ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

'Rogue' cleaning tool targets Mac users

Tom Espiner ZDNet Australia Liam Tung ZDNet Australia

Published: 16 Jan 2008 13:43 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Mac users have been warned by F-Secure against downloading a free "rogue" security application, MacSweeper.

According to the Finnish antivirus company, the application is reminiscent of scams that often target Windows users.

By making the intended victim believe they have a virus, the distributors of MacSweeper hope to sell software to the concerned user, said F-Secure.

"It claims to clean compromising files from your Mac and it will always find something to fix/clean, but the only way to do so is to buy the program," explained F-Secure threat response manager, Patrik Runald, in a blog post.

"[It's] designed to trick people into thinking that they have security problems and that the only way to solve them is to buy the software. Until now this issue has been a Windows-only problem, but that's not the case anymore," added Runald.

Runald said further evidence that MacSweeper is "a scam" is "the fact that when you visit the MacSweeper website with a PC and click on 'Scan', it will tell you that you have security vulnerabilities in folders like system_root/home [a folder that doesn't exist]."

Runald blamed the increasing user base of Mac OS X for the emergence of such "scams".

"Mac users will increasingly come under attack from bad guys and this new rogue application and the constant stream of new variants of [Mac Trojan] DNSChanger is proof of that. It doesn't mean that Mac is becoming less secure in and of itself. But it does mean that Mac users will have to watch out for social-engineering tricks just like Windows users have had to do for years," Runald added.

The distributors of MacSweeper — apparently a company called Kivvi Software — also copied security company Symantec's "About us" statement on its website and replaced its name with their own, Runald said.

In a reply to Runald's blog post by a "Macsweeper developer" on Wednesday, the poster claimed Macsweeper developers were "trying to make a good software [sic]".

"I would like to explain all the situation, about MacSweeper [sic]," said the post. "We are really trying to make a good software [sic], and you won't find any viruses/spyware/Trojans/malware in MacSweeper (test it yourself, if you don't believe me, you can use any type of firewalls, dissemblers, or other tools) [sic]."

According to the "developer", Kivvi Software is using sales partners that "forces us to use this marketing type [sic]".

"I would like to say sorry for all inconveniences that we could bring to you, but believe MacSweeper is meant to be a useful application," the "Macsweeper developer" added.

Late last year, security vendor Intego claimed to have found the first Trojan targeting Mac OS X Tiger: DNSChanger. The malware distributors attempted to infect Macs by offering a video-streaming decoder — a codec — that the distributors claimed could decode porn that was not viewable through QuickTime. Like this latest scam, the distributors used social-engineering techniques to trick users into downloading the software.

The Trojan worked by changing a Mac's DNS settings to redirect victims to porn websites. F-Secure later reported it had discovered 32 variants of the Trojan and said it was related to the group distributing the Zlob Trojan.

Credit: Mac users targeted by fake antivirus tool from ZDNet Australia

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
7 out of 9 people found this useful


Full Talkback thread

1 comment

  1. Research your facts! mindpower

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Business Development Manager - Market leaders in Civil Engineering

The role is responsible for managing the UK sales activity to achieve realistic sales targets by generating a sales pipe-line and promotional ...

Junior HTML / CSS developer - Dorset

HTML, CSS website developer to join their team of two, to update content and images for their corporate website. Junior HTML / CSS - My client, based ...

ASP Website Developer - SQL Server - B2B - North Oxfordshire

Huxley Associates are recruiting for ASP Web Developers to work for a leading Software provider working on B2B websites and web based applications ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation