New Mac Trojan injects ads into Chrome, FF, and Safari pages

  • 21 March 2013
  • 2 replies
  • 11 views

Userlevel 7
Just yesterday, I posted about our new-and-improved SecureAnywhere solution for Macs. The purpose was two-fold: 1. I wanted to make sure WSA users know that our very useful Password Manager is now included in our Mac solution (if you have an ISP or Complete subscription) and 2. I wanted to remind Webroot Community-goers that Macs are not virus/phishing-proof.
 
Well, sure enough, here's a new reinforcement of my reminder. According to numerous reports (including this one by The Next Web), Russian security firm Doctor Web discovered a new Mac Trojan by the name of Yontoo that tries to trick users into installing a browser plugin in an attempt to steal info and make money for it's creators.
 
"When launched, Trojan.Yontoo.1 prompts the user to install something called "Free Twit Tub" or something similar...instead of the claimed program, the Trojan downloads and installs the adware plugin for Chrome, Firefox, and Safari. When users surf the web, the plugin transmits information about the loaded pages to a remote server, and returns with a file that enables the trojan to embed third-party code into pages visited by the user."


Mac viruses and phishing attacks are real. And they're here to stay. So if you're a Mac user (I am), I can't stress the importance of protecting it with great internet security to prevent your computer from Yontoo and other attacks!

 
Here's a pic of an install prompt Yontoo victims may see:

 

(Source: The Next Web)

 
 

2 replies

Userlevel 7
Nice timing!  And thank you for the reminder.  😃
Userlevel 7
What? I though Macs were immune to attacks! 😃

Reply