Malware, Vulnerability Management

New variant of Apple malware once again puts users at risk

A new twist on an old piece of Apple malware, named OSX/Tibet.C, has put the backdoor on users' radars again.

According to researchers at Mac security software company Intego, the malware is downloaded to computers unbeknownst to users via Java applets hosted on compromised websites. The attack is known as a 'watering hole' because it baits victims without having to target them individually.

The trojan contacts a China-based command-and-control server which gives operators remote access.

Apple's operating system is typically malware free, although the password-stealing Flashback malware infected hundreds of thousands of machines last year. Tibet.C exploits Java vulnerabilities which can be patched by downloading Java 7u25 and newer versions of the platform. 

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.