Cybercriminals create botnet using Mac computers
Last Updated: Wednesday, April 15, 2009 | 5:38 PM ET
CBC News
Related
External Links
(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)
Traditionally, botnets have spread through PCs running Windows, and not Macs, in part because of the low market share worldwide of computers like the iMac, shown here behind Apple CEO Steve Jobs in a 2006 photo.
(Paul Sakuma/Associated Press)A piece of malicious software unwittingly shared over a peer-to-peer network in January was the key tool in what security researchers are saying was the first known attempt to create a botnet of Mac computers.
Researchers at Symantec say the Trojan, called OSX.Iservice, hid itself in pirated versions of the Apple application iWork '09 and the Mac version of Adobe Photoshop CS4 that were shared on a popular peer-to-peer bittorrent network.
Once downloaded, the applications themselves worked normally, but the Trojan opens a "back door" on the compromised computer that allows it to begin contacting other hosts in its peer-to-peer network for commands.
Researchers Mario Barcena and Alfredo Pesoli of Symantec Ireland, writing in the April 2009 issue of the Virus Bulletin, say the network of infected computers attempted to initiate a denial of service attack on a website in January.
"OSX.Iservice is an interesting piece of malware — not only does it make use of Mac OS internals, but it is also the first Mac botnet that we are aware of," they wrote.
A botnet, or robot network, is a group of linked computers — sometimes called zombies — that have been commandeered, in some instances by criminals, to perform a host of actions, from connecting and infecting other computers to sending out spam or launching distributed denial of service attacks to bring down websites or web servers.
But traditionally, botnets have spread through PCs running Windows, and not Macs, in part because of the low market share of Macs worldwide.
Apple had 7.2 per cent of personal computer market share in the United States in the fourth quarter of 2008, according to technology analyst IDC, but was not among the top five PC makers worldwide, as ranked by shipments.
Kevin Haley, director of Symantec Security Response, said cybercriminals who want to create a botnet of computers traditionally attack machines running Microsoft's Windows operating system because the goal is to have the biggest network possible.
"It's a numbers game," said Haley. "If you're going to go after the largest market, you have to go after the largest target."
An example of a particularly successful botnet is the one created by the Conficker worm, which by some estimates is believed to have spread to as many as 12 million machines.
By comparison, the iBotnet, as the Symantec researchers have dubbed it, spread to only a few thousand computers before it was identified. A number of security firms say removal of the Trojan is simple once it has been identified.
The method used to infiltrate the computers — tricking users to install a Trojan hiding in a free version of software — is also a fairly basic way to access a computer, said Haley, and is not a technique exclusive to Macs or any particular vulnerability inherent in the computer's operating system.
Haley said downloading any file from an unknown source is a potentially dangerous practice, no matter what computer a person uses.
The malicious software, or malware, is unique, however in that it only clearly targeted Mac users and also included a variation — found in the corrupted Adobe Photoshop CS4 file — that used some of the functions on the Mac OS that relate to its own authorization services interface, according to the Symantec Ireland authors.
"With malware authors showing an increasing interest in the Mac platform, we believe that more advanced [user interface] spoofing tricks may be seen in the future," they wrote.
Ryan Naraine, the security evangelist at Kaspersky Lab, said that while a Mac botnet may not be practical for criminals, the discovery of the Trojan is proof that no operating system is inherently safe.
Share Tools
Top News Headlines
- Aylmer triple stabbing leads to first-degree murder charges

- The estranged partner of a young mother who was stabbed to death along with her parents at their home in Aylmer, Que., has been charged with first-degree murder Friday. more »
- Wildfires, high winds put northeastern Ontario on alert
- It's going to be a tense weekend in northeastern Ontario where strong, shifting winds have been fuelling a forest fire that has blanketed the Timmins area with smoke and ash. more »
- Labrador fire out of control
- A forest fire continues to burn out of control in Happy Valley-Goose Bay today, according to provincial firefighting officials. more »
- The risks and responsibilities of taking on Mt. Everest

- The deaths of five climbers last weekend on Mt. Everest, with more summits underway this weekend, fuels the debate about the risks and responsibilities of high altitude climbing. more »
Latest Technology & Science News Headlines
- Unloading of docked SpaceX capsule to start Saturday
- The privately bankrolled SpaceX Dragon capsule made a historic arrival at the International Space Station on Friday, and astronauts will begin unloading some of the 544 kilograms of food, water, clothing and other supplies its carrying starting Saturday.
more »
- South Africa, Australia to share world's largest telescope
- South Africa and Australia will jointly host the Square Kilometre Array, which promises to be the world's largest telescope, the international consortium in charge of the project said Friday. more »
- Bonavista, N.L., 'coyote' was really wolf, tests confirm
- Wolves have not been seen in Newfoundland since around 1930 and were believed to have been hunted to extinction on the island, but genetic tests have confirmed that an 82-pound animal shot on the Bonavista Peninsula in March was, in fact, a wolf. more »
- Once-rare argus butterfly thriving thanks to climate change
- Global warming is threatening the existence of many species, such as the giant polar bear, but in the case of Britain's brown argus butterfly, it took a species in trouble and made it thrive. more »
- Yahoo scraps digital magazine designed for iPad
- Yahoo has killed Livestand, a tablet magazine, just six months after its debut on the iPad. more »
Bob McDonald's Blog
Government to shut down unique fresh water research area May. 25, 2012 12:31 PM The Experimental Lakes Area research facility in Northern Ontario is being closed down after 44 years of providing invaluable data to scientists in Canada and internationally, a decision that has stunned researchers and environmental groups.
Quirks & Quarks
- May 26: Before the Lights Go Out May. 25, 2012 4:15 PM A new book, "Before the Lights Go Out: Conquering the Energy Crisis Before It Conquers Us", suggests that the unpredictable, unplanned, ad-hoc way our energy use developed in the past will shape our energy future.
Latest Features
- Aylmer triple stabbing leads to first-degree murder charges
- Everest victim's husband says family not seeking government help
- B.C. premier unhappy with disgraced Mountie's transfer
- Canada ending 'Buffalo shuffle' for visas, closing consulate
- What a Greek euro exit could mean for Canada
- Third B.C. salmon farm quarantined
- RCMP officer charged in fatal crash
- Police probe Halifax homicide after shooting
- Ottawa man in hospital after lightning strike

