Jan 28 2009

Trojan Found in Pirated Copies of Adobe Photoshop CS4 for Mac

  • Written by soulxtc
  • 4 Comments


Mac users downloading copies via BitTorrent tracker sites get hit with another malware attack.

Just yesterday I reported on how Mac users, who have prided themselves for years that it was their PC cousins bearing the brunt of virus and malware attacks, were being infected by a Trojan horse contained in pirated copies of Apple’s iWork ‘09 downloaded from public BitTorrent tracker sites.

Now there a new variant of the iServices Trojan horse has been discovered by the same security firm Intego in pirated copies of Adobe Photoshop CS4

The actual Photoshop installer is clean, but the Trojan horse is found in a crack application that serializes the program.

OSX.Trojan.iServices.B

After downloading this version of Photoshop, users will run the crack application to be able to use it. The crack application extracts an executable from its data, than installs a backdoor in /var/tmp/, a directory which is not deleted when the computer is restarted. (If the user runs the crack application again, the Trojan horse creates a new executable with a different name; these random names make it harder to ensure safe removal of the malware.)

The crack application then requests an administrator password, launching the backdoor with root privileges. This copies the executable to /usr/bin/DivX, then creates a startup item in /System/Library/StartupItems/DivX. The program checks to see if it has been launched with root privileges, then saves the root hash password in the file /var/root/.DivX. It listens on a random TCP port, and answers requests such as GET / HTTP/1.0 by sending a 209-byte packet, and makes repeated connections to two IP addresses.

Next, the crack application opens a disk image which is hidden in its resource folder, in a folder named .data, and proceeds to crack the Photoshop program, allowing it to be used.

OSX.Trojan.iServices.B

Since the malicious software connects to a remote server over the Internet, the creator of this malware will be alerted that this Trojan horse is installed on different Macs, and will have the ability to connect to them and perform various actions remotely. The Trojan horse may also download additional components to an infected Mac.

Intego is issuing this alert to warn Mac users not to download Photoshop CS4 installers from sites offering pirated software. (As of 6 am EST, nearly 5,000 people have downloaded this installer, according to a major BitTorrent tracker site.) Since the Trojan horse, in this case, is found merely in the crack application that is bundled with Photoshop CS4, users should avoid downloading any cracking software from sites that distribute pirated software. The risk of infection is serious, due to the number of infected users, and these users may face extremely serious consequences if their Macs are accessible to malicious users. The first version of this Trojan horse was seen downloading new code to infected computers, which were then used in a DDoS (distributed denial of service) attack on certain web sites. Since this new variant uses the same technology, and contacts the same remote servers, it is likely that it will attempt to download new code and perform such actions.

jared@zeropaid.com

Related Posts

  1. Trojan Found in Pirated Copies of Apple iWork ‘09
  2. Adobe To Offer Ad-Supported, Web-Based Version Of Photoshop
  3. P2P Trojan Makes PC Talk, Laugh at You, While Erasing Hard Drive
  4. Pirated Copies of Vista About to Go ‘Black?’
  5. Microsoft Reduces Approach to Pirated Copies of Vista
Zeropaid on Facebook

Comments

  1. ejonesss

    does it use the same installer package as iwork does?

    meaning is it a separate installer that is not part of the original legit installer?

  2. soulxtc

    yep it contains an additional package called iWorkServices.pkg that is bogus…..
    IMG http://www.intego.com/pix/ism0901.png

  3. ejonesss

    @soulxtc that is iwork that contains iWorkServices

    upon further research (downloading) i found it is the cracker that installs the bogus divx extension.

    first photoshop is a image editor NOT A VIDEO EDITOR and has no reason to be using divx.

    you virus writers we know about the trick .

    if you really want to pull one over us then impersonate a driver or something that fits into the same category as what you are planting it in.

    if you are going to be disguising a trojan as divx then plant it into the installer of a program like toast (has the ability to convert divx file to dvd) or a video converter program.

  4. thepuzzler

    Hmm Why would anyone give a Crack [k] Root access??

Trackbacks url:

Leave a Comment...

  • Advertisement

    Giganews Newsgroups

1 Star2 Stars3 Stars4 Stars5 Stars
(1 votes, average: 4.00 out of 5)
Loading ... Loading ...

  • mpsharp.com Blog » Watching NFL games online: [...] show you a number of streams to choose from for each game.  All the streams require some sort of StreamTorrent pl...
  • ejonesss: no it is not going to completely stop piracy because while it will stop those whose reason for piracy is quality it is n...
  • file sharing anonymously - P2Pfreak.com: [...] and Trusty Files) just google any one of them and you will get some great info. also here IP filtering with uTorr...
  • soulxtc: Wasn't aware people were guaranteed jobs...
  • mountain_rage: BTW Youtube is supposed to go 1080P soon :D....
  • Gibbbo: Unfortunately the European stores still don't have anything close to the selection available in the USA store. I'm buyin...
  • STUDY: Artists Earn More in a P2P World: [...] personal favorite is the “The Impact of Music Downloads and P2P File-Sharing on the Purchase of Music: A Study F...
  • D.AN: So a stupid plan has been become a doubly-retarded plan....
  • sdsd