Intego Security: New Mac OS X Trojan Horse on Porno Sites

Intego Security on a Trojan hosted on porno sites, that tricks users into thinking they’re installing a QuickTime video codec that will allow them to watch free videos:

This Trojan horse, a form of DNSChanger, uses a sophisticated method, via the scutil command, to change the Mac’s DNS server (the server that is used to look up the correspondences between domain names and IP addresses for web sites and other Internet services). When this new, malicious, DNS server is active, it hijacks some web requests, leading users to phishing web sites (for sites such as Ebay, PayPal and some banks), or simply to web pages displaying ads for other pornographic web sites.

(Via Macworld.)

Wednesday, 31 October 2007