Latest Mac trojan spreads through Microsoft Word documents
Kasperskky lab expert discovered that a new version of a backdoor trojan for Apple's OS X operating system takes advantage of an exploit in Microsoft Word to spread.
The new Mac-specific trojan, named "Backdoor.OSX.SabPub.a," uses a Java exploit to infect targeted machine. It spreads through Microsoft Word documents that exploit a vulnerability known as "CVE-2009-0563." There are currently at least two variants of the "SabPub" trojan, which remains classified as an "active attack." It is expected that new variants of the bot will be released in the coming weeks, as the latest was created in March.
He also found that an infected machine was taken over by a remote user who started analyzing the machine and even stole some documents from the Mac.
"We are pretty confident the operation of the bot was done manually — which means a real attacker, who manually checks the infected machines and extracts data from them," - Kasperskky lab expert wrote in a post to SecureList.
Follow us on