AppleScript.THT Mac Trojan in the Wild

By admin | Jun 23, 2008

sad_mac.jpgMacs have had the privy of not owning market share.  Now, that’s good and bad.  Good in that malicious individuals won’t target you because of the ROI.  And it’s bad because you don’t have much market share!  Anyway, Various sources are indicating that a Mac trojan, named AppleScript is actively being exploited.

The problem with this trojan, in terms of design, is that it has to be run on the machine by the current user.  Hackers are currently dumping variants of the trojan onto peer to peer sharing services in hopes of getting some folks.  If you were to install the downloaded package, you would be essentially giving control of your Mac to hackers.  Here is part of the notice from SecureMac:

“The Trojan horse runs hidden on the system, and allows a malicious user complete remote access to the system, can transmit system and user passwords, and can avoid detection by opening ports in the firewall and turning off system logging. Additionally, the AppleScript.THT Trojan horse can log keystrokes, take pictures with the built-in Apple iSight camera, take screenshots, and turn on file sharing. The Trojan horse exploits a recently discovered vulnerability with the Apple Remote Desktop Agent, which allows it to run as root.

The Trojan is distributed as either a compiled AppleScript, called ASthtv05 (60 KB in size), or as an application bundle called AStht_v06 (3.1 MB in size). The user must download and open the Trojan horse in order to become infected. Once the Trojan horse is running, it will move itself into the /Library/Caches/ folder, and add itself to the System Login Items”



Related Posts:

Blogger Exploit A Platform For Hackers
It's getting pretty hectic out here in Internetland. Remember the Storm Trojan I mentioned mere days ago? Well, from the...

“Storm” Warning: Worms Getting More Vicious
The Storm Trojan. One of the nastiest viruses to hit the 'Net in some time has really been active as...

WildCharge Wireless Charger
If hooking up a small cord to your electronic device is a pain for you, then you should consider the...

Phone Virus in the Wild
Nokia 6600The Cabir virus has now become the first United States mobile phone virus in the wild. The virus...

Web Attacker Increases Security Threat
A russian company has posted a "Smartbomb" toolkit that allows people to post websites to exploit recent vulnerabilities in Internet...

Leave a Comment

If you would like to make a comment, please fill out the form below.

Name (required)

Email (required)

Website

Comments

© 2007 PaulTech Network, - Daily Blog Tips Themes