« Site ‘Under construction’ hosts malware
Ambassadors for education’s site compromised »

Mac OS X virus free?

October 26th, 2009

There’s an article about: “Don’t bug me: why Macs are still virus free” I read today.

“The real answer is UNIX, the foundation technology Mac OS X is based on” says Neal Costello.

While it is true that Unix systems have been designed with a very different approach, it does not mean that they are impenetrable.

The reason why we see less malware on Linux is because malware authors are money driven. If I was a bad guy and wanted to infect as many people as possible, I would write a virus for Windows. It would guarantee me the highest ROI.

Thinking that you are safe because you are running a Mac is making a big mistake. In fact, in most malware infections, the weakest link is the end user. That type of thinking will get you in big trouble when a fake codec will pop up and you blindly install it. A well-educated PC user will not fall for that.

Same for phishing scams, having a Mac does not protect you any better than having Windows. You click a link in your email to “update” your bank account. It turns out it’s a fake site and it just stole your credentials. Well, Mac OS X or not you have just been a victim of Identity Theft.

There is a lot of buzz about Bots and Botnets… You may be surprised, but they exist on the Mac as well:

bot

Extract from the source code:

code

At the end of the day, you may want to choose whatever OS you wish but don’t believe everything you hear. It’s good for marketing to say “Macs have no viruses” because people are genuinely concerned with security… Remember when everybody was saying “don’t use IE, use Firefox”? Well, the number of exploits for Firefox rose significantly… Again, the bad guys will go where the money is. It may take them longer to bypass a UNIX system, but if it’s worth the effort, they will gladly do it.

Updated to add:

Neal Costello from makemineamac.info, responded to my post:update

Interesting to see the shift from “Virus free” to “relatively low number of exploits” ;-)

I’ve had quite a few people tell me “you don’t have a Mac product so why the heck do you bother talking about Mac threats?”. Well, to that my answer is that I blog about security threats. They could be on your PSP, iPhone, Atari… doesn’t matter!

Jerome Segura

    This entry was posted on Monday, October 26th, 2009 at 11:00 am and is filed under Mac security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.