this month that a massive botnet of Mac OS X machines was building, and it reached more than 700,000 machines before antivirus vendors, including Kaspersky Lab, F-Secure, and Symantec, issued their own detection and removal tools. Apple issued an update to patch for the exploited vulnerability over the weekend. The Flashback malware exploits a known vulnerability in Java that had been patched by Oracle.

Apple did not respond to an inquiry for this article. Its updates for OS X Lion and Mac OS X v10.6 patch the Java implementation hole and remove Flashback, and Apple also provided an update for OS X Lion that removes Flashback from Macs that don't run Java.

Read the rest of this article on Dark Reading.

Put an end to insider theft and accidental data disclosure with network and host controls--and don't forget to keep employees on their toes. Also in the new, all-digital Stop Data Leaks issue of Dark Reading: Why security must be everyone's concern, and lessons learned from the Global Payments breach. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Andrew Hornback
50%
50%
Andrew Hornback,
User Rank: Apprentice
4/25/2012 | 12:41:00 AM
re: Apple Mac Attack Began With Infected WordPress Sites
If it takes something like this (the infection) and the media covering it, as another poster says, in a manner such like gloating to get Mac users to wise up and actually think about security on their systems - Good!

Any and every system with an active network connection and the capability of connecting to the Internet is vulnerable. Period, end of story.

I've heard many users of "alternative" platforms (i.e. Mac, Linux, etc.) claim that their systems are basically invulnerable. That is FAR from true and the more exposure, education and understanding that can be derived from situations like this, the better. Right?

Andrew Hornback
InformationWeek Contributor
MyW0r1d
50%
50%
MyW0r1d,
User Rank: Apprentice
4/23/2012 | 8:03:12 PM
re: Apple Mac Attack Began With Infected WordPress Sites
It's you. Look at like this, when a champ stumbles every publication is going to rush to analyze it, how could it happen and is the end of the era over? History is full of them, they did it with M. Ali, M. Jordan, S. Oneil, nothing special about it. On the other hand, can't remember an article from a Window's user stating they didn't need AV or antimalware of some sort and I do remember a few from MAC users. It's not gloating, it's simple fact. So from this article, is it WordPress security that should be of more concern.
Aden11
50%
50%
Aden11,
User Rank: Apprentice
4/23/2012 | 2:37:59 PM
re: Apple Mac Attack Began With Infected WordPress Sites
It is amusing to see the way 'WINDOWS' users are reacting.
tuckbodi
50%
50%
tuckbodi,
User Rank: Apprentice
4/20/2012 | 4:53:33 PM
re: Apple Mac Attack Began With Infected WordPress Sites
Is it just me or is Info Week (and the other PC mag's) just jumping up & down gloating about this malware?!!? Kinda cracks me up....one versus a million on the other platform! AND on the Mac, you have to give it permission and any idiot who logs in as an admin is, well, an idiot!
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0640
Published: 2014-08-20
EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to bypass intended restrictions on resource access via unspecified vectors.

CVE-2014-0641
Published: 2014-08-20
Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to hijack the authentication of arbitrary users.

CVE-2014-2505
Published: 2014-08-20
EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to trigger the download of arbitrary code, and consequently change the product's functionality, via unspecified vectors.

CVE-2014-2511
Published: 2014-08-20
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.

CVE-2014-2515
Published: 2014-08-20
EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided by D2GetAdminTicketMethod and D2RefreshCacheMethod, which allows remote authenticated users to gain privileges via a request for a superuser ticket.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.