Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

French security firm bashes Microsoft for talking up Mac malware

Threat from Mac 'backdoor' just isn't credible enough to mention, says Intego

A Mac security firm today criticized Microsoft for warning Mac users of new malware, saying that the threat simply wasn't worth mentioning.

Late Monday, the Microsoft Malware Protection Center (MMPC), the group that researches malware and crafts signatures for the company's antivirus products, alerted users of a new Mac "backdoor," a program that, once installed, downloads additional attack code or lets hackers steal files from the compromised computer.

In a blog post, Microsoft malware engineer Meths Ferrer said that MMPC had found the backdoor, dubbed "Backdoor:MacOS X/Olyx.A," in an archived file that also contained a Windows backdoor called "Wolyx.A."

According to Ferrer, Olyx.A disguises itself as a Google application support file when run by the user, then establishes a remote connection to an IP address hosted in Seoul, South Korea.

But Intego, a French antivirus company that focuses exclusively on the Mac, took exception to Ferrer's blog post.

"They're making it out like this is something serious, but it's not in the wild at all and not being installed," said Peter James, a spokesman for Intego. "This is no big deal."

A backdoor must either be manually installed by a user -- perhaps after being tricked into running the file -- or packaged with other malware that exploits a vulnerability or uses social engineering tricks to get the victim to run the program, said James.

There's no evidence that Olyx is in wide circulation or being used by other malware, such as Mac-specific "scareware," the phony antivirus software that fools people into installing it after faking security alerts.

"It could so stuff if it was in the wild, but it's not," argued James.

It's rare to see one antivirus firm bash another for issuing a warning or alerting customers to a possible threat. But that didn't stop Intego, which saw Ferrer's blog as counterproductive.

"We get criticized every time we issue a security alert," said James, adding that people accuse it of crying wolf about threats to the Mac, which has historically been relatively immune to attacks because of its small market share.

Cyber criminals with profit in mind are much more likely to target Windows simply because Microsoft's operating system powers nearly 90% of the world's personal computers.

"When something is a real threat, we'll say something," said James. "If it's not, we don't publicize [the malware] by issuing an alert. We've got other things to do."

Intego created an Olyx definition for its VirusBarrier product on June 30.

"It's kind of interesting that Microsoft took a month [to mention Olyx] after it started circulating," James said, taking another swipe at the Redmond, Wash developer. "Maybe this is a sign that they're going to be analyzing more Mac malware in the future."

Other security companies have also made mention of Olyx, including Kaspersky Lab, which highlighted the backdoor in a malware report for June 2011.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed. His e-mail address is gkeizer@computerworld.com.

See more articles by Gregg Keizer.

Read more about security in Computerworld's Security Topic Center.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Apple, Google, Intego, Kaspersky, Kaspersky Lab, Microsoft, MPC, Topic
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Google, Intego, Mac OS, Malware and Vulnerabilities, Microsoft, operating systems, security, software
Latest Blog Posts
Whitepapers
  • HP Imaging and Printing Services
    According to Gartner, a major focus for organisations today and in the foreseeable future is shifting from cost reduction to growth, expansion, innovation, and operational excellence. If your organization is serious about driving growth and innovation and improving customer experiences, you’ll find that a well-managed imaging and printing environment is key to these goals. A growing number of organizations are turning to services as a means of integrating imaging and printing into their overall IT infrastructure strategies. It may be one of the fastest ways to continue to drive down costs, fund innovation, and prepare your organisation to capitalise on future opportunities. Read more.
    Learn more »
  • Simplifying branch office security
    Securing your business network is more important than ever. Malware, botnets and other malicious programs threaten your network—at your central offices and your branch offices alike. Yet enforcing consistent network security throughout your enterprise can be challenging—especially for those of you with branch offices with few users and no IT expertise. This paper introduces a new standard—an innovative, unified, cost-effective solution for managing branch office security, with centralised reporting and a clear process for determining return on investment (ROI).
    Learn more »
  • Spear Phishing Attacks - Why they are successful and how to stop them
    There's been a rapid shift from broad, scattershot attacks to advanced target attacks that have had serious consequences for victim organisations. The increased use of spear phishing is directly related to the fact that it works, as traditional security defences simply do not stop these types of attacks. This paper provides a detailed look at how spear phishing is used within advanced attacks and the key capabilities organisations need in order to effectively combat these emerging and evolving threats.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments