Major Security Breach Discoverd in macOS High Sierra

Mac OS X 10.7.3 update

Apple has released and update to Mac OS X Lion10.7. The release includes a sizeable security update to most technologies that fixes multiple vulnerabilities in the operating system. Full details of the security update can be found in the Apple knowledge-base article: http://support.apple.com/kb/HT1222

The OS update includes Safari v5.1.3 as well as additional support for new languages and resolutions for compatibility and performance issues.

Further details of the new version of Mac OS X can be found on the Apple
website.

Security Update 2012-001 Released

A security update for Mac OS X has been released for all Mac OS X 10.6.8, OS X Lion version 10.7 to 10.7.2 users. The publication coincides with the release of Mac OS X 10.7.3

The update fixes over 50 vulnerabilities in the Mac operating system, ranging from core technology amendments that resolve arbitrary code execution to multiple vulnerabilities in QuickTime and PHP. The update covers most technologies from Apache to X11.

Full details of the security update can be found on the Apple website
http://support.apple.com/kb/HT1222

New Mac OS X Trojan distributed via BitTorrent file-sharing sites

gc
A new Mac OS X Trojan has been discovered on BitTorrent sites. The threat, dubbed OSX.DevilRobber or OSX.Miner, has appeared within legitimate copies of GraphicConverter v7.4, Flux v3.2.5 and CorelPainter v12, which the virus writer has modified and posted on the file-sharing websites. The Trojan is installed on your computer when the parent application’s installer is run.

The threat appears to be quite sophisticated, adopting a multi-pronged approach to harvesting personal details from your computer, including stored information from encryption software and Safari, and sends this to a remote server. In addition, the Trojan utilizes your Graphics processor (GPU) to perform calculations required to undertake bitcoin mining, hence the name. If it discovers a bitcoin wallet it will save that, too.

bitcoin

If your Mac becomes infected by this Trojan then the first thing you may notice is a sluggishness as it performs the bitcoin permutations required for ‘mining’. Check for the presence of a folder in your login user area called ~/Library/mdsa1331/ and a launch agent file in ~/Library/LaunchAgents/ that looks unfamiliar. The current version of the trojan creates a startup file, which at first glance appears to have come from Apple, com.apple.legion.plist.

Interestingly, the Trojan script exits if it detects that LittleSnitch, a network analyzing tool, is installed on your Mac. Presumably this is because it will highlight network traffic and raise awareness of the Trojan’s presence in the wild.


As always, we advise extreme caution when downloading software from file-sharing websites as you don’t always get what you expect. Unfortunately in this case you get a lot more than you bargained for!

ProtectMac AntiVirus detects this new Trojan as OSX.DevilRobber.

Security Update 2011-006 Released

Apple has published a security update for Mac OS X to compliment the latest release of Lion 10.7.2. This update also improves the security of Macs running Mac OS X 10.6.8.

There is numerous security fixes included in this update to improve the stability and security of your computer relating to core technologies, networking, file viewing and downloading and in particular Quicktime and the Application Firewall. Full details of the security update can be found on the Apple website
http://support.apple.com/kb/HT5002

Update 26 Oct 2011: The Quicktime fixes are also available for Windows computers.