New Flashback Variant Continues Java Attack, Installs Without Password

Intego has discovered a new variant of the Flashback malware, Flashback.S, which continues to use a Java vulnerability that Apple has patched. No password is required for this variant to install, and it places its files in the user’s home folder, at the following locations:

  • ~/Library/LaunchAgents/com.java.update.plist
  • ~/.jupdate

It then deletes all files and folders in ~/Library/Caches/Java/cache in order to delete the applet from the infected Mac, and avoid detection or sample recovery.

Update your Macs people, update. If you are freaking out, and want an antivirus for your Mac, Sophos, Avast, and ClamxAV are free options. But really, antivirus give a false sense of security and are no match to common sense and updating everything regularly, and this is true fro Mac or PC.

About these ads
Tagged , , , , , , , , ,

Comments

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.

Join 582 other followers

%d bloggers like this: