The Mudcat Café TM
Thread #137558   Message #3146894
Posted By: JohnInKansas
03-May-11 - 01:17 AM
Thread Name: Tech: Osama Death causes Malware Explosion
Subject: Tech: Osama Death causes Malware Explosion
Warnings are up:

Malware Specifically targets Mac Users

Malware attack specifically targets Mac users

By Rosa Golijan

It's not unusual for a new malware attack to pop up on the Internet every other moment, but the latest vicious bit of software floating around is particularly fascinating because it specifically targets Mac users.

The Next Web reports that a malware version of the popular MacDefender antivirus application is confusing and infecting a great number of Mac users right now:

Early reports show that users have been targeted as they search Google Images, one user stating that the bogus MacDefender application was automatically downloaded as he browsed images of Piranhas. Further searching through the Apple Discussion boards suggests that the malware campaign is targeting users of Apple's Safari browser, displaying warnings that the user's computer has been infected with viruses that only the unofficial MacDefender application can remove.

Part of the reason many are being easily infected by the malware is that Safari — the default browser in Mac OS — can be set to automatically open trusted software. This means that users are getting infected without even a hint of what's happening until the malicious app demands payment for "protection" like a digital mob boss.

The good news? So far it doesn't appear that the malicious MacDefender app does much, other than attempt to scare people into forking over their credit card numbers. It can even be easily removed:

1.        To ensure you do not automatically download the app, uncheck the following: Safari > Preferences > General > uncheck "Open 'safe' files after downloading."

2.        Searching for the application and deleting it directly may fail, saying the app is in use. To stop it running, check Activity Monitor (in Applications > Utilities) and disable anything that relates to MacDefender.

3.        Look in /Library/StartupItems and, same place, LaunchAgents and LaunchDaemons for references to the malware app.

4.        Once quit, head to the Applications folder and drag the MacDefender app to the trash, then delete trash.

5.        To ensure all references to the app are cleared, run a search using Spotlight and delete all MacDefender references you find.
As a precaution, it would be wise for Safari users to toggle the "Open 'safe' files after downloading" setting whether they're infected or not. It could prevent attacks similar to this one.
Rosa Golijan writes about tech here and there. She's a bit obsessed with Twitter and loves to be liked on Facebook.

And for EVERYBODY

Bin Laden death brings malware explosion

By Suzanne Choney

With the biggest news in a decade dominating the Internet, it didn't take long for rogue viruses, Trojans and other malware to mess with computers given the chance.

Web searches and links to a variety of stories — real and fake — about the death of Osama bin Laden are sprouting with all kinds of malicious software as cybercriminals look for a big payday tied to the appetite for news about the Al-Qaida leader's demise.

"The bad guys were quite fast and started to poison searches results in Google Images," said Favio Assolini, a Kaspersky Labs expert on the security software company's blog. "Some of the search results are now leading users to malicious pages."

As an example, Assolini shared a Google search page with the words "osama bin laden body" typed in the search box. "When clicking an image in the results page, the user will be redirected to one of the malicious domains," antivirus.cz.cc/fast-scan/ and pe-antivirus.cz.cc/fast-scan/, he said. Both are "offering" a copy of rogueware called "Best Antivirus 2011." And both can bring your computer down.

"When searching, even for images, be careful," Assolini warns.
And the computer programmer quickly becoming known "the guy who liveblogged the Osama raid without knowing it" even found his own blog server stricken by malicious software.

"It is a good thing my blog server is infected with malware today, I guess :-/" Sohaib Athar said on his Twitter page, after being inundated with questions by journalists and Twitter followers.
But it is NOT a good thing if you click on Athar's website that's listed on his Twitter page. That's where some malware is sprinkled, and you could get hit.

Christen Gentile of Kaspersky Labs' said as Internet users search for bin Laden news, "they should be aware of two new types of scams that are ready and waiting to take advantage of them."

Cybercriminals, Gentile said, have begun search engine optimization efforts, where they "take popular search terms," like bin Laden or anything associated with him or his death, "and use them to direct people to malware ... in popular search engines, trying to lure users to install rogueware."

Search results in Google images have been poisoned, he said. "Some of the search results are leading users to malicious pages. Upon clicking on this search result or image, the user will be redirected to a malicious domain which can infect the user's computer."

Also, on Facebook, where an "Osama bin Laden is DEAD" page sprouted up, there are some advertising offers celebrating bin Laden's death and offering "free tickets or free sandwiches, in some cases," Gentile said. "By clicking on these ads, users will be redirected multiple times, each time asking for more information, resulting in the potential gathering of email addresses or sensitive information."
advertisement

For more information on the Facebook scram, check Kaspersky Lab's blog.

SophosLabs has a good guide to help you decide what to do:
Watch out for the links you're likely to come across in email or on social networking sites offering you additional coverage of this newsworthy event.

Many of the links you see will be perfectly legitimate links. But at least some are almost certain to be dodgy links, deliberately distributed to trick you into hostile internet territory.

If in doubt, leave it out!

Sometimes, poisoned content is rather obvious. The links in this spam captured by SophosLabs, for example, give the impression of going to a news site:

"If you go to a site expecting to see information on a specific topic but get redirected somewhere unexpected — to a 'click here for a free security scan' page, for instance, or to a survey site, or to a 'download this codec program to view the video' dialog — then get out of there at once. Don't click further. You're being scammed," says SophosLabs' Paul Ducklin on the company's blog.

So be extra careful on the Interwebs today, kids. Don't do what I did — click on a link that I thought was legitimate, only to be hit with a rogue installation of a Windows "Total Security Removal" Trojan that flashed fake security alerts and installed itself on my computer without my permission.

I'm working to get if off the laptop right now, and writing this on another computer. It's a Mac, but from colleague Rosa Golijan's report today, I see that's not safe, either.

[end quotes]

John