Apple - Trend Micro Uncovers DNS-Changing Mac Trojan - eWeek Security Watch

Trend Micro Uncovers DNS-Changing Mac Trojan

Written By
Brian Prince
Brian Prince
Aug 12, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Researchers at Trend Micro have spotted a Domain Name System-changing Trojan targeting Mac computers.

Disguised as MacCinema Installer, the Trojan is detected by Trend Micro as OSX_JAHLAV.D and is considered to be an update to the OSX_JAHLAV.C malware identified in June. The malware poses as an Apple QuickTime Player update with the file name QuickTimeUpdate.dmg. Users are prompted to download the malware when viewing certain videos from .com domains with the IP address 91.214.45.73, such as:

• allincorx • bigdron • cikaredo

A full list of the domains can be found here. If a computer is infected, an attacker can reroute the victim’s Web traffic to rogue Websites, according to the TrendLabs Malware Blog.

“The Trojan contains component files detected as UNIX_JAHLAV.D and obfuscated scripts detected as PERL_JAHLAV.F,” wrote Det Caraig, a researcher with Trend Micro. “The Perl script then downloads a file from a malicious site and stores it as /tmp/{random 3 numbers}, detected as UNIX_DNSCHAN.AA, which allows a malicious user to monitor the affected user’s activities. This may also cause the user to be redirected to phishing sites or sites [that] other malware may be downloaded from.”

Trend Micro officials noted that the domain names have been set up so that if the main IP is taken down, cyber-criminals can easily move the back end to another IP address without the need to change code or scripts. Mac users should stay away from the domains and IP addresses Trend Micro has listed and be wary of prompts to download software updates that do not come from Apple’s legitimate Website.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.