Mac OS X Trojan steals processing power to produce Bitcoins
- 01 November, 2011 04:29
- Comments
A newly identified Mac OS X Trojan bundles a component that leverages the processing power of video cards (GPUs) to generate Bitcoins, a popular type of virtual currency.
The new Trojan was dubbed DevilRobber by antivirus vendors and is being distributed together with several software applications via BitTorrent sites.
Interview: Bitcoin technical lead Gavin Andresen
"This malware is complex, and performs many operations," security researchers from Mac antivirus vendor Intego warned. "It is a combination of several types of malware: It is a Trojan horse, since it is hidden inside other applications; it is a backdoor, as it opens ports and can accept commands from command and control servers; it is a stealer, as it steals data and Bitcoin virtual money; and it is a spyware, as it sends personal data to remote servers," they explained.
The Bitcoin mining program that DevilRobber installs on infected computers is called DiabloMiner and is a legitimate Java-based application used in the virtual currency's production.
Bitcoin is a form of virtual cash that can be exchanged by users without the need for an intermediary bank or payment service. Bitcoins are actually cryptographic hashes that get generated piece by piece using specialized programs like DiabloMiner, according to a public algorithm.
One Bitcoin is currently valued at around US$3.20, and it is a good source of profit for both Bitcoin miners, who legitimately use their computer resources to generate them, and cybercriminals who steal them.
The DevilRobber trojan steals processing power, which can lead to slow computer performance, as well as actual Bitcoins, which are kept in virtual wallets on the victim's machine.
"OSX/Miner-D [DevilRobber] also spies on you by taking screen captures and stealing your usernames and passwords," warned Graham Cluley, a senior technology consultant at antivirus vendor Sophos.
"In addition, it runs a script that copies information to a file called dump.txt regarding truecrypt data, Vidalia (TOR plugin for Firefox), your Safari browsing history and .bash_history," he added.
So far, the Trojan has been detected in a BitTorrent download for GraphicConverter version 7.4, an image editing application for Mac OS X. However, this doesn't mean that there aren't similarly Trojanized torrents out there.
"Clearly, Mac users -- like their Windows cousins -- should practice safe computing and only download software from official websites and legitimate download services," Cluley said. He also stressed that Mac users should install an antivirus program, which is not hard to do and costs nothing.
There are several providers of free antivirus solutions for Mac and all of their solutions are more capable than Mac OS X's default anti-malware defense mechanism, which some Trojans already bypass or even disable.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- The Mac Security Blog » New Malware DevilRobber Grabs Files and Bitcoins, Performs Bitcoin Mining, and More
- Bitcoin technical lead Gavin Andresen
- DevilRobber Mac OS X Trojan horse spies on you, uses GPU for Bitcoin mining : Naked Security
- New Mac Trojan horse disables Apple's automatic malware updates : Macworld
-
Apple aims iPads at High Schools
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Rapid achievement of employee productivity gains in a modern workforce
The last few years have seen explosive innovation in the ways that users interact with software applications, resulting in a huge surge in the adoption of tablet, smartphone, and web based social applications. Fortunately there are some simple incremental steps that any organisation can take to transition to a more people centric communications system, while lifting employee productivity. Read more. -
Enterprise Buyers Guide for Printers
Every enterprise owns, and regularly replaces, printers, copiers, multifunctional products and fax machines. The problem most face is not too few choices, but too many. How do you even begin to select the right one? Here is the Computerworld guide to buying a printer for the enterprise. -
Advanced Malware Exposed - How advanced malware, zero-day and targeted APT attacks are evading today's network defences
This handbook shines a light on the dark corners of advanced malware, both to educate as well as to spark renewed efforts against these stealthy and persistent threats. By understanding the tools being used by criminals, we can better defend our nations, our critical infrastructures and our citizens. It is certainly my hope that this book will provide readers with a new understanding of the rapidly developing cyber threat landscape and practical insights into how they can protect their data and computing infrastructures. - Robert F. Lentz, President and CEO, Cyber Security Strategies, LLC
-
Microsoft Office
-
Office 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Teach Yourself Visually Windows 7
-
Windows 7 for Seniors for Dummies®
-
Office 2007 for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle








Comments
Post new comment