SecureMac has discovered a new Trojan horse in the wild that affects Mac OS X, including Snow Leopard (OS X 10.6). The Trojan horse, Trojan.osx.boonana.a, is spreading through social networking sites, including Facebook, disguised as a video. The Trojan is currently appearing as a link in messages on social networking sites with the subject "Is this you in this video?"
When a user clicks the infected link, the Trojan initially runs as a Java applet, which downloads other files to the computer, including an installer, which launches automatically. When run, the installer modifies system files to bypass the need for passwords, allowing outside access to all files on the system.
Additionally, the Trojan sets itself to run invisibly in the background at startup, and periodically checks in with command and control servers to report information on the infected system. While running, the Trojan horse hijacks user accounts to spread itself further via spam messages. Users have reported the Trojan is spreading through e-mail as well as social media sites.
The Java component of the Trojan horse is cross-platform, and includes other files that affect Mac OS X as well as Microsoft Windows. There have been reports of similar behavior in recent Trojan horses targeting Microsoft Windows, but they have not included cross-platform capabilities until now.
The Trojan attempts to hide its internet communications and actions through obfuscated code spread through multiple files, and will attempt to contact additional command servers if the primary servers are unavailable.
This Trojan horse is currently in the wild affecting users of both operating systems.
Users can protect themselves from infection by turning off Java in their web browser. This can be accomplished in Safari by clicking the Security tab under Safari Preferences, and making sure the "Enable Java" checkbox is unchecked.
DAZZLE'S UPGRADE PACK
If you haven't already done so, upgrade your game by downloading Dazzle's all-in-one upgrade pack. It comes with everything you need for today's servers. Does your blue bar freeze when joining servers? Do you lag in games? Do you get an annoying siren in Phobik's Servers? This is what you need. CLICK HERE TO DOWNLOAD.
If you haven't already done so, upgrade your game by downloading Dazzle's all-in-one upgrade pack. It comes with everything you need for today's servers. Does your blue bar freeze when joining servers? Do you lag in games? Do you get an annoying siren in Phobik's Servers? This is what you need. CLICK HERE TO DOWNLOAD.
Boonana Trojan for Mac OS X spreads via social media
- GRRReat
- Popped Bot Head
- Posts: 324
- Joined: Sat Jun 02, 2007 4:42 am
Boonana Trojan for Mac OS X spreads via social media
Words can cut like a sword or heal a deep wound!
-
- Need Major Repair
- Posts: 817
- Joined: Fri Dec 29, 2006 4:03 pm
- Location: Richland, WA
Re: Boonana Trojan for Mac OS X spreads via social media
Looks like you need a antivirus program if your running a Mac....
- LGM
- Site Admin
- Posts: 2102
- Joined: Fri Dec 29, 2006 12:59 pm
- Location: Very Northwest WA
Re: Boonana Trojan for Mac OS X spreads via social media
Yup...
and, if anyone wants it, here's a link to a tool that will remove it.
Free from securemac.com
http://www.securemac.com/boonana/
I had seen a few facebook friends get caught up by the fake page that harvests FB logins and takes over to post those vids... but didn't open them. My computer is clean.
Be careful out there, you mac users. You can be virus attacked too.
and, if anyone wants it, here's a link to a tool that will remove it.
Free from securemac.com
http://www.securemac.com/boonana/
I had seen a few facebook friends get caught up by the fake page that harvests FB logins and takes over to post those vids... but didn't open them. My computer is clean.
Be careful out there, you mac users. You can be virus attacked too.
- parCAT
- Need Major Repair
- Posts: 993
- Joined: Sat Feb 24, 2007 11:30 pm
- Location: MA
Re: Boonana Trojan for Mac OS X spreads via social media
Oh no! I've been getting these at least twice a week from friends on facebook I rarely talk to. Usually in the form of an IM message that Grrreat mentioned--LGM wrote:I had seen a few facebook friends get caught up by the fake page that harvests FB logins and takes over to post those vids...
Luckily, my lack of curiosity allowed me to ignore the links. I assumed their accounts were being hacked anyways, and good thing too. Guess I was right.GRRReat wrote:The Trojan is currently appearing as a link in messages on social networking sites with the subject "Is this you in this video?"
meow !
- Baba
- Need Major Repair
- Posts: 1230
- Joined: Thu Dec 28, 2006 12:05 am
- Location: Oakland, California
Re: Boonana Trojan for Mac OS X spreads via social media
thanks for the heads up!
so far I am still clean
so far I am still clean
Who is online
Users browsing this forum: ClaudeBot [Bot] and 17 guests