Home Business IT Security Intego warns of buggy Mac malware
Get all your tech news delivered to your mail box five days a week
iTWire UPDATE - it's FREE!


Security vendor Intego is warning Mac users of a new piece of commercial malware.

NetWeirdRC is a commercial backdoor tool targeting Mac OS X 10.6 and later, as well as Windows, Linux and Solaris, according to Intego.

Sold for as little as $US60, NetWeirdRC 'phones home' after installation and awaits commands to carry out functions including installing files, executing commands, stealing browser passwords and taking screen shots.

The good news is that due to an apparent bug, NetWeirdRC does not run after the Mac is restarted.

Instead of adding itself to the Login Items list, it adds the user's home folder. That would presumably be easy to fix now the developer has been made aware of it.

Intego speculates that the malware would be distributed either via a custom dropper or by inducing recipients to open the file (eg, by attaching it to an email with a persuasive cover story).

RECRUITMENT & RETENTION REPORT 2013

HIRE OR FIRE? BUY OR BUILD

2013 is well underway and Australian companies need to know whether they should invest in IT skills training or pay a premium for the people they need.

If you want to know which choices are being made in your sector, what skills are hard to find, which sectors intend to hire or fire and where the IT spend is going, this free report is must have.

GET YOUR REPORT NOW

Stephen Withers

joomla visitors

Stephen Withers is one of Australia¹s most experienced IT journalists, having begun his career in the days of 8-bit 'microcomputers'. He covers the gamut from gadgets to enterprise systems. In previous lives he has been an academic, a systems programmer, an IT support manager, and an online services manager. Stephen holds an honours degree in Management Sciences, a PhD in Industrial and Business Studies, and is a senior member of the Australian Computer Society.

Connect

http://bs.serving-sys.com/BurstingPipe/adServer.bs?cn=tf&c=19&mc=imp&pli=5460041&PluID=0&ord=[2000]&rtu=-1