Attacks/Breaches
5/1/2012
12:20 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Mac Flashback Malware Bags Big Bucks

Analysis of the Flashback malware code estimates that botnet operators are earning $10,000 per day. Users of older Mac operating systems remain at risk.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
The Flashback malware that infected hundreds of thousands of Macs was built for a single overriding purpose: profit. In fact, the developers and operators of the malware and related botnet could be raking in a cool $10,000 per day, according to researchers at Symantec, who said they're continuing to unravel what the malware can do.

By some estimates, more than 600,000 Macs were infected with Flashback, which spread using a Java vulnerability. Apple began pushing an update for that Java vulnerability less than two weeks after the Mac malware was discovered, on April 4, 2012. By the end of April, the number of reported Flashback infections had significantly decreased.

Still, Apple users were ensnared because of the six-week delay between knowledge of the Java vulnerability becoming public--owing to attackers reverse-engineering a Windows update in February 2012--and Apple releasing its own Java update that patched the flaw. "This window of opportunity helped the Flashback Trojan to infect Macs on a large scale. The Flashback authors took advantage of the gap between Oracle and Apple's patches by exploiting vulnerable websites using WordPress and Joomla to add malicious code snippets," according to a blog post from Symantec Security Response.

[ Read After Flashback, Apple Walled Gardens Won't Help. ]

Any Mac OS X user visiting a compromised site risked being infected by Flashback. In particular, Symantec said the infected sites would redirect the user's browser to a website hosting multiple Java exploits, which would use the known Java vulnerability to decrypt and install the initial Flashback Java applet. At that point, the applet would install a loader, as well as an ad-clicking component.

The ad-clicking component works with Chrome, Firefox, and Safari, and "can intercept all GET and POST requests from the browser," said Symantec. "Flashback specifically targets search queries made on Google and, depending on the search query, may redirect users to another page of the attacker's choosing, where they receive revenue from the click."

But the intended click would never reach Google. "This ultimately results in lost revenue for Google and untold sums of money for the Flashback gang," Symantec said. How much money? Based on its 2011 study of the Xpaj botnet, Symantec found that 25,000 click-fraud infections could generate up to $450 per day. "Considering the Flashback Trojan [infection] measures in the hundreds of thousands, this figure could sharply rise to the order of $10,000 per day," it said.

Although the number of Flashback infections continues to decline, Russian antivirus vendor Doctor Web, which first discovered the malware, said that older Macs remain at risk.

Overall, 63% of Flashback infections affected Macs running 10.6 (Snow Leopard), while only 11% hit users of 10.7 (Lion), which is the latest Mac operating system and accounts for 40% of all in-use OS X installations, according to NetMarketShare.

But an older Mac operating system, OS X 10.5 (Leopard), which is used by 13% of Mac users, accounted for 25%--the second highest number--of Flashback infections. Although free software can help Leopard users block Flashback, Apple is no longer shipping Leopard security updates. That puts Leopard users at greater risk of being attacked, because the Java vulnerability exploited by Flashback and SabPub will remain unpatched, and thus will likely continue to be targeted by new malware.

InformationWeek is conducting a survey to get a baseline look at where enterprises stand on their IPv6 deployments, with a focus on problem areas, including security, training, budget, and readiness. Upon completion of our survey, you will be eligible to enter a drawing to receive an 16-GB Apple iPad. Take our InformationWeek IPv6 Survey now. Survey ends May 11.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web