Apple promises malware removal tool for Flashback trojan
Detection, removal already possible with commercial antivirus software
Posted: Apr 11, 2012 10:46 AM ET
Last Updated: Apr 11, 2012 12:30 PM ET
Apple says it is developing software that will detect and remove malware estimated to have infected more than 650,000 Macs running the OS X operating system.
Apple posted the information on a page about the malware known as "Flashback" in the support section of its website, which was updated Tuesday.
The page also describes how Mac users can protect themselves from the trojan malware, which infects computers via a vulnerability in Java, plug-in software needed for web browsers to run certain kinds of applications. Infected computers become part of a botnet of thousands of computers that can be remotely controlled by special servers to conduct activities such as delivering spam and taking part in denial-of-service attacks.
The malware can be detected and removed by some commercial, third-party antivirus software packages, or it can be removed manually by advanced users.
Apple noted that it released a Java update on April 3 that fixes the Java security flaw on computers running OS X v10.7 and Mac OS X v10.6. However, it said users running Mac OS X v 10.5 or earlier should disable Java in their web browser preferences.
An entry posted Wednesday on the Naked Security blog, run by the antivirus software company Sophos, noted that Apple hasn't provided a patch for users of OS X v10.5 or earlier "and isn't saying if it will ever do so."
It also noted that patching Java reduces the chance of infection, but doesn't rule it out, and users who install the patch may still have become infected before installation.
Apple changes security approach
Paul Ducklin, Sophos's head of technology in the Asia Pacific and the author of the post, said Apple's acknowledgement that it is working on a detection and removal tool is a big step, considering that the company traditionally says it "does not disclose, discuss or confirm security issues until a full investigation has occurred and the necessary patches or releases are available."
Macs have traditionally been rarely targeted by the makers of malicious software, who have tended to focus instead on PCs. The Java vulnerability was patched for the PC operating systems Windows, Linux and Unix back in February.
The Mac Flashback trojan epidemic, Ducklin wrote, is "bad luck, this time, for Mac users, but perhaps good news in the long term. If nothing else, Apple's security team has touched down on Planet Earth." He added that the company's decision to share information about the security flaw early is better for everyone.
According to Dr. Web, a Russian antivirus software maker that has been studying the virus, there were 655,700 Macs infected with Flashback as of Tuesday, a rise from 550,000 on April 4. At that time, 20 per cent of infected computers were in Canada. Another 57 per cent were in the U.S.
The Flashback trojan can be detected using a number of antivirus services, including a free one from Dr. Web and Sophos's free Anti-Virus for Mac Home Edition, which also removes it.
The antivirus software maker F-Secure has posted instructions for manually removing Flashback, but warns that it is a risky process "recommended only for advanced users." The company advises other users to seek professional technical assistance.
Top News Headlines
- Obesity now recognized as a disease
- The American Medical Association has voted to recognize obesity as a disease, while doctors in Canada say they also treat it as such. more »
- B.C. First Nation sets fires to save bison
- A First Nation band is reviving the age-old practice of controlled burning in order to improve the health of forests and restore the population of the wood bison in a corner of northeastern B.C. more »
- 1 in 8 bird species threatened with extinction
- One in eight bird species worldwide faces the threat of extinction, according to a report released by Birdlife International. more »
- Canada buys rare War of 1812 collection for $573K
- The government of Canada was the winning bidder for a large collection of letters, maps and other papers that once belonged to Sir John Sherbrooke, the lieutenant-governor of Nova Scotia who conquered Maine for the British during the War of 1812. The collection sold for $573,000 at auction in London. more »
Latest Technology & Science News Headlines
- How open is Ottawa's new 'open data' website?
- Treasury Board President Tony Clement is touting the federal government's revamped data portal as a "new natural resource." But that online window for previously published data arrives at the same time the government faces controversy over just how open it really is. more »
- Genetically-modified crop inventors win World Food Prize
- Three pioneers of plant biotechnology whose work brought the world genetically modified crops have been awarded this year's World Food Prize. more »
- Anti-social media app helps you avoid other people
- A cheeky new app, billed "an experiment in ant-social media," leverages a user's own social network to decrease the likeliness of actually crossing paths with someone in it. more »
- 'Tweet' gets 21st century update in Oxford dictionary
- Tweeting in the social-networking sense has become so pervasive that the Oxford English Dictionary has broken one of its own rules to add new meanings for "tweet" as both a noun and a verb. more »
Bob McDonald's Blog
- After Hadfield, who's the next Canadian in space? Jun. 13, 2013 12:01 PM Canada's singing astronaut announced his retirement this week, leaving Jeremy Hansen and David Saint-Jacques to fill his space boots. But there is no date set for when the next Canadian will fly in space.
Quirks & Quarks
- June 22: How to Build a Brain Jun. 19, 2013 10:42 AM Scientists are embarking on ambitious projects to understand the incredible complexity of the human brain and to simulate it in a computer. They hope it will help us understand mental disorders, as well as the nature of thought, memory, and conciousness.
- Sopranos star James Gandolfini dies in Italy
- Bob Rae quits as MP in 'very emotional' decision
- Wearing a mask at a riot is now a crime
- 2 men jailed in Dominican wedding fight back in Canada
- B.C. teacher duct-taped students' mouths
- Obesity now recognized as a disease
- Dozens of children seized from Manitoba Mennonite community
- Half of First Nations children live in poverty
- Huge ancient city at Angkor Wat revealed by lasers