Flashback Trojan Returns With a Multi-Pronged Infection Strategy

Last year, we profiled a Mac trojan horse known as "Flashback" that was masquerading as a Flash Player installer. While Apple has taken steps to protect users from the threat using its File Quarantine system under which users' computers initiate daily checks for updated malware definitions, the malware's authors have continued to tweak the trojan to improve its ability to both infect systems and evade detection.

Security firm Intego has issued a report on a new variant of the trojan, known as Flashback.G, which adopts a multi-pronged strategy in attacking users' systems. The first two methods rely on vulnerabilities in Java, and while the vulnerabilities are patched in systems running up-to-date versions of Java, outdated systems can be silently infected through these security holes.

flashback g certificate
Flashback.G's self-signed certificate seeking to trick users into allowing installation

On up-to-date systems lacking the Java vulnerabilities, Flashback.G presents a self-signed certificate claiming to be from Apple in an attempt to fool users into allowing the trojan to be installed on their systems. Once installed, the trojan begins searching for user names and passwords it can relay to the malware's authors.

This malware patches web browsers and network applications essentially to search for user names and passwords. It looks for a number of domains – websites such as Google, Yahoo!, CNN; bank websites; PayPal; and many others. Presumably, the people behind this malware are looking for both user names and passwords that they can immediately exploit – such as for a bank website – as well as others that may be reused on different sites.

Notably, Intego reports that the trojan aborts its own installation if it detects the presence of any of several antivirus applications on a user's Mac, presumably seeking to remain below the radar while focusing on vulnerable systems.

Intego recommends that users on Mac OS X Snow Leopard make sure that Java is fully up-to-date by running a check through Software Update, and for all users to be aware of the social engineering trick the trojan uses in attempting to gain permission for installation. The company of course also recommends that users equip their systems with antivirus software.

While malware has not been a tremendous threat to Mac users so far, its presence has been growing. Apple has stepped up its efforts to combat malware by enhancing its File Quarantine system to provide for the daily definition checks. OS X Mountain Lion will see another significant step with the introduction of Gatekeeper, a system by which users can limit installation of apps to sources such as the Mac App Store and developers who have registered with Apple as "identified developers".

Apple's Developer-ID program will utilize digital signatures on applications to link applications with a specific developer. If the developer is later discovered to be distributing malware or otherwise behaving improperly, installations of its existing apps can be deactivated by Gatekeeper. Gatekeeper does have its limitations, however, as it only scans applications downloaded through a handful of mechanisms such as browsers and can not detect applications that are modified by malware after their initial launch.

Top Rated Comments

androiphone Avatar
122 months ago
and this is why the 2 most important parts of computing are:

1. keep your computer up-to-date

and

2. use a little common sense when something pops up (though I admit that is easier to more knowledgeable people like us than the wider 'mass' consumer)
Score: 32 Votes (Like | Disagree)
grapes911 Avatar
122 months ago
Apple computers do not get a virus. Yeah right. (as the Tui advertisment goes).

Trojan != Virus
Score: 30 Votes (Like | Disagree)
karohan Avatar
122 months ago
Whatever, still malware.

It sounds pedantic, but it is sort of an important distinction to make. Viruses can be spread without any user input, while trojans still require the user to at some point (albeit unknowingly) permit them.
Score: 21 Votes (Like | Disagree)
Small White Car Avatar
122 months ago
Apple computers do not get a virus. Yeah right. (as the Tui advertisment goes).
First off, no one in any position of authority has ever said Macs don't or can't get viruses.

Secondly, this is a trojan, so talking about viruses here is kind of beside the point.


And to think people said that the fact that OS X lacked malware had nothing to do with it's marketshare.
Their computer marketshare is far, far larger than their malware market share.

So yeah, I'm STILL saying that there are other factors at play. If that wasn't true you'd see malware market share matching sales market share. And that hasn't happened.
Score: 18 Votes (Like | Disagree)
grapes911 Avatar
122 months ago
And to think people said that the fact that OS X lacked malware had nothing to do with it's marketshare.
The argument has usually been applied to viruses. Trojans require user input and can effect anything. Yes, security holes are taken advantage of to make this Trojan look legit, but there is no defense for the most basic Trojan. If I wrote and app that said you'll be granted three wishes after you enter your password, but instead I use your password to delete all files on you computer, that is a Trojan. There is no defense for such things expect common sense.

Whatever, still malware.
It's a huge distinction.

So for those of us who got their parents Macs..

Anyone recommend a good A/V program while we wait for ML to come out?
The best AV program is to not download from or even visit shady sites.
Score: 16 Votes (Like | Disagree)
BigBagaroo Avatar
122 months ago
Why is "Continue" the default choice when the root certificate is not trusted?
Score: 13 Votes (Like | Disagree)

Top Stories

YouTube Picture in Picture Feature

YouTube Says iOS Picture-in-Picture Coming to All US Users

Friday June 18, 2021 9:41 am PDT by
After a long wait, YouTube for iOS is officially gaining picture-in-picture support, allowing all users, non-premium and premium subscribers, to close the YouTube app and continue watching their video in a small pop-up window. In a statement to MacRumors, YouTube says that picture-in-picture is currently rolling out to all premium subscribers on iOS and that a larger rollout to all US iOS...
Top Stories 63 Feature

Top Stories: Beats Studio Buds Announced, Apple Watch Series 7 Rumors, and More

Saturday June 19, 2021 6:00 am PDT by
The Apple news cycle started to move beyond WWDC this week, but that doesn't mean there still wasn't a lot to talk about, led by the official debut of the much-leaked Beats Studio Buds that might give us a hint of what to expect for the second-generation AirPods Pro. With no hardware announcements at WWDC, we also took a look at when we might finally see the long-rumored redesigned MacBook...
ios wifi settings

iOS Bug Causes Specific Network Name to Disable Wi-Fi on iPhones

Sunday June 20, 2021 4:15 am PDT by
A wireless network naming bug has been discovered in iOS that effectively disables an iPhone's ability to connect to Wi-Fi. Security researcher Carl Schou found that after joining a Wi-Fi network with the name "%p%s%s%s%s%n" his iPhone's Wi-Fi functionality was left "permanently disabled." Changing a hotspot's SSID did nothing to correct the problem, with even a reboot failing to make a...
maxresdefault

Video: 20 Annoyances Apple Fixed in iOS 15 and macOS Monterey

Friday June 18, 2021 11:36 am PDT by
With iOS 15 and macOS Monterey, Apple is adding several quality of life improvements, which are designed to address some of the complaints that people have had with these operating systems for years now. Subscribe to the MacRumors YouTube channel for more videos. In our latest YouTube video, we're highlighting some of our favorite "fix" features that address long-running problems in iOS and...
16 inch macbook pro m2 render

When Can We Expect the Redesigned MacBook Pros Now?

Wednesday June 16, 2021 7:11 am PDT by
With no sign of redesigned MacBook Pro models at this year's WWDC, when can customers expect the much-anticipated new models to launch? A number of reports, including investor notes from Morgan Stanley and Wedbush analysts, claimed that new MacBook Pro models would be coming during this year's WWDC. This did not happen, much to the disappointment of MacBook Pro fans, who have been...
space gray magic accessories trio

Apple Stops Selling Magic Accessories in Space Gray

Friday June 18, 2021 9:16 am PDT by
Apple this week stopped selling its Magic Keyboard with Numeric Keypad, Magic Mouse 2, and Magic Trackpad 2 accessories for the Mac in a Space Gray color, around three months after discontinuing the iMac Pro, which also came in Space Gray. Last month, Apple listed the Space Gray accessories as available while supplies last, and the company has now removed the product pages from its website...
m1 v intel thumb

Intel Processor Market Share May Fall to New Low Next Year Due to Apple Silicon

Friday June 18, 2021 2:06 am PDT by
Intel may see its market share fall to a new low next year, in large part thanks to Apple's decision to move away from using Intel processors in its Mac computers and instead use Apple silicon. Apple announced last year that it would embark on a two-year-long journey to transition all of its Mac computers, both desktops, and laptops, to use its own in-house processors. Apple is expected to...
3nm apple silicon feature

Apple Supplier TSMC Readies 3nm Chip Production for Second Half of 2022

Friday June 18, 2021 6:59 am PDT by
Apple supplier TSMC is preparing to produce 3nm chips in the second half of 2022, and in the coming months, the supplier will begin production of 4nm chips, according to a new report from DigiTimes. Apple had previously booked the initial capacity of TSMC's 4nm chip production for future Macs and more recently ordered TSMC to begin production of the A15 chip for the upcoming iPhone 13,...
2021 back t0 school

Apple Launches 2021 Back to School Promotion: Free AirPods With Eligible Mac or iPad Purchase

Thursday June 17, 2021 4:56 am PDT by
Apple today launched its seasonal back-to-school sale for the upcoming school year in the United States and Canada, offering students free AirPods alongside purchases of select Macs and iPad models. Similar to last year's promotion, this year's offer includes free AirPods alongside the purchase of a MacBook Air, MacBook Pro, the new 24-inch iMac, the Mac Pro, Mac mini, and the new M1-powered ...
applecare lower prices

Apple Lowers Prices of AppleCare+ Plans for M1 MacBook Air and MacBook Pro

Thursday June 17, 2021 7:33 am PDT by
Apple today lowered the prices of AppleCare+ plans for MacBook Air and 13-inch MacBook Pro models equipped with the M1 chip. Coverage offered by the plans, as well as accidental damage fees, appear to remain unchanged. In the United States, AppleCare+ for the MacBook Air now costs $199, down from $249. The new price applies to both M1 and Intel-based MacBook Air models, although Apple no...