Apple support forums confirm malware explosion
zdnet.com
zdnet.com
The naysayers who want to downplay this as business as usual are wrong.
I have had three cases of this within two weeks at my company. Prior to that time, I have not had a single piece of Mac malware infect my machines over a period of 8 years.
This is not business as usual. I expect to find a whole lot more of this in the near future, and for the first time since I've managed IT at this company, I'm researching anti-malware solutions for Mac.
I'd advise you to educate your users (as not to enter their passwords every time the computer asks them for no apparent reason), run proper backups and check Safari (and other browser) defaults.
Do you really think that Mac users are inherently less gullible than Windows users?
I have been in this business long enough to know that there are always certain users who will click anything that pops up on their screen, no matter how clearly you try to convince them otherwise. If education solves your future Mac virus problem, then more power to you. But that's just not the real world.
Understandably, this would require you to micro-manage all your users who want to have their own, specialized setups, but...
Good luck with your search for anti-malware. For what I have seen on the windows side of the fence, things aren't pretty.
Any real solution goes through user education. When they know what to expect from their computers, they become much more difficult targets. You may enlist the help of some clever programs, but software won't solve the problem.
Why is it that you assume that I am not educating my users just because I am looking into Mac anti-virus software? Did I say that anti-virus software is the end-all be-all of security?
I have windows users here also. Every one of them runs anti-virus, and it has saved my department countless hours cleaning or rebuilding machines. I have the metrics to prove it.
If you really think that an enterprise can get along with education alone, you clearly have not spent much time in the IT support trenches, dealing with the average computer user.
By the way, all this only encourages me to keep using ADBlock+ ...
It doesn't help that there's a setting in Safari to automatically run "safe" downloads.
I'm intensely curious about how far this thing goes. If it were to, say, start hooking into launchctl ... well, that would be interesting indeed.
This feature has always struck me as a cordial invitation from Apple to trick their users via some means or other.
The "safe download" social engineering attack was outlined years ago, so it's somewhat surprising it took this long to widely exploited.
Which was the right thing to do, by the way. I don't want disk images running shell scripts when they are mounted manually OR automatically.
If normal users keep their random application installing limited to the app store they should be fine. If you DO install "video players" from porn sites or download stuff off the pirate bay, you might end up with malware...
From TFA:
EB: So customers who get hit by this are installing it and giving their admin password?
AC: Yes.
As a consequence, users are trained to give their password to random apps, and they end up not paying attention anymore to which app they give it to.
EDIT : Disclaimer : im mostly a linux user.
"somebody accustomed to being told that the computer is always right" -- if they believe that, it's stupid, and they have worse problems than malware.
I'm getting so tired of this blame-the-user-for-everything attitude on Slashdot, HN, and elsewhere.
Some of the blame belongs to Apple/Safari. You see, Safari's default settings allow for the automatic download and execution of "safe content".
The clever authors of MacDefender/MacProtector packaged things up so that by merely visiting a hostile web page in Safari, it causes Safari to automatically download and automatically run the MacDefender/MacProtector installer.
For example, you may be browsing Google Images. You click on one. The next thing you know, and this happens in just a second or two on a broadband connection, the installer program for MacDefender/MacProtector is running.
Now fortunately, the installer process itself is benign. If you quit the installer, you won't get infected. If you continue through the installer, however, the Trojan will be installed.
I can see how a lot of people might think Apple automatically pushed out an anti-virus, or something, and that's why the installer starting running automatically.
Feel free to blame the user all you want...right now, it seems very popular to blame "those stupid users" for everything. But in this case, Apple/Safari deserve a nontrivial share of the blame for Safari's outstandingly asinine defaults.
The fact the the install process is benign is not "fortunate" though -- to qualify as "safe" they're running Apple's installer from a pkg. If they provided their own installer, the installer wouldn't be considered by Safari to be "safe" and the whole thing wouldn't work.
I'm glad that systems are finally getting the same kind of package management that we have enjoyed on Linux for well over a decade, but it's a serious bummer that it has to come with such scammy-feeling commercialistic trappings before it can be brought to the masses. It's hard to put my finger on the feeling exactly.
Frankly, what's wrong with a package management system that charges consumers and pays commissions to the host?
In Ubuntu, I never, ever install one-off DEBs. Every single piece of software is installed through a repo. I'm able to trust that software and I don't let other apps get root privileges unless I grant them and know what's going on.
The Apple App Store is not a package management system. It's a store. Developers have to relinquish control and money to have their apps listed there. Thus, many apps must still be installed manually. It's not an open ecosystem and it's not really fair to compare them.
Synaptic and trusted repositories saves me from malware because there is no reason not to use them. There are many reasons not to use Apple's.
Except for iOS, usually you can still optionally install software in another way, or even create your own repository (Linux packages, Android markets). So the "tainted" bit is the totalitarian aspect of it.
And, most of the time, Linux uses an app store. We just call it Synaptic.
As far as developers are concerned, they'll be welcome to purchase Mac Pros at their usual insane markup.
if they do, I'll finally switch to Linux
Ditto, and Apple won't care one bit about losing us.
Just as Gruber doesn't say nice things about Microsoft and/or Windows, neither do Ed Bott and Mary Jo Foley say nice things about Apple and/or OS X.
Ed Bott's Windows Expertise: http://www.edbott.com/weblog/
Ed Bott's Microsoft Report: http://www.zdnet.com/blog/bott
Mary Jo Foley's All About Microsoft: http://www.zdnet.com/blog/microsoft
You can safely ignore 95% of everything these guys say about what they perceive to be the opposition. They make Gruber's bias look like child's play.
Until last week, Mac malware was as common as unicorns. Now there is one. And, as pointed out, Safari's default behaviour of running stuff it deems safe automatically is very dangerous.
That might be true if "malware" includes only exploits that call attention to themselves and disseminate indiscriminately.
But OS X has many times been the first OS to fall in the pwn2own competition, and since there has long been a market in OS X exploits, clearly some Mac have been being compromised.
- The Mac is often the best Pwn2own gizmo - It gives high cred to whoever pwns it. - Nobody pays as much attention to owning a Windows box - Windows vulnerabilities may get more than the Pwn2own prize on the market.
Sophos free for Mac: http://www.sophos.com/en-us/products/free-tools/sophos-antiv...
Avast (beta) free for Mac: http://forum.avast.com/index.php?topic=78646.0
ClamXav (free) for Mac: http://www.clamxav.com/
Be careful out there folks. You don't know what's on the other end of that link.
1. You click a link in Safari
2. The installer package is downloaded
3. Safari unpacks it and executes the installer
Note: you are not infected yet
4. The user completes the installer wizard, entering their password along the way
5. The computer is "infected"
This sucks, but it's not a drive-by infection. Yet.
Chrome does not unpack and run downloads, so you'd have to execute the downloaded package yourself.
"I have never found more than one or two in-the-wild reports. This time, the volume is truly exceptional."
I went to the forums and searched for Mac Defender, Apple Security, and Mac Protector and found a few dozen posts. Plenty of people posting straightforward solutions.
Definitely a nice piece of linkbait.
1. AV program catches the attempt, prevents the installation.
2. Much simpler from Apple's perspective: prevent installation from outside the App Store.
I am not unfamiliar with Apple’s forums. I’ve done similar searches in the past, especially after reading some of those same posts that Gruber called out from 2008. I have never found more than one or two in-the-wild reports. This time, the volume is truly exceptional.
This appears to be the first widespread malware attack.
It looks as if it's now requiring much less stupidity to get malware on the mac, but that's really all that's changed. Email scams are now considering the fact that I might be using a mac.