Mac Trojan Horse poses as Adobe Flash Installer
The latest attempt from digital wrongdoers to infect your Mac has been spotted taking on the look and feel of Adobe's Flash Installer.
The latest attempt from digital wrongdoers to infect your Mac has been spotted taking on the look and feel of Adobe's Flash Installer.
Despite your feelings on whether you like Flash on your Mac, this Trojan poses a fairly serious threat to those unsuspecting users who may think they are simply updating Flash Player.
F-Secure has named the Trojan Bash/QHost.WB and have provided some insight as to how it works.
Once installed, the Trojan adds entries to the hosts file to hijack users visiting various Google sites (e.g., Google.com.tw, Google.com.tl, et cetera) to the IP address 91.224.160.26, which is located in Netherlands. The server at the IP address displays a fake Web page designed to appear similar to the legitimate Google site.
The Trojan is currently dormant, meaning that while it will take you to the fake Google site, nothing will happen. It is, however, programed to serve pop-up ads once the user has accessed the false IP.
The solution? Only install Adobe updates from Adobe's official Web site. As with any Trojan designed for Mac, the malware only works if the user allows it. Most of the threats currently in the wild can be avoided by simply sticking to paid versions of software obtained directly from trusted creators of the product.
Do you have a Mac security story? Let me know in the comments!