X

Apple quietly adds anti-malware in Snow Leopard update

The company didn't mention anything about adding an anti-malware update to OS X 10.6.4, which it released on Tuesday, Sophos says.

Elinor Mills Former Staff Writer
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service and the Associated Press.
Elinor Mills
 
Apple has updated the file that contains signatures of malware that targets the Mac in its Snow Leopard update. Sophos

In the latest update to Snow Leopard, Apple included software to protect Mac computers from a Trojan horse that has been distributed by attackers disguised as iPhoto, but which opens a back door on the machine, security firm Sophos said on Friday.

When Apple released OS X 10.6.4 on Tuesday, the company said it addressed certain compatibility issues with VPN connections and other things, but failed to mention anything about adding an anti-malware update.

But buried in the code is an update to the XProtect.plist file, which contains signatures of malware written to target the Mac. The signatures now detect malware dubbed "HellRTS," Graham Clulely of Sophos wrote in a blog post.

HellRTS, which Sophos detects as "OSX/Pinheard-B," is a Trojan that has been around several months. It lets attackers use infected computers to send spam, take screenshots, access files, and pretty much take control of the computer, Sophos said.

"Unfortunately, many Mac users seem oblivious to security threats which can run on their computers. And that isn't helped when Apple issues an anti-malware security update like this by stealth, rather than informing the public what it has done," Clulely writes. "You have to wonder whether their keeping quiet about an anti-malware security update like this was for marketing reasons. "Shh! Don't tell folks that we have to protect against malware on Mac OS X!"

Representatives from Apple did not immediately return e-mails seeking comment on Friday afternoon.