New MacDefender Variant Installs Without Admin Password Requirement
Intego, antivirus firm, has discovered a new variant of the"MacDefender" malware that not requires an administrator password for installation.
Unlike the previous variants of this fake antivirus, no administrator's password is required to install this program. Since any user with an administrator's account - the default if there is just one user on a Mac - can install software in the Applications folder, a password is not needed. This package installs an application - the downloader - named avRunner, which then launches automatically. At the same time, the installation package deletes itself from the user's Mac, so no traces of the original installer are left behind.
The second part of the malware is a new version of the MacDefender application called MacGuard. This is downloaded by the avRunner application from an IP address that is hidden in an image file in the avRunner application's Resources folder.
Yesterday Apple issued its first public notice on the MacDefender malware, providing users with steps for avoiding or removing the software. It is unknown whether protection against the new "MacGuard" variant will be included in the software update from Apple.