Fake Snow Leopard sites leading to trojan infections
Hackers are trying to take advantage of users looking for free versions of the Snow Leopard software.

Criminals are already trying to take advantage of Mac users looking for Apple's Snow Leopard, with websites offering the software for free found to be carrying malware.
Trend Micro security researcher Feike Hacquebord found fake sites carrying a variant of the JAHLAV family of malware that can change a user's DNS server and point them towards a fake website - in some cases to phishing sites.
This is a similar threat to a version of JAHLAV that affected versions of Quicktime as well as pose as pirated versions of PDF application Foxit Reader.
Trend Micro solutions architect Rik Ferguson said that criminals were taking advantage of the "desire" and "greed" of people who were not willing to pay for the new OS when it is released.
"It's exploiting some very, very old human weaknesses," he said.
Apple seems to be taking notice of the new wave of Mac malware, with Ferguson saying that he had it confirmed from Snow Leopard beta testers that the real release would carry anti-malware controls.
"It's great that they are waking up to the threat I really, really welcome that," he said. "What I would say though of what I've seen pre-release, is that it is very rudimentary, very signature based for two types of malware, and that doesn't include the malware that was found in this case."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He said that the creators of JAHLAV were very likely the same kind of people behind traditional PC malware, as they were seeing similar techniques such as social engineering putting it in downloads people were searching for.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Exploitation of Docker remote API servers has reached a “critical level”
News Hackers are targeting Docker’s remote access API as it allows them to pivot from a single container to the host and deploy malware with ease
By Solomon Klappholz
-
Cyber criminal underground “thriving” as weekly attacks surge by 75% in Q3 2024
Cyber attacks reached another all-time high this quarter as digital crime continues to be a highly profitable industry for threat actors
By Solomon Klappholz
-
Alarm raised over patched Phemedrone Stealer malware that's being used to target Windows PCs - here's what you need to know
News Phemedrone Stealer is being used to exploit a vulnerability in Windows Defender SmartScreen despite the issue being patched in November 2023
By Solomon Klappholz
-
SOC modernization and the role of XDR
Whitepaper Automate security processes to deliver efficiencies across IT
By ITPro
-
Uncovering the ransomware threat from global supply chains
Whitepaper Effectively mitigate ransomware risk
By ITPro
-
The near and far future of ransomware business models
Whitepaper Discover how criminals use ransomware as a cyberweapon
By ITPro
-
Trend Micro security predictions for 2023
Whitepaper Prioritise cyber security strategies on capabilities rather than costs
By ITPro
-
'Potentially unsecured' SMBs are propping up an IT supply chain riddled with ransomware
News More than half of IT supply chains have been impacted by ransomware attacks in recent years and organisations are failing to implement the necessary steps to prevent future damage
By Connor Jones