Attacks/Breaches
5/1/2012
12:20 PM
Connect Directly
RSS
E-Mail
50%
50%

Mac Flashback Malware Bags Big Bucks

Analysis of the Flashback malware code estimates that botnet operators are earning $10,000 per day. Users of older Mac operating systems remain at risk.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
The Flashback malware that infected hundreds of thousands of Macs was built for a single overriding purpose: profit. In fact, the developers and operators of the malware and related botnet could be raking in a cool $10,000 per day, according to researchers at Symantec, who said they're continuing to unravel what the malware can do.

By some estimates, more than 600,000 Macs were infected with Flashback, which spread using a Java vulnerability. Apple began pushing an update for that Java vulnerability less than two weeks after the Mac malware was discovered, on April 4, 2012. By the end of April, the number of reported Flashback infections had significantly decreased.

Still, Apple users were ensnared because of the six-week delay between knowledge of the Java vulnerability becoming public--owing to attackers reverse-engineering a Windows update in February 2012--and Apple releasing its own Java update that patched the flaw. "This window of opportunity helped the Flashback Trojan to infect Macs on a large scale. The Flashback authors took advantage of the gap between Oracle and Apple's patches by exploiting vulnerable websites using WordPress and Joomla to add malicious code snippets," according to a blog post from Symantec Security Response.

[ Read After Flashback, Apple Walled Gardens Won't Help. ]

Any Mac OS X user visiting a compromised site risked being infected by Flashback. In particular, Symantec said the infected sites would redirect the user's browser to a website hosting multiple Java exploits, which would use the known Java vulnerability to decrypt and install the initial Flashback Java applet. At that point, the applet would install a loader, as well as an ad-clicking component.

The ad-clicking component works with Chrome, Firefox, and Safari, and "can intercept all GET and POST requests from the browser," said Symantec. "Flashback specifically targets search queries made on Google and, depending on the search query, may redirect users to another page of the attacker's choosing, where they receive revenue from the click."

But the intended click would never reach Google. "This ultimately results in lost revenue for Google and untold sums of money for the Flashback gang," Symantec said. How much money? Based on its 2011 study of the Xpaj botnet, Symantec found that 25,000 click-fraud infections could generate up to $450 per day. "Considering the Flashback Trojan [infection] measures in the hundreds of thousands, this figure could sharply rise to the order of $10,000 per day," it said.

Although the number of Flashback infections continues to decline, Russian antivirus vendor Doctor Web, which first discovered the malware, said that older Macs remain at risk.

Overall, 63% of Flashback infections affected Macs running 10.6 (Snow Leopard), while only 11% hit users of 10.7 (Lion), which is the latest Mac operating system and accounts for 40% of all in-use OS X installations, according to NetMarketShare.

But an older Mac operating system, OS X 10.5 (Leopard), which is used by 13% of Mac users, accounted for 25%--the second highest number--of Flashback infections. Although free software can help Leopard users block Flashback, Apple is no longer shipping Leopard security updates. That puts Leopard users at greater risk of being attacked, because the Java vulnerability exploited by Flashback and SabPub will remain unpatched, and thus will likely continue to be targeted by new malware.

InformationWeek is conducting a survey to get a baseline look at where enterprises stand on their IPv6 deployments, with a focus on problem areas, including security, training, budget, and readiness. Upon completion of our survey, you will be eligible to enter a drawing to receive an 16-GB Apple iPad. Take our InformationWeek IPv6 Survey now. Survey ends May 11.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-3304
Published: 2014-10-30
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

CVE-2013-7409
Published: 2014-10-30
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .m3u (playlist) file.

CVE-2014-3446
Published: 2014-10-30
SQL injection vulnerability in wcm/system/pages/admin/getnode.aspx in BSS Continuity CMS 4.2.22640.0 allows remote attackers to execute arbitrary SQL commands via the nodeid parameter.

CVE-2014-3584
Published: 2014-10-30
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.

CVE-2014-3623
Published: 2014-10-30
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vect...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.