New Mac OS X backdoor trojan "Tsunami" discovered

Share this article:
A trojan that has been targeting Linux users for several years is now setting its sights on the Mac OS X, security researchers warned.

The so-called “Tsunami” backdoor trojan, detected as OSX/Tsunami.A., is derived from an older Linux malware family that has been around since at least 2002, Robert Lipovsky, researcher at anti-virus company ESET, said in a blog post Wednesday. It enables infected machines to participate in distributed denial-of-service (DDoS) attacks intended to flood websites with traffic.

Once it has made its way onto a system, the malware attempts to connect to an IRC channel, where it can receive further commands. Besides enabling DDoS attacks, it can be used to download additional malware and take control of an affected machine.

Graham Cluley, senior technology consultant at security firm Sophos, told SCMagazineUS.com in an email Wednesday that none of his company's customers have reported their computer infected by Tsunami.

"The sky is not falling," he said.

Even so, Mac malware is a real problem, though much less prevalent than Windows threats, Cluley said in a blog post Tuesday. Last week, for example, researchers discovered a separate Mac trojan, which was crafted to disable the anti-malware protection Apple has built into its OS X platform.

Share this article:

Sign up to our newsletters

More in News

Instagram iOS and Android apps vulnerable to session hijacking

Two researchers wrote about the Instagram app for iOS and Android is vulnerable to session hijacking because both send unsecured information through HTTP.

Report: Hackers stole data from Israeli defense firms

A report by Brian Krebs detailed the intrusions, which occurred between Oct. 2011 and Aug. 2012.

Neverquest trojan targets regional banks in Japan

Symantec researchers found a new variant of the banking trojan.