How exactly does this Trojan horse work?
When a user double-clicks the file, Mac OS X sees the carb and cfrg resources, assumes that the file is an application and launches it. The cfrg resource, which points to the actual code contained in the ID3 tag, allows this code to be executed. The application then opens, launches iTunes via an AppleEvent and plays the sound contained in the MP3 file.
Next, the code contained in the file's ID3 tag continues executing. In the current Trojan horse, an alert is displayed, saying that it is indeed an application.
This type of Trojan horse could launch any application that runs under Mac
OS X.
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?