No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

Flashback, Trojan, poses, Flash, Player, installer
Dell has begun offering flash storage as an alternative to a conventional disk drive...
Intel has joined the trend to solid-state drives based on NAND flash memory with...
It may have taken two and half years to develop and be, as Steve...
Despite lower capacity and higher prices, flash memory will continue to outpace hard drives...
Nokia has continued its dizzying pace of innovation in mobile devices with a series...

Flashback Trojan poses as Flash Player installer

Business IT - Technology

Are Mac malware writers getting smarter? A recently discovered Trojan deactivates a popular security tool.


Following the discovery of the Revir Trojan, security companies are warning of another new Mac Trojan, this time posing as an Adobe Flash installer. Dubbed Flashback by Intego (apparently the first to report it), the Trojan disables Little Snitch, a security product intended to alert users of any attempt by software to 'phone home'.

It seems Flashback has been seen in the wild, with unspecified malicious web sites providing links to what purports to be Flash Player, but is actually Flashback. When downloaded and launched, the file opens in the normal Mac OS X Installer, whereas the real Flash installer is self-contained.

Flashback deactivates Little Snitch and installs a dynamic loader file (~/Library/Preferences/Preferences.dylib) that sends information to a remote server. Intego officials describe the code as "quite sophisticated".

Information transmitted includes the Mac's UUID and the Mac OS X version number. The code has an auto-update mechanism, and is also able to download additional software.

If you suspect a Mac may be infected with the malware, look for the ~/Library/Preferences/Preferences.dylib file.

Page 2: Getting Flash safely.