New OS X trojan injects ads into pages in Chrome, Firefox, and Safari
thenextweb.com
thenextweb.com
It won't send you any emails, but it will prevent rogue software from being installed.
I would expect to see a higher penetration on Macs, since I assume people using Macs don't have the higher level of paranoia that has been engendered in Windows.
---
Hey, I want to watch this video/movie/clip/trailer but I need to download and install this tool first, alright, click click click, hey, my trailer didn't show up. On to the next website I go.
---
There is no good way to stop crap like this either, the user is willingly installing it themselves, people hate the walled garden that iOS has become, and that OS X is becoming with the App Store, yet that is one of the ways that the OS can be secured. You have people up in arms about it being closed off or being inaccessible because of these new restrictions, but at the same time people want to be able to install whatever they want.
Whitelisting is the only real secure way to make sure that the wrong app doesn't run. Blacklisting means you are always chasing the ball and the target.
'People' say a lot of things. I've personally never heard a non-geek complain about Apple's 'walled garden'. Mac and iOS device sales are higher than ever.
It's trivial for publishers to detect Yontoo's technology, and alert people when it's happening. Something as simple as:
try{if(new ActiveXObject("YontooIEClient.Api"))found=!0;}catch(e){};
try{found=!!localStorage['y2LocXML'+location.pathname];}catch(e){};