New variant of Boonana Trojan Horse in the Wild

November 4, 2010 in Announcements

[prMac.com] Las Vegas, Nevada - A new variant of the Boonana malware, first documented and named by SecureMac, has been discovered by ESET. The new variant, trojan.osx.boonana.b, behaves in a very similar manner to the original malware, and is currently being distributed on multiple sites. In addition to the website documented by ESET as currently distributing the malware, SecureMac has identified two more websites that are currently hosting the new malware variant. Rather than the initial site which tricks users into running (and installing) the malware, these servers seem to be hosting update code for the malware. The infected machines contact these servers looking for updates to the malware payload. At the time of analysis (November 2nd, 2010), these servers were live, and distributing malware.

In addition to the malware updates, these servers contain what appear to be keystroke logs from infected machines, including usernames and passwords.

With a quick glance, Boonana may look like a variant of Koobface, which was discovered for Windows back in 2008. However, ESET has also confirmed SecureMac's initial analysis of Boonana as a new unique piece of malware, which does not share a common code-base with the previously discovered Koobface worm. ESET's threat analysis of Boonana can be found at ESETs blog.

Additionally, Microsoft identifies the malware as Trojan:Java/Boonana, and rates it as a severe threat for both Mac and Windows.

Another security vendor has verified that the Boonana malware is capable of infecting Linux machines, and will proceed to join a botnet once installed. The malware also affects Mac OS X and Microsoft Windows.

SecureMac's free Boonana Trojan Removal Tool can detect and remove the threat for Apple's Mac OS X; manual removal instructions are included in SecureMac advisory. The free Boonana Trojan Horse removal tool runs on Mac OS X 10.5 and higher. Users may also run MacScan Security and Privacy software for Mac OS X to detect the Boonana Trojan Horse. MacScan runs on Mac OS X 10.2.4 or higher and includes a free 30-day trial. Existing users are encouraged to download the latest malware definitions before scanning.

Since 1999, SecureMac has been at the forefront of Macintosh system security. The site not only features complete Macintosh Anti-Spyware and Antivirus solutions, but also operates as a clearinghouse for news, reviews and discussion of Apple computer security issues. Users from novice to the most advanced will find useful information at SecureMac that is designed to make their computer experience trouble free. Copyright (C) 2010 SecureMac. All Rights Reserved. Apple, the Apple logo and Macintosh are registered trademarks of Apple Inc. in the U.S. and/or other countries.

###

Nicholas Raba
President
Email this

PDF
Read other releases by this member.


Trackbacks

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 4:38 pm on Cube-Zone

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 4:24 pm on Press Releases

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 12:19 pm on iSlate is here

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 10:20 am on IPHONE NEWS

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 3:08 am on MyAppleSpace

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:10 am on The MacTrack - iPhone, iPod, iPod Touch and Mac News

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:10 am on The iPhone Bible

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:09 am on Good Morning Mac

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:09 am on Mac Fanatic

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:08 am on Daily App Show - Video App Reviews for iPhone and iPod Touch Users

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:07 am on Technology News Service

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:07 am on Apps | iPhone App Reviews | iTouch | iPad Applications

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:07 am on MacMegasite

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:07 am on GSM Mobile Phone News

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:07 am on Apimac - Apple News Wire

New variant of Boonana Trojan Horse in the Wild

posted Nov 4, 2010 at 2:03 am on Breaking Windows