Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Tsunami backdoor trojan ported from Linux to take control of Macs too

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » General Discussion Donate to DU
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:01 PM
Original message
Tsunami backdoor trojan ported from Linux to take control of Macs too
The Linux-based Tsunami backdoor trojan has made its way over to the Mac, according to security firm ESET. The company posted to its blog (hat tip to Macworld) that a Mac-specific variant, OSX/Tsunami.A has made an appearance on the trojan scene, though ESET made no mention of whether it was gaining any traction among users.

ESET's Robert Lipovsky wrote on Wednesday that the code for OSX/Tsunami.A was ported from the Linux version of the trojan that the company has been tracking since 2002. Hard-coded is a list of IRC servers and channels, which the trojan tries to connect to in order to listen for malicious commands sent from those channels.

Lipovsky published a list of the commands pulled from the Linux variant of Tsunami, but the general gist is that the trojan can open a backdoor to perform DDoS attacks, download files, or execute shell commands. Tsunami has "the ability to essentially take control of the affected machine."

Security firm Sophos also acknowledged the appearance of the Mac-targeted Tsunami backdoor, but reminded users that there is still "far less malware existence for Mac OS X than for Windows." Still, the company says the problem is real and that users should protect themselves with anti-malware software. "We fully expect to see cybercriminals continuing to target poorly protected Mac computers in the future," Sophos' Graham Cluley wrote. "If the bad guys think they can make money out of infecting and compromising Macs, they will keep trying."

http://arstechnica.com/apple/news/2011/10/tsunami-backdoor-trojan-ported-from-linux-to-take-control-of-macs-too.ars
Printer Friendly | Permalink |  | Top
Old and In the Way Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:06 PM
Response to Original message
1. Us PC users are available to help with any questions our fellow Mac users may have
Edited on Wed Oct-26-11 01:06 PM by Old and In the Way
with regards to AV software. :P
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:32 PM
Response to Reply #1
3. Well said.....
Printer Friendly | Permalink |  | Top
 
villager Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:07 PM
Response to Original message
2. Yet it doesn't actually target Linux machines?
I use Ubuntu on one of my laptops, and always assume I'm at less "viral risk" when using it...

(Though OS X is based on Linux, yes?)
Printer Friendly | Permalink |  | Top
 
formercia Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:34 PM
Response to Reply #2
4. OS X is based on FreeBSD
close but not the same animal.
Printer Friendly | Permalink |  | Top
 
Tesha Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:44 PM
Response to Reply #4
7. Actually, NetBSD. (NT)
Printer Friendly | Permalink |  | Top
 
formercia Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:50 PM
Response to Reply #7
8. How so?
It's my understanding that the lead programmer for FreeBSD went to work for Apple to develop OSX. NetBSD is strictly Open Source.
Printer Friendly | Permalink |  | Top
 
Xithras Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:52 PM
Response to Reply #2
10. Sure it does.
It's a full rootkit. It's primary role is to set up DDOS zombies, but is capable of accessing the filesystem, can run other commands on the machine, and can potentially run with full user priv's.

Security researchers have been saying for many years that Linux and Mac's aren't inherently any more secure than modern Windows PC's, but that they simply don't get the same black hat attention as Windows because they're such relatively small markets. That may have been the case 10 years ago when Mac's were 3% of the market and Linux desktops were 1%, but those platforms are getting more attention from botnet and malware authors now that their marketshare has grown.

Things are only going to get worse. My own linux PC's are all virus protected at this point, as is my Mac Mini.

Saying that "I don't need antivirus because I run Linux or Mac" is like saying "I don't need to wear a condom because I only sleep with nuns, and everyone knows that nuns don't have STD's." That's true when you're the only one sleeping with the nuns, but what if everyone on the block starts doing it?
Printer Friendly | Permalink |  | Top
 
formercia Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 02:20 PM
Response to Reply #10
14. If you run without a firewall and have every service running..
I have a PowerPC IBook that had a real nasty backdoor on it when I acquired it. Even reinstalling the OX didn't remove it. Finally, I installed NetBSD, then reinstalled OSX. That took care of it.
Printer Friendly | Permalink |  | Top
 
retread Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 03:34 PM
Response to Reply #10
16. This is a port of a 2002 Linux trojan.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:35 PM
Response to Original message
5. But, but, but, Macs are immune from viruses!!
:sarcasm:
Printer Friendly | Permalink |  | Top
 
formercia Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:52 PM
Response to Reply #5
9. They pretty much were until Apple went from the PowerPC to Intel.
That made it much easier to port Windows based Binaries to OSX.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 02:08 PM
Response to Reply #9
12. Nope, nobody was writing viruses to go after 6% market share.
NO OS is invulnerable. It's easier to attack a Mac or Linux based machine than you think.
Printer Friendly | Permalink |  | Top
 
formercia Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 03:32 PM
Response to Reply #12
15. I wonder who wrote the backdoor that was on my PowerPC IBook
Someone went to a lot of trouble for nothing.......
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-27-11 09:47 AM
Response to Reply #12
17. Uh, 5% now
latest stats, not even a blip on the radar, and since most Apple owners are too busy taking photos of themselves to put up on Facebook instead of worrying about security, they get taken advantage of.....

:evilgrin: :sarcasm:

Printer Friendly | Permalink |  | Top
 
SpiralHawk Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:38 PM
Response to Original message
6. z-z-z-z-z-z-z...
Edited on Wed Oct-26-11 01:48 PM by SpiralHawk
wake me up when the flailing fear-flingers fade...
Printer Friendly | Permalink |  | Top
 
Hutzpa Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 01:53 PM
Response to Reply #6
11. + 20
nt.
Printer Friendly | Permalink |  | Top
 
flamingdem Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-26-11 02:11 PM
Response to Original message
13. Is there a way to check for it? nt
Printer Friendly | Permalink |  | Top
 
slackmaster Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-27-11 09:49 AM
Response to Reply #13
18. Low-level format the hard drive and install Windows 7 and you'll be fine.
:hide:
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 18th 2024, 05:57 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » General Discussion Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC