Slashdot Mirror


Mac Trojan Horse Disguised as Word 2004

Espectr0 writes "Macworld is alerting of a malware program for the Mac. A Macworld reader alerted the magazine to the malware after he downloaded the file from Limewire. The reader told Macworld: 'I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta. The file unzipped, and to my delight the Microsoft icon looked genuine and trustworthy.' However, he added: 'I clicked on the installer file, and to my horror in 10 seconds the attachment had wiped my entire Home folder!'" This sounds similar to the recent trojan horse proof-of-concept. There are many ways to make one file look like another, on any platform. This is 2004, you should know by now not to open a file from an untrusted source.

4 of 785 comments (clear)

  1. Not like the recent warning by Anixamander · · Score: 5, Informative

    This sounds similar to the recent trojan horse proof-of-concept

    This is nothing of the sort. The recent warning was for mp3 or other non-executable looking files carrying a trojan horse payload...that is far sneakier than this. This is simply a program that doesn't do what it claims to do. He expected an executable, he got an executable. An if he really thought that Microsoft would relase a public beta through limewire...well, caveat emptor and all.

    Since it only deleted his home directory, it probably wasn't that sophisticated. I'm surprised it didn't attempt to escalate privilieges under the guise of an installer and do even more damage.

    I suppose I should make a clippy joke here (I'm really tempted), but I actually like office X and am looking forward to the next version.

    --
    Do not taunt Happy Fun Ball(TM)
  2. Re:Fast User Switching Rules... by Bullet-Dodger · · Score: 5, Informative

    Little Snitch is good for preventing anything from phoning home. Does have slightly annoying behavior unless it's registered, however. Anyone know of an OSS program to do this?

  3. Re:"Darwin" - style award winner by bamf · · Score: 5, Informative

    Actually I think you'll find that it fits the defintion of Trojan Horse perfectly.

  4. Like in biology, viruses have hosts by Theatetus · · Score: 5, Informative

    Just to clear things up for you:

    • A virus is a program that runs in the memory space of another executable and replicates itself to other instances of that executable; essentially, it's an unwanted plug-in.
    • A worm is a program that replicates itself against the user's wishes without requiring another executable as a host.
    • A Trojan horse is a program that masquerades as a desired program in order to gain access to the user's system. Trojan horses may or may not replicate themselves.

    This is pretty clearly a Trojan horse: it advertised itself to the lUser as a copy of Microsoft Word in order to gain access to his system. The payload of the unwanted software (be it virus, worm, Trojan, or something else) is irrelevant to its classification.

    --
    All's true that is mistrusted