Infected Mac Computers Worth 43 Cents in Cyber-underworld

執筆者
Brian Prince
Brian Prince
Published: Sep 25, 2009
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

New research from Sophos underscores a growing interest in the Mac among cyber-criminals.

In a presentation at Virus Bulletin’s VB Conference, in Geneva, Sophos Labs researcher Dmitry Samosseiko revealed a malware affiliate network offering 43 cents per infected Mac computer. The offer was the work of a larger network of Russian spammers, malware authors and businesspeople pushing everything from phony watches to medications-an alliance he called the “Partnerka.”

This goes to show that Apple Macs, which are targeted far less than Microsoft Windows PCs, are not without security threats.

“Mac users are not immune to the scareware threat,” Samosseiko wrote in a paper released at the conference. “In fact, there are ‘codec-partnerka’ dedicated to the sale and promotion of fake Mac software. One of the recent examples is Mac-codec.com … the site is no longer available, but just a few months ago it was offering $0.43 for each install and offered various promo materials in the form of MacOS ‘video players.'”

Earlier in 2009, attackers tried to infect people using pirated versions of Mac software in an attempt to build a Mac botnet. DNS (Domain Name System)-changing Trojans targeting Macs have been reported this year as well.

Perhaps in response to the changing landscape, Apple took the additional step of adding some new malware detection capabilities to Mac OS X 10.6, aka “Snow Leopard,” using known malware signatures. If malware is detected, Snow Leopard will recommend moving the file to the trash.

“Cyber-criminals are interested in money, full stop,” Sophos Security Analyst Michael Argast told eWEEK. “The fact of the matter is that users of Windows or Mac machines all buy stuff online, access online banking, have confidential information-and it is that information the criminals are after.”

Rogue affiliate networks like the ones outlined by Samosseiko in his paper have the potential to earn attackers serious money. One such network uncovered by Finjan earlier in 2009 reportedly made $10,800 a day pushing scareware.

At Symantec Security Response, Research and Development Manager Marc Fossi said Symantec hasn’t seen any specific advertisements for Mac bots in the cyber-underground, but said attackers are keen to get their hands on whatever they can. Argast echoed the sentiment.

Advertisement

“What we do know is that fake codec Trojans have been increasingly prolific, and we started seeing them pop up for the Mac platform about a year ago,” Argast said. “Based on the breadth of the attacks, and variety of sites and malware involved, it is quite probable that affiliate networks like this have been in place for some time, and simply added the Mac as a platform of interest.”

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。