Free apps install spyware on Macs

 

Summary

Spyware is downloaded along with free Mac OS X screensavers and an app, says security company Intego.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

Mac users downloading free screensavers and a video converter app from several popular download sites also got spyware that installs a back door, collects data, and sends encrypted information to remote servers, security company Intego said on Tuesday.

The high-risk spyware, dubbed OSX/OpinionSpy, was being installed along with nearly 30 screensavers developed by a company called 7art and an app called MishInc FLV to MP3, according to a list compiled by Intego.

They were found on Softpedia, MacUpdate, and CNET-owned VersionTracker, according to a post on Intego's Mac Security Blog.

VersionTracker had removed all of the items on the Intego list by late afternoon. A MacUpdate representative said the company disabled the screensavers earlier on Tuesday and had never offered the MishInc converter. "Our users were discussing the software installed alongside the 7art screensavers as far back as March," the company said in an e-mail. Softpedia, 7art, and MishInc publisher Brothersoft did not immediately respond to e-mails seeking comment late on Tuesday.

The spyware, a Windows version of which has existed since 2008, is not contained in the apps but is downloaded during the installation process. It is often marked as a "market research" program called PremierOpinion that claims to collect browsing and purchasing information for use in market reports, but it can also come with no warning or message, Intego said.

It's unclear exactly what data is collected and sent to the remote server, but it could include personal information like usernames, passwords, and credit card numbers, the post said.

Here is what the spyware does:

-runs as root with full rights to access and change any file on the computer,

-opens a back door using port 8254,

-scans all accessible files on local and network drives,

-analyzes packets entering and leaving the computer over a local area network, enabling one infected Mac to collect data from different computers on a school or business local network,

-injects code with no user action required into Firefox, Safari, and iChat and copies personal data from those applications, infecting the code of the applications in the Mac's memory but not the actual application files,

-regularly sends encrypted data to a number of servers using ports 80 and 442 about files scanned, as well as other information including e-mail addresses, iChat message headers, and URLs.

The spyware can be automatically upgraded to add new features without the knowledge of the computer user. It occasionally asks for the user's name or prompts the user to fill out surveys via a dialog box.

In some cases the infected computer will not work correctly and the user will need to force a reboot. In addition, deleting the original app or screensaver will not delete or interfere with the spyware, Intego said.

"While its distribution is limited, we warn Mac users to pay careful attention to which software they download and install," the company said. "Given the type of data that it collects, the company behind this spyware can store detailed records of users, their habits, their contacts, their location, and much more."

To see if your system is infected, there are several free Mac malware scanners including ClamXav and iAntiVirus.

This article was first published as a blog post on CNET News.

Talkback

thanks for the info. I know the good program which allows to protect your Mac against viruses - Protemac NetMine.

Rita June 3, 2010
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

#radio Radio Serbia by EnjoyIT 1.0 http://t.co/nGQFvX2E

Rise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c

RT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

CFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX

Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

RT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 hour ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL

Rise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt

Rise in Chinese-funded acquisitions could trigger more regulatory clearance issues overseas http://t.co/cvLSpTwo #in

Alibaba seeks $2.3B from shareholders for Yahoo deal. http://t.co/qLRAhRQk

CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

Quickflix WatchNow 2.0 http://t.co/XWti5VWT

Official UEFA #EURO2012 app with Orange 2.0 http://t.co/yoAOXTI1 #hotpeopleifollow

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

3 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

3 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

4 days ago by wykoong on Drop the egos, copy ideas, then innovate