French security firm bashes Microsoft for talking up Mac malware
- 27 July, 2011 03:03
- Comments
A Mac security firm today criticized Microsoft for warning Mac users of new malware, saying that the threat simply wasn't worth mentioning.
Late Monday, the Microsoft Malware Protection Center (MMPC), the group that researches malware and crafts signatures for the company's antivirus products, alerted users of a new Mac "backdoor," a program that, once installed, downloads additional attack code or lets hackers steal files from the compromised computer.
In a blog post, Microsoft malware engineer Meths Ferrer said that MMPC had found the backdoor, dubbed "Backdoor:MacOS X/Olyx.A," in an archived file that also contained a Windows backdoor called "Wolyx.A."
According to Ferrer, Olyx.A disguises itself as a Google application support file when run by the user, then establishes a remote connection to an IP address hosted in Seoul, South Korea.
But Intego, a French antivirus company that focuses exclusively on the Mac, took exception to Ferrer's blog post.
"They're making it out like this is something serious, but it's not in the wild at all and not being installed," said Peter James, a spokesman for Intego. "This is no big deal."
A backdoor must either be manually installed by a user -- perhaps after being tricked into running the file -- or packaged with other malware that exploits a vulnerability or uses social engineering tricks to get the victim to run the program, said James.
There's no evidence that Olyx is in wide circulation or being used by other malware, such as Mac-specific "scareware," the phony antivirus software that fools people into installing it after faking security alerts.
"It could so stuff if it was in the wild, but it's not," argued James.
It's rare to see one antivirus firm bash another for issuing a warning or alerting customers to a possible threat. But that didn't stop Intego, which saw Ferrer's blog as counterproductive.
"We get criticized every time we issue a security alert," said James, adding that people accuse it of crying wolf about threats to the Mac, which has historically been relatively immune to attacks because of its small market share.
Cyber criminals with profit in mind are much more likely to target Windows simply because Microsoft's operating system powers nearly 90% of the world's personal computers.
"When something is a real threat, we'll say something," said James. "If it's not, we don't publicize [the malware] by issuing an alert. We've got other things to do."
Intego created an Olyx definition for its VirusBarrier product on June 30.
"It's kind of interesting that Microsoft took a month [to mention Olyx] after it started circulating," James said, taking another swipe at the Redmond, Wash developer. "Maybe this is a sign that they're going to be analyzing more Mac malware in the future."
Other security companies have also made mention of Olyx, including Kaspersky Lab, which highlighted the backdoor in a malware report for June 2011.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed. His e-mail address is gkeizer@computerworld.com.
See more articles by Gregg Keizer.
Read more about security in Computerworld's Security Topic Center.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Apple aims iPads at High Schools
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
HP Imaging and Printing Services
According to Gartner, a major focus for organisations today and in the foreseeable future is shifting from cost reduction to growth, expansion, innovation, and operational excellence. If your organization is serious about driving growth and innovation and improving customer experiences, you’ll find that a well-managed imaging and printing environment is key to these goals. A growing number of organizations are turning to services as a means of integrating imaging and printing into their overall IT infrastructure strategies. It may be one of the fastest ways to continue to drive down costs, fund innovation, and prepare your organisation to capitalise on future opportunities. Read more. -
Simplifying branch office security
Securing your business network is more important than ever. Malware, botnets and other malicious programs threaten your network—at your central offices and your branch offices alike. Yet enforcing consistent network security throughout your enterprise can be challenging—especially for those of you with branch offices with few users and no IT expertise. This paper introduces a new standard—an innovative, unified, cost-effective solution for managing branch office security, with centralised reporting and a clear process for determining return on investment (ROI). -
Spear Phishing Attacks - Why they are successful and how to stop them
There's been a rapid shift from broad, scattershot attacks to advanced target attacks that have had serious consequences for victim organisations. The increased use of spear phishing is directly related to the fact that it works, as traditional security defences simply do not stop these types of attacks. This paper provides a detailed look at how spear phishing is used within advanced attacks and the key capabilities organisations need in order to effectively combat these emerging and evolving threats.
-
Teach Yourself Visually Windows 7
-
Computers for Seniors for Dummies, 2nd Edition
-
Microsoft Office
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
Office 2007 for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies® Dvd+book Bundle








Comments
Post new comment