HomeForumsEMUG User GroupShuffle NewsletterTrainingAppleIDX PricesGalleryCalendarAboutContactSearch

Go Back   EmiratesMac > Mac stuff > News & Rumors Mac
Register FAQ Members List Search Today's Posts Mark Forums Read Log Out

News & Rumors Mac News and Rumors all about Mac.


Welcome to EmiratesMac! Join EmiratesMac today! Contact us!
Closed Thread
 
LinkBack Thread Tools Display Modes
Sponsored Links
Old 23rd June 2008, 09:11   #1 (permalink)
Senior Member
 
gajanan's Avatar
 
Join Date: Sep 2007
Location: Born in AUH living in DXB
Posts: 220
gajanan is on a distinguished road
Exclamation [Trojan] - AppleScript.THT Trojan Horse

Quote:
AppleScript.THT Trojan Horse
New OS X Trojan Horse in the Wild
SecureMac Security Advisory
Discovery: June 19th, 2008

Updated: N/A

Security Risk: Critical

SecureMac has discovered multiple variants of a new Trojan horse in the wild that affects Mac OS X 10.4 and 10.5. The Trojan horse is currently being distributed from a hacker website, where discussion has taken place on distributing the Trojan horse through iChat and Limewire.

The Trojan horse runs hidden on the system, and allows a malicious user complete remote access to the system, can transmit system and user passwords, and can avoid detection by opening ports in the firewall and turning off system logging. Additionally, the AppleScript.THT Trojan horse can log keystrokes, take pictures with the built-in Apple iSight camera, take screenshots, and turn on file sharing. The Trojan horse exploits a recently discovered vulnerability with the Apple Remote Desktop Agent, which allows it to run as root.

The Trojan is distributed as either a compiled AppleScript, called ASthtv05 (60 KB in size), or as an application bundle called AStht_v06 (3.1 MB in size). The user must download and open the Trojan horse in order to become infected. Once the Trojan horse is running, it will move itself into the /Library/Caches/ folder, and add itself to the System Login Items.

Protection: To protect your system against this threat, run MacScan 2.5 Macintosh Spyware Trojan Keystroke Logger, Mac Spyware Detection Removal Protection Mac OS X (MacScan is a product of SecureMac) with the latest Spyware Definitions update (2008011), dated June 19th, 2008. SecureMac recommends that users download files only from trusted sources and sites.

Additional removal instructions and resources will be posted once available.

Resources: http://www.securemac.com/data/applescripttht.pdf
Taken from : AppleScript.THT Trojan Horse - Mac OS X Trojan Horse
Hope this helps.
Cheers.


gajanan is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 23rd June 2008, 15:40   #2 (permalink)
Administrator

 
Magnus's Avatar
 
Join Date: Apr 2006
Location: Dubai
Posts: 7,804
Magnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond repute
I believe that was already posted about.
Magnus is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Apple, the Apple Logo, and Macintosh are trademarks of Apple, Inc., registered in the U.S.A. and other countries. EmiratesMac is a recognized independent user group and has not been authorized, sponsored, or otherwise approved by Apple, Inc.
All times are GMT +4. The time now is 08:04.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0