No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

Flashback, Trojan, hides, inside, Safari
In a case of a malware purveyor attacking pirate file-sharers, security vendor Sophos has...
The Storm (aka Peacomm, Dorf, Small and BAI) attack that previously spread under the...
UK-based Internet security firm SurfControl has detected a malicious threat disguised as a link...
Experts at anti-virus vendor Sophos's global network of virus and spam analysis centres, have...
Security experts from anti-virus vendor Symantec have identified the first Trojan that targets Sony...

Flashback Trojan hides inside Safari

Business IT - Security

 

A new version of the Flashback Trojan targeting Mac OS X is just that bit more insidious than its predecessors.

 

The Flashback Trojan first appeared last month. Posing as an Adobe Flash installer, it installed code that could send information about the computer, and also had the capability to download additional malware.

 

The latest variant - Flashback.D - hides its payload not in the user's Preferences folder (it could previously be found at ~/Library/Preferences/Preferences.dylib), but inside the Safari application bundle.

Security company Intego has revealed that the Trojan now installs its payload as /Applications/Safari.app/Contents/Resources/UnHackMeBuild, and adds an entry to Safari's Info.plist file (/Applications/Safari.app/Contents/Info.plist) that loads it when Safari starts.

That Intego blog entry explains the two-step process needed to manually remove Flashback.D.