Security experts F-Secure have discovered a new Mac Trojan that disguises itself as a PDF file.
The malware downloads the file into a temp file, then opens itself as a PDF in order to distract users from any other suspicious activity which may be going on.
The PDF contains text written in Chinese-language “relating to political issues, which some users may find offensive.”
Whilst Mac malware might be considered rarer than Windows targeted payloads, this isn’t the first that has been discovered this year, or even this month. ITProPortal also reports that there is another circulating that mimics the Adobe Flash installer.
“This (PDF) malware may be attempting to copy the technique implemented by Windows malware, which opens a PDF file containing a ‘.pdf.exe’ extension and an accompanying PDF icon,” F-Secure warns.
Whilst the sample of the Trojan that they are investigating doesn’t yet have an extension or an icon, F-Secure admits this could have been lost when it was submitted.
However, they say, this could also indicate that the malware is “even stealthier than in Windows” as it may be able to “use any extension it desires.”
The Trojan more than likely comes in through an email attachment and once executed, installs Backdoor:OSX/Imuler.A, which is capable of contacting a remote server for instructions.
It then takes screenshots of the infected machine and steals files to send to the controller.
Whilst F-Secure says that the command and control of this malware is not yet capable of communicating, as it is in its infancy, the domain it is registered to has shown recent signs of activity.
“The author could be just testing the water to see if the sample is detected by different AV vendors,” the security company points out.
Last month a Flash trojan was discovered which hijacks a user browser and mimics Google search pages.
It then displays a false search results page and pulls pop-ups from a remote server.
F-Secure recommends that users only download Flash from the Adobe website and don’t open any email attachments that come from people they don’t know.










