Mac OS X MP3 File Trojan Horse--Fact or Fiction?

Intego, maker of VirusBarrier software, issued a press release yesterday from it's Paris office that warned of the existence of a trojan horse "virus" for Mac OS X masquerading as an MP3 song file and noted that the latest version of their VirusBarrier's definitions will scan for the trojan. Intego's notice set off a huge debate on the web, including on at least three major Mac lists that we read.

While debaters argued for and against the possibility of such a file, many were cynical pointing out that there have been no such notices from other virus protection vendors or even Apple itself and no one has reported having been struck by the trojan. Later in the day McAfee issued a beta of their Virex X v7.5 following the furor but did not claim that it addressed the alert that Intego issued.

So is the trojan real and the Intego warning to be heeded? Here is a purported (note the incomplete sentence at the end of the third paragraph) email from Intego addressing the question posted to a list we subscribe to:

Dear xxx,

This virus was forwarded to us (and many others in the Mac security
industry) by an individual who found it on his system earlier this week. We
identified it as a Trojan horse application that is able to hide it
executable code within the ID3 tag of an MP3 file. While the filename will
still have a suffix of ".mp3", the file's file type under Mac OS is set to
"APPL" which will allow the file to be executed as an application.

Because the code is written as a "Carbon" application, it does not need to
have the .app extension in order to run, only to have it's hidden file type
set to APPL. Carbon applications can run in either Mac OS X or the classic
Mac OS. The suffix of .mp3 is then just seen as part of the filename rather
than a denotation of file type.

When the infected file is launched by double-clicking, or opening, with the
Mac's Finder, the virus code will begin to run. First it attempts to launch
your iTunes application and load the MP3 file as a data file so that it will
appear to be playing as though nothing is wrong. Since the virus code is
hidden in the ID3 tags, the audio portion will play as normal. The virus
then continues to run, infecting other MP3 files within the same folder, and
attempts to access some of the CoreServices components of the operating
system. It does not appear to

The current virus that has been found only infects MP3 files. But the
concept used in this virus could be used to create variants that work with
other file types as well. Any data file type that allows for a notation
field to be embedded into the file, such as the ID3 tag that is used for
this purpose in the infected MP3 files, could be targeted as another carrier
for future viruses. While there is not a currently known virus that uses
image files as the transport, it is unfortunately a small step for a virus
writer to modify the current MP3Concept Trojan horse to use another file
type as it's transport method. This is why our virus definitions have been
engineered to look for this type of code outside of just MP3 files as a
measure of preparedness.

Thank you for choosing Intego.

____________________________________________________________________
David M
Intego Technical Support http://www.intego.com/support

We are not experts in this field so we can not offer our readers any useful advice beyond the traditional advice of always be conservative, i.e. do not click on files attached to an email that you were not expecting even if it appears to be from someone that you know.

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive