SecureMac claims to have discovered several variants of a Trojan horse in the wild targeted at users of Mac OS X 10.4 and 10.5

Distributed as a compiled AppleScript called ASthtv05 or as an application, the Trojan allows remote access to the system and can transmit system and user passwords. SecureMac also said the Trojan is also capable of logging keystrokes and turning on file sharing.

The Trojan takes advantage of a vulnerability with Apple Remote Desktop that allows it to run as root. You must download and open the infected file for the Trojan to become active, but once it is active, it will add itself to the System login items.

SecureMac said its product, MacScan, has been updated to remove the Trojan.

Tags: , , ,

Leave a Reply

You must be logged in to post a comment.