Register FAQ/Rules Forum Spy Search Today's Posts Mark Forums Read

Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate.

 
Go Back   Mac Forums > News and Article Discussion > MacRumors.com News Discussion
TouchArcade.com - iPhone Game Reviews and News

Reply
 
Thread Tools Search this Thread  
Old Jan 22, 2009, 02:19 PM   #1
MacRumors
macrumors bot
 
Join Date: Apr 2001
iWork '09 Torrent Carrying OS X Trojan



A security alert posted this morning by antivirus vendor Intego reveals that the company has discovered a new Trojan horse that is being carried by pirated copies of iWork '09 circulating on a number of torrent sites.

The Trojan, which Intego has classified as a "serious" risk and named OSX.Trojan.iServices.A, allows a malicious user to connect to an infected machine and perform various functions, as well as download additional software to the machine.

Quote:
This software is installed as a startup item (in /System/Library/StartupItems/iWorkServices, a location reserved normally for Apple startup items), where it has read-write-execute permissions for root. The malicious software connects to a remote server over the Internet; this means that a malicious user will be alerted that this Trojan horse is installed on different Macs, and will have the ability to connect to them and perform various actions remotely. The Trojan horse may also download additional components to an infected Mac.
Intego reports that over 20,000 users had downloaded the package as of 6:00 AM Eastern time this morning, and an update to an entry posted on Intego's Mac Security Blog notes that the Trojan now appears to be actively downloading new code to infected machines and using them to carry out denial-of-service attacks on certain websites.

Article Link: iWork '09 Torrent Carrying OS X Trojan
MacRumors is offline   Reply With Quote
Old Jan 22, 2009, 02:21 PM   #2
gkarris
macrumors 601
 
gkarris's Avatar
 
Join Date: Dec 2004
Location: Somewhere In The Universe
and starts the onlsought of Mac viruses....
__________________
"This gate's plastic." Captain Carter, Stargate SG-1, "Touchstone"
Mini/MacBook/iPhone/TV
Olympus E-420/E-500, Canon 20D
gkarris is offline   Reply With Quote
Old Jan 22, 2009, 02:22 PM   #3
Schtumple
macrumors 68040
 
Schtumple's Avatar
 
Join Date: Jun 2007
Location: There >
Karma's a bitch eh?

Wonder how many machines are now infected with this trojan (as it spreads).
__________________
My Music
3rd party software is NOT made by Apple
Schtumple is offline   Reply With Quote
Old Jan 22, 2009, 02:22 PM   #4
Tallest Skil
Banned
 
Join Date: Aug 2006
Location: 1 Geostationary Tower Plaza
Quote:
Originally Posted by gkarris View Post
and starts the onlsought of Mac viruses....
Trojan, not virus.
Tallest Skil is offline   Reply With Quote
Old Jan 22, 2009, 02:28 PM   #5
K3mp
macrumors 6502
 
Join Date: May 2008
Location: S.E. Louisiana
Send a message via Skype™ to K3mp
They type in their password. It looks like somebody just wrote a malicious app. I guess that is what they get for being cheap. Has anyone found a removal tool for it yet? Or is it still spreading?
__________________
iPhone 8Gb(Replaced by a 32GB 3GS)MacBookPro 2.8 GhziPod nano 2GBTV
MRoogle: MacRumors Search+Google
K3mp is offline   Reply With Quote
Old Jan 22, 2009, 02:30 PM   #6
Sky Blue
macrumors 68040
 
Sky Blue's Avatar
 
Join Date: Jan 2005
Quote:
Originally Posted by K3mp View Post
I guess that is what they get for being cheap.
Yup. get what they deserve.
__________________
"The case is so square that it easily stands at attention as if begging for treats."
Sky Blue is online now   Reply With Quote
Old Jan 22, 2009, 02:30 PM   #7
born4sky
macrumors 6502
 
Join Date: Mar 2008
Steve wants to collect statistics
born4sky is offline   Reply With Quote
Old Jan 22, 2009, 02:30 PM   #8
Peterkro
macrumors 68000
 
Peterkro's Avatar
 
Join Date: Aug 2004
Location: Inglan a bitch
Quote:
Originally Posted by K3mp View Post
They type in their password. I guess that is what they get for being cheap. Has anyone found a removal tool for it yet? Or is it still spreading?
Users that have downloaded and installed a pirated version of iWork '09 can check for iWorkServices in /System/Library/StartupItems. iWorkServices is the malicious payload that's installed along with iWork.
Peterkro is offline   Reply With Quote
Old Jan 22, 2009, 02:31 PM   #9
mrboult
macrumors member
 
Join Date: Jul 2008
Location: London, England
Ha ha. Serves them right the suckers!
mrboult is offline   Reply With Quote
Old Jan 22, 2009, 02:32 PM   #10
h.21
Banned
 
Join Date: Nov 2008
Quote:
Originally Posted by gkarris View Post
and starts the onlsought of Mac viruses....
Consider yourself to be highly lucky that you have no idea what a virus actually is.

Isn't OS X grand?
h.21 is offline   Reply With Quote
Old Jan 22, 2009, 02:32 PM   #11
K3mp
macrumors 6502
 
Join Date: May 2008
Location: S.E. Louisiana
Send a message via Skype™ to K3mp
Quote:
Originally Posted by born4sky View Post
Steve wants to collect statistics
That actually sounds realistic .
__________________
iPhone 8Gb(Replaced by a 32GB 3GS)MacBookPro 2.8 GhziPod nano 2GBTV
MRoogle: MacRumors Search+Google
K3mp is offline   Reply With Quote
Old Jan 22, 2009, 02:33 PM   #12
zephead
macrumors 68000
 
zephead's Avatar
 
Join Date: Apr 2006
Location: SoCalifornia
It just goes to show that even if you have a Mac, just use a little common sense and you'll be fine.
__________________
California sunlight, Sweet Calcutta rain, Honolulu starbright, The Song Remains the Same....
MacBook CD 2GHz/250/2/10.6.1/white~iPhone 3G/16/3.1.2/JB
zephead is offline   Reply With Quote
Old Jan 22, 2009, 02:34 PM   #13
BoyBach
macrumors 68030
 
BoyBach's Avatar
 
Join Date: Feb 2006
Location: UK
Illegal software carries a trojan? As Justin Trousersnake once sang: "Cry Me A River."
BoyBach is offline   Reply With Quote
Old Jan 22, 2009, 02:35 PM   #14
glasserp
macrumors regular
 
Join Date: Apr 2008
Location: East Lansing, MI
Send a message via AIM to glasserp
Interesting. Two things: Could this possibly be prevented for those with Little Snitch? Wouldn't they see "OSX.Trojan.iServices.A is trying to connect to ##.###.###", and then deny access to it? Also, couldn't this be removed by the user just deleting OSX.Trojan.iServices.A from StartupItems?
__________________
MacBook, 2.0GHz CD, 2GB RAM, Mac OS X 10.5.7; iPhone 3G, 16GB
glasserp is offline   Reply With Quote
Old Jan 22, 2009, 02:36 PM   #15
LaDirection
macrumors regular
 
Join Date: Jul 2006
********. I dl and installed iWorks, so did 4 people I know, none of us has this freakin' thing installed.

Intego is at it again with imaginary threats
LaDirection is offline   Reply With Quote
Old Jan 22, 2009, 02:37 PM   #16
drlunanerd
macrumors 65816
 
drlunanerd's Avatar
 
Join Date: Feb 2004
Location: Pottering
Ouch. Seems Apple is doing pirates a favour by not requiring a serial number in iWork '09, but these peeps have got burnt and won't realise it.

Ironically the other day I spent hours troubleshooting a weird problem a client was having on their Power Mac G5. Turns out all their Word documents were infected with a macro virus. I wasted a lot of time as I just didn't think to check for viruses, it being OS X and all
__________________
Apple UK 2009 price policy = bag of hurt

Last edited by drlunanerd : Jan 22, 2009 at 03:34 PM. Reason: typo
drlunanerd is offline   Reply With Quote
Old Jan 22, 2009, 02:38 PM   #17
swingerofbirch
macrumors 68000
 
Join Date: Oct 2003
Location: The Amalgamated States of Central North America
Why would anyone dl the torrent when you can get the full version minus serial code from apple?
__________________
Blog of Failure
After using a PC all day, coming home to my Mac is like a tall, cold glass of peach iced tea.
swingerofbirch is offline   Reply With Quote
Old Jan 22, 2009, 02:38 PM   #18
zombitronic
macrumors 6502a
 
zombitronic's Avatar
 
Join Date: Feb 2007
-1 for the pirates.
zombitronic is offline   Reply With Quote
Old Jan 22, 2009, 02:39 PM   #19
Eidorian
macrumors G3
 
Eidorian's Avatar
 
Join Date: Mar 2005
Location: Indiana
Send a message via AIM to Eidorian
Which is why you just get the direct download from Apple.
__________________
MRoogle it!
hikari T7500 2.2 GHz / 4 GB / 320 GB / GMA X3100 / 10.5.8
chobimaru Core i5 750 2.66 GHz / 4 GB / 640 GB / 4830 / Windows 7
Eidorian is offline   Reply With Quote
Old Jan 22, 2009, 02:40 PM   #20
Peterkro
macrumors 68000
 
Peterkro's Avatar
 
Join Date: Aug 2004
Location: Inglan a bitch
Quote:
Originally Posted by swingerofbirch View Post
Why would anyone dl the torrent when you can get the full version minus serial code from apple?
Good question.
Peterkro is offline   Reply With Quote
Old Jan 22, 2009, 02:41 PM   #21
drlunanerd
macrumors 65816
 
drlunanerd's Avatar
 
Join Date: Feb 2004
Location: Pottering
Quote:
Originally Posted by LaDirection View Post
********. I dl and installed iWorks, so did 4 people I know, none of us has this freakin' thing installed.

Intego is at it again with imaginary threats
'Fraid it's real, I picked up on this a few days ago via some underground info.
Might want to get rid of whatever you downloaded and get the real McCoy from Apple
__________________
Apple UK 2009 price policy = bag of hurt
drlunanerd is offline   Reply With Quote
Old Jan 22, 2009, 02:42 PM   #22
sjc83
macrumors member
 
Join Date: Oct 2008
Location: Cleveland
Send a message via AIM to sjc83
**** happens....
__________________
Sam
2.0 Ghz Aluminum Macbook 4GB RAM
iPod Touch 16 gig
iPod Nano 4 gig
sjc83 is offline   Reply With Quote
Old Jan 22, 2009, 02:43 PM   #23
jackiecanev2
macrumors 6502a
 
jackiecanev2's Avatar
 
Join Date: Jul 2007
Send a message via AIM to jackiecanev2
Wirelessly posted (iPhone: Mozilla/5.0 (iPhone; U; CPU iPhone OS 2_2 like Mac OS X; en-us) AppleWebKit/525.18.1 (KHTML, like Gecko) Version/3.1.1 Mobile/5G77 Safari/525.20)

Haha. I have no sympathy. It actually kind of made me smile....
__________________
MBA 1.86 | 16GB iPhone 3G | BB 8900 | 24" ACD
making drinks, cutting up bodies, and saving trees.
jackiecanev2 is offline   Reply With Quote
Old Jan 22, 2009, 02:44 PM   #24
Kilamite
macrumors Demi-God
 
Kilamite's Avatar
 
Join Date: Mar 2007
Location: Scotland
Quote:
Originally Posted by drlunanerd View Post
Ironically the other say I spent hours troubleshooting a weird problem a client was having on their Power Mac G5. Turns out all their Word documents were infected with a macro virus. I wasted a lot of time as I just didn't think to check for viruses, it being OS X and all
Not the same as an actual virus for OS X.
__________________
- MacBook Pro Unibody 15" 2.8GHz 'anti-glare'
- Apple TV 1TB (work in progress)
- iPhone 3G 8GB
- MobileMe // OS X 10.6.2
Kilamite is online now   Reply With Quote
Old Jan 22, 2009, 02:45 PM   #25
synth3tik
macrumors Demi-God
 
synth3tik's Avatar
 
Join Date: Oct 2006
Location: Minneapolis, MN
Send a message via AIM to synth3tik
They should have just not said anything. Karma can be a bitch!

Ha, the other day I ran across an iWork 09 torrent that came out a day after the release. Thankfully I can't even figure why I would want to buy, let alone steal the suite.
synth3tik is offline   Reply With Quote

Reply

Mac Forums > News and Article Discussion > MacRumors.com News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 09:19 PM.

Mac News | Mac Rumors | iPhone Game Reviews | iPhone Apps

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2002-2009, MacRumors.com, LLC