Mac Trojan Horse Discovered in the Wild

[11/1] WARNING: Mac Trojan Horse Discovered in the Wild

Named "OSX.RSPlugin.A Trojan Horse" by Intego, a trojan horse that infects Macs has been discovered and a notice posted by Intego. While it is thought to be introduced by clicking to watch a porn site's video, it can be modified to come from any malicious Web site in a similar fashion.

The trojan horse is a DNSChanger, i.e. it sets your computer to go to sites selected by the attacker, possibly phishing sites, and not what is typed into your Web browser's address field. It also has a cron file that runs every so often to reinstate the bogus DNS addresses should they be found and changed. Going to a financial-related Web site could lead to disaster.

Intego, of course, recommends buying and installing its VirusBarrier X4 to protect against the trojan horse. But you can block it by not downloading any video codec if so requested and by setting your Web browser to not open "safe" files after downloading--in Safari it's a checkbox in the General tab of Safari's preferences.

Macworld posted a excellent lengthy article describing how to detect the "OSX.RSPlugin.A Trojan Horse" and how to remove it manually. [Bill Fox]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive