Information Security News mailing list archives

Flashback botnet not shrinking, huge numbers of Macs still infected


From: InfoSec News <alerts () infosecnews org>
Date: Mon, 23 Apr 2012 02:16:43 -0500 (CDT)

https://www.computerworld.com/s/article/9226429/Flashback_botnet_not_shrinking_huge_numbers_of_Macs_still_infected_

By Gregg Keizer
Computerworld
April 20, 2012

Contrary to reports by several security companies, the Flashback botnet is not shrinking, the Russian antivirus firm that first reported the massive infection three weeks ago claimed today.

Dr. Web, which earlier this month was the first to report the largest-ever successful malware attack against Apple's OS X, said Friday that the pool of Flashback-infected Macs still hovers around the 650,000 mark, and that infections are continuing.

Also on Friday, Liam O Murchu, manager of operations at Symantec's security response center, confirmed that Dr. Web's numbers were correct.

Both Dr. Web's tally and its contention that infections are ongoing flew in the face of other antivirus companies' assertions. Kaspersky Lab and Symantec, which have each "sinkholed" select domains -- hijacked them before the hackers could use them to issue orders to compromised machines -- used those domains to count the Macs that try to communicate with the malware's command-and-control centers.

[...]


_______________________________________________
LayerOne Security Conference
May 26-27, Clarion Hotel, Anaheim, CA
http://www.layerone.org


Current thread: