Site Meter

A Real Mac OS X Virus On The Loose

OK, technically it’s a Trojan but I think the term “virus” is better to get attention. The Unofficial Apple Weblog states:

In the wake of the ARDAgent vulnerability discovered yesterday, we all have something new to look out for: OSX.Trojan.PokerStealer is the official name of a trojan horse masquerading as a poker game. The trojan is distributed in a 65K .zip archive.

According to security company Intego, running the trojan activates SSH, and transmits the username, password hash, and IP address of the computer to a server. It asks for an administrator's password after displaying a message about a corrupt preference file that needs to be repaired.

The "PokerGame" application is 159,843 bytes, and includes the text "Copyright 2008 Andrew" in the version information (visible in Get Info).

Don’t be a fool. Don’t download stuff from non-reputable sites and don’t open attachments you don’t know what they are.