Welcome | Sign In
MacNewsWorld.com
Hacks & Malware

Warning to iWork Pirates: Here There Be Trojans

Print Version
E-Mail Article
Reprints
Warning to iWork Pirates: Here There Be Trojans

Mac users looking to scoop up free -- as in, stolen -- copies of Apple's iWork '09 are getting a boatload of infected loot. Some illicit copies of the application carry a trojan horse, which will latch on to the user's Mac and open the door to any number of bad things. Though the only people likely to get infected here are pirates, security companies are offering solutions.


Major companies around the world value the opinion of thought leaders like you! Join our new tech panel to be invited to a variety of interesting and rewarding survey opportunities. In exchange for your valuable time and insight, you will have exclusive access to rewards programs such as Paypal, Amazon and retail gift cards. Learn more.

Mac security Planning for the next peak season? Ensure your website is fast, secure and available 24/7. Click here to learn how. firm Intego sounded the alarm Thursday on a trojan horse it spotted hiding in pirated copies of Apple's (Nasdaq: AAPL) iWork '09. Since then, several more security solution providers have responded.

On the surface, the trojan -- OSX.Trojan.iServices.A -- might seem relatively benign. After all, only those who stole a copy of iWork '09 can get it. While those numbers may edge into the thousands, pirate Mac lovers tend not to be clients of enterprise Mac security solution providers.

Symantec (Nasdaq: SYMC) Security Response rates OSX.iWork a low-level threat, presumably because its reach is limited to a relatively small number of users looking to nab a pirated copy of iWork. Intego, on the other hand, rates it as serious.

What Gives?

"The risk is extremely low -- you can only get infected if you are downloading illegal software," Rich Mogull, an independent security expert with Securosis.com, told MacNewsWorld.

But what if a user, ahem, does download the illegal software?

"You're screwed," he said.

So What Does It Do?

First of all, Mac installer packages are made-up scripts that install the applications and various files in the correct places on a Mac's hard drive. When installing iWork 09, Intego reports, the iWorkServices package is installed, and the installer for the trojan horse is launched as soon as a user begins the installation of iWork, following the installer's request of an administrator password.

This trojan is installed as a startup item in /System/Library/StartupItems/iWorkServices, where it has read-write-execute permissions for root. The malicious software then connects to a remote server over the Internet and essentially holds open a back door to the Mac.

"The trojan itself is severe just because it is installed with root privileges and has full access from the malicious source to change or modify," Nicholas Raba, president of SecureMac, told MacNewsWorld. "The trojan knows where it's located at, and once installed, it connects to the source and it notifies its location -- its IP address -- and awaits commands."

The trojan could scan the infected Mac for sensitive information, track Internet activity, record logins and passwords, and do just about anything nefarious thing the bad guy pulling the strings wants.

But Aren't These Just Pirates?

For those who toe the software line, there might be a tendency to simply dismiss the trojan as something the iWork '09 robbers deserve. Still, in a tough economy -- and with teenagers running rampant over the household WiFi connection -- newbie software robbers might snag something they hadn't bargained for. Intego says that as of last night, 20,000 people had downloaded the pirated iWork '09 installer.

For good or bad, it seems as if security solution providers are keeping their eye focused on the issues of viruses and malware, no matter where or how they appear.

"In regards to pirated software, we don't condone piracy; however, SecureMac does protect against malware, and just because it was included in the iWorks package isn't to say it couldn't be included in any other package, such as freeware or open source or something like that," Raba explained.

From its home page, SecureMac is offering a free download, iWorksServices Trojan Removal Tool, that will remove the trojan from compromised Macs.

"Right now it's specifically called 'iWorksServices,' but if they decide to package it with anything else it will evolve from there," he added.

In an update to its original alert, Intego is now reporting that the iServices.A Trojan horse is actively "downloading new code and acting as a botnet, participating in distributed denial of service attacks on certain Web sites."


Print Version E-Mail Article Reprints More by Chris Maxcer


More by Chris Maxcer

Who's the Big Winner in the Great iPhone Escape?
July 27, 2010
Congratulations, iPhone jailbreakers: The Library of Congress is on your side. Although the principle of the decision is commendable, the institution's ruling on device jailbreaking probably won't bring on a flood of new jailbreakers. What will it change? Well, maybe Apple will be just a little looser with what makes it into the App Store. And T-Mobile might have a little side-business opportunity.
My Futile, Frustrating Hunt for a Decent iPhone Case
July 20, 2010
Apple says all iPhone 4 owners will get a free case, but anyone who's hunted around for a decent device protector probably learned quickly that at this point, selection is incredibly weak. It's a combination of being spoiled for the last two years by identical chassis designs as well as Apple's business-as-usual level of secrecy -- which may have been amplified after that prototype leak.
My Time Capsule Was Too Young to Die
July 13, 2010
"Sometimes they just die" seems to be a popular reaction when a gadget kicks the bucket. It's true -- no electronic gizmo should be expected to last forever. But shouldn't a data backup system made by a company like Apple endure a little longer than just two years? Now, Apple is finally doing the right thing for customers whose Time Capsules went kaput due to overheating issues.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
ECT News Network Information
Reader Services
Corporate
ECT News Network