Tuesday, May 31, 2011

Debunking The Myths Of Mac And Mobile Malware

Writing malware, as with writing any other type of software, involves costs and benefits.  Like any software developer, malware authors want to reach as many users as they can, usually by creating a program that is easy and fast to deploy and can be written with minimum effort.  But with malware, these costs and benefits aren’t as obvious as many observers think.


Here at Dasient, we have a unique opportunity to detect and analyze much of the malware that is currently being distributed on the Web. What we've found is that some of the “conventional wisdom” about writing malware has proven to be myth.  Let’s take a look at some of these myths -- and how they differ from the realities we have found in our own analysis.


Myth #1:  Systems running MacOS are safer from malware than those running other operating systems.

For years, some Mac aficionados thought their systems were inherently more secure than those using Windows, for the simple reason that there were so many more exploits and malware variants turning up on Windows – and so many more Windows machines were getting infected.  However, while MacOS has perhaps been less frequently targeted, there is no inherent reason that it is safer from malware.  As MacOS market share continues to increase – not only on the desktop and laptop but also on the iPhone and iPad – cybercriminals have been investing more time into not only social engineering MacOS, but also finding exploits targeting Apple devices.

The rash of "Mac Defender" infections earlier this month is one example.  The Mac Defender scareware, which attempts to fool users into downloading bogus security software that is simply a wrapper for malware, is targeted specifically at Apple users. Another attack, IncognitoRAT, uses Java in an attempt to convert both Macs and PCs into botnet zombies. These new attacks, and a number of other recent exploits, help to prove that the Mac operating environment is indeed an attractive target, and we expect this trend to continue.

Myth #2:  The wide variety of mobile operating systems makes portable devices a less attractive target than traditional PCs.

Because mobile devices use so many operating system platforms – Windows CE, MacOS, Symbian, Android, and others – mobile devices would seem to be an unattractive environment for malware authors who are seeking to reach many users with a single exploit.  But in fact, there is much more commonality among these devices and operating systems than one might expect.  For instance, many of these devices have pre-installed browsers that either are WebKit or are based on WebKit, an open source browser engine that serves as the basis for Apple’s Safari and Google’s Chrome.

By targeting WebKit, malware authors can develop attacks that work on multiple mobile operating systems, including Android and iPhone, two of the most popular mobile operating systems.  A closer look at WebKit may lead many malware authors to go after the mobile and portable space, proving the exact opposite of conventional wisdom.  We expect malware authors will invest more heavily in targeting WebKit, and the resulting exploits could reach a surprising number of mobile platforms.

Myth #3:  Social engineering is the preferred tactic for delivering malware to its destination.

Social engineering is a very popular first step in malware deployment – think emails with infected attachments, “scareware” that frightens users into downloading fake security software, websites with infected videos or images. Tactics such as these are often attractive ways to spread malware.

Over time, however, we’ve seen that malware authors prefer more automated attacks that don’t require the user to do anything.  Drive-by downloads on popular websites have replaced email attachments, as the attackers get a higher "conversion rate" of user machines that get infected since the user simply has to visit the infected page and not even click on anything.  Drive-by-downloads also typically occur silently, within just a few hundred milliseconds, and don't give the user any signal that their machine is infected.  Even once infected, cybercriminals can keep the malware that they download and run on users' machines running in stealth, starting up only one or two processes, and keep a low footprint of activity by limiting how much email spam or network traffic they incur so that they can use the compromised machine for longer.  In addition, malware variants that are sent via drive-by-downloads are generated by automated processes that also run the variants through all traditional anti-virus engines to ensure they are not detectable on "day zero" prior to deployment.  Such automated malware variant generation has replaced the manual construction of malware.  

Myth #4: Malware authors would like to develop their code on cross-platform frameworks that enable a single exploit to work on multiple operating environments.

Recent attacks leveraging Java or other cross-platform technologies are interesting, but we don’t see them taking over the world. The fact is that applications run better when they are written for the operating environment they are going to run on.  If you were a software developer and you wanted your code to run most efficiently on a PC, would you write to the Windows APIs or Java?  Just as cross-platform development tools don't give the most efficient implementations for legitimate software packages, we also don’t see many malware authors looking to build their exploits using cross-platform techniques.  This is not to say that we won't see more exploits built on Java -- but it is unlikely that cross-platform exploit development will be the wave of the future.

The above are just a few examples of the malware myths and trends we are seeing at Dasient.  The key in analyzing these trends -- as well as the malware that may be infecting your own enterprise environment -- is to identify what's actually happening, rather than what various pundits might say is happening.  With our ability to detect and analyze malware in real time and on a large scale, we are finding that some of the conventional wisdom about malware development isn't so wise after all.  If you are supporting environments that contain a growing number of Apple and/or mobile devices, it might be worth taking a fresh look at the new wave of exploits -- and whether your current security tools are able to cope with them.


81 comments:

  1. Many Mac users believe that Mac OS is not vulnerable to malware, said Catalin Cosoi, Head of Online Threats Lab at security firm Bitdefender, in an interview with Macworld. It’s true that Windows users are much more at risk than Mac users, with just a couple of hundred samples of malware for Mac OS and about 40 million for Windows. However, there are still many threats for Mac users, and Cosoi warns that they’re only going to get worse.
    sciatic nerve
    sciatica pain relief

    ReplyDelete
  2. There are millions of blogs currently on the world wide web but this is the top one due to the useful information you are sharing with the readers. Thank you
    web hosting company

    ReplyDelete
  3. http://www.youtube.com/watch?feature=player_detailpage&v=zXKV78VERio

    ReplyDelete
  4. Look at the happy faces of people wonder

    ReplyDelete
  5. http://youtu.be/AufWWR_WIf8
    don`t miss this message...

    ReplyDelete
  6. Nice blog, hi friend, i found that there is one website offering free puzzle games. Just take one minute to sign up then you will receive one free puzzle game. Its URL is http://www.684899.com/en/CosmicCreature/project_1.htm Click the below button of the page to get in. I've done it and now i am enjoying it. Would you like one?

    ReplyDelete
  7. Really it is awesome work by the blogger. I do like this writings. Also I will wait for more like this. To learn more concerning this, please click here. Thanks a lot………

    ReplyDelete
  8. I adore the way to be taught from end to end this way and I wish for to thank the admin because he/she did a good job over here. The content helps me a lot to accomplish by workings. I highly recommend this blog site.

    ReplyDelete
  9. Great blog! I genuinely love how it is easy on my eyes as well as the info are well written. I am wondering how I may be notified whenever a new post has been madessay writer

    ReplyDelete
  10. I stumbled across your blog and was instantly amazed with all the useful information that is on it. Great post, just what i was looking for and i am looking forward to reading your other posts soonI get BlackScale clothes from here

    ReplyDelete
  11. Thanks lot for providing individuals with a spectacular possibility, I have to voice my passion for your sharpness in writing and giving acknowledges.Thanks for a good postargumentative essay

    ReplyDelete
  12. Whenever i see the post like yours i feel that there are still helpful people who shareessay writing service au reviews information for the h elp of others, it must be helpful for others.Thanks and good job.

    ReplyDelete
  13. This is a terrific article, and I would like more information if you have any. I am fascinated with this topic and your post has been one of the best I have read.dissertation writing services

    ReplyDelete
  14. I am extremely happy to find this site.I hunted to be grateful you for this great study!! I absolutely enjoying every little bit of it and I have you bookmarked to check out new stuff you post,Funding Database Bridge Loans

    ReplyDelete
  15. Thanks for sharing this great article! I am always searching for informative information like this!check my grammar

    ReplyDelete
  16. I authentically relished reading it, you're a large author.I will double-check that I bookmark your blog essaysshark.com and conclusively will come to back subsequent on. I desire to boost yourself to extend your large job, have a satisfying forenoon.

    ReplyDelete
  17. I was wondering if you ever suggested changing the layout of your blog? Its very well in writing; I love what you've got to state. But perhaps paper writing services you could a little more in the way of content so individuals could attach with it better. You've got an alarming allotment of text for only having one or two images.

    ReplyDelete
  18. This is very|a very|a extremely} nice post I found some really nice info here paper writing service reviews . i actually assume it’s nice info that additional individuals ought to see continue the good work be back once more presently.

    ReplyDelete
  19. It took us three years to construct the NeXT computer. If we'd given customers what they said they liked, we'd have constructed a computer they'd have been joyous with a year after we spoke to them - not certain thing they'd desire now.English Editing & Proofreading Services For ESL Speakers

    ReplyDelete
  20. Hello,great dispatched notes. facts and numbers are appealing stimulating and kept me gigantic someone write my essay allowance of time which I have spend on certain thing additional rather than of searching mails like this. I am waiting for more

    ReplyDelete
  21. There are wholeheartedly a allotment of minutia like that to take into consideration.I read and appreciate the whole piece and I really relished it to be dependable.merchant services

    ReplyDelete
  22. assuring details and figures, many thanks to the scribe. It is incomprehensible to me now, but in general, best essay sites the utility and significance is swamping. Thanks afresh and good luck!

    ReplyDelete
  23. period paper writing is a sculpture or an art that can be become skilled at. procedures and looms, apparatus and procedures can be professional at, clever and perfect. This means to educate that presents. To furnish loan a hand to our custom essay service composing service is habitually geared up. To get contain of additional in sequence great pleasure stay close or adhere with us.

    ReplyDelete
  24. What you're saying is wholeheartedly factual. I realist that every one-by-one should state the equal thing, but I just accept as factual that you put it in a way that every one-by-one can appreciate. I furthermore love the images you put in here,, best research paper writing service They fit so well with what you're endeavoring to state.Thanks for sharing a nice site... Thanks a lot.

    ReplyDelete
  25. astonishing read, I as of late passed this up on a cohort who was doing a little investigate with this subject. Likewise he positively came by me noon meal in lightweight of the way that I ran over over it for him. I genuinely may furthermore an obligation of admiration is in place with respect to the free midday meal,Thanks,,,proofreading website

    ReplyDelete
  26. Wonderful post. I am searching awesome news and idea. What I have found from your site, it is actually highly content. You have spent long time for this post. It's a very useful and interesting site. Thanks! Canton Fair 2013

    ReplyDelete
  27. That’s right, this website is one of the top 12,000 most viewed in FUCKING PAKISTAN.
    Why? Because they are the “English speaking writers” this fucked up company hires. I have also found evidence that suggests they have other writers in India and the Philippines. I know of a couple of companies that offer real English writers and I thought was one of them. Turns out they’re just a bunch of liars.

    The scam is real. They are thieves who could care less about you. Maybe you’ve had a couple decent papers from them. But sleep well knowing that they will take any measure to screw you over.

    That’s enough. Rant’s over. Fuck you,

    Sincerely,
    A VERY PISSED OFF FORMER CUSTOMER

    Reviewed by Sean Evans on March 25,2013 – Rating: 1.0
    Miserable experience.They ripped me off for $600 for a dissertation and refuse to give me my money back.”
    2 THOUGHTS ON “MY REVIEW”
    Taylor on June 4, 2013 at 10:52 PM said:
    You are right. I have been debating with them for at least a month now, trying to get my refunds, it’s because the writer can’t even write shit or follow the prompt. Claimed to be “professional” yeah right. They also claimed that they refunded my money already by just clearing out my balance. However, the email I received from money bookers still saying I was charged on that date. They lied & keep on saying “your refunds should be in 4-6.” i waited & after 2 weeks, still nothing. I keep on checking back even though they closed my inquiry many times. I mean, I only uploaded $55 for the balance, but I didn’t use it. The money isn’t that a big deal, it’s just the writers & their service is poorly done. I cancelled the writer because 1. Passed deadline 2. The paper was off topic, completely vague, lacks development & much more. 3. way different from U.S writing style 4. Busy schedule & I just want to try how this service work. Personally, i definitely to not recommend this service.

    Reply ↓
    admin on June 20, 2013 at 9:42 PM said:
    Thanks for your feedback, I’m glad to see that I’m not the only one.

    ReplyDelete
  28. This comment has been removed by the author.

    ReplyDelete
  29. Wow, what a blog! I mean, you just have so much guts to go ahead and tell it like it is. - Buy College Paper

    ReplyDelete
  30. Wonderful mail, thanks for putting this together! "This is obviously one great post. Thanks for the precious information and insights you have so provided here. Keep it up!" credit card processing

    ReplyDelete
  31. This is the first instant actually have glimpsed you’re joyous and do reminiscent of to notify you – it's actually pleasing to look at and that i am appreciative for your diligence. while if you expected did it all through a very very easy method that will be actually gracious. whereas over all I very not mandatory you and affirmative can comprise for a alallotmentment of mails like this. many express thankfulness most. auto title loans st. louis

    ReplyDelete
  32. This is the prime moment I even have seen your content and do prefer to notify you – it's very pleasant to ascertain and that i realise your onerous labor. although if you likely did it in an exceedingly clear-cut means that may be very pleasant. however over all I exceedingly counseled you and positive can expect additional mails like this. Thanks most. cash advance costa mesa

    ReplyDelete
  33. According to estimates from Dasient's Q4 Malware Update, 1.1 Million Web sites were infected with malware in Q4 2010.mba dissertation in UK

    ReplyDelete
  34. Buy Hot Animal Kigurumi Onesies Pajamas At Wholesale Price.
    dinosaur onesie
    stitch onesie

    ReplyDelete
  35. I simply have a glimpse here and seem pleasant to seek out this journal. Made content writing hand and extremely cooperative website. I wish most of we are inclined to United Nations bureau locality unit to search out these methods of things, here we will observe everything. I’m with the content tribute and do esteem him as a decent supplier. Thanks for your labor and you too. payday loans

    ReplyDelete
  36. inscription have to stream for the one-by-one who reads to comprehend what is human being whispered. good value going live casino online components are finished from beginning to end do study and data and the cleverness of present it pursue.

    ReplyDelete
  37. Here is the prime time My spouse and i have even seen your articles and also perform prefer to tell an individual – it is quite pleasant to find out knowning that my partner and i know the tedious toil. Houlteninstitute.com despite the fact that in case you probable did it in a really clear-cut indicates which might be quite pleasant. on the other hand total My spouse and i very counseled an individual and also optimistic can get extra mails this way. Appreciate it most.

    ReplyDelete
  38. Your Guide is revelent to the topic and this will help us and your writing style make great impact in our mind thanks for writing this article. University Assignment Help

    ReplyDelete
  39. This is the first instant actually have glimpsed you’re joyous and do reminiscent of to notify you – it's actually pleasing to look at and that i am appreciative for your diligence. Bigone . tai avatar . tai iwin . game iwin . game avatar game di dong
    while if you expected did it all through a very very easy method that will be actually gracious. whereas over all I very not mandatory you and affirmative can comprise for a alallotmentment of mails like this. many express thankfulness most

    ReplyDelete
  40. This is the first blink I have glimpsed your content and do like to notify you – it is if reality be notified pleasing to glimpse and I be convinced about your hard work. But if you did it in a clear-cut way that would be actually good. But over all I considerably suggested you and certain will linger for more mails like this. articulate thankfulness you so much. cash advance

    ReplyDelete
  41. This is the major instant I even have glimpsed your content and do favour to notify you – it's very satisfying to ascertain and that i realise your onerous work. while if you foreseen did it in an exceedingly clear-cut means that may be very satisfying. whereas over all I exceedingly counseled you and affirmative can anticipate supplemented mails like this. Thanks you most. payday loans oceanside

    ReplyDelete
  42. To start with the major line of my commentaryary – I do resembling to accolade a monster due to the periodical tribute. If reality be notified it's a good work by him and that I discovered out an dependable facilitate by his/her stunning minutia and figures. I effortlessly crave to announced, great pleasure comprise it up your work. generally I’ll converse about with your posting and change. endeavouring ahead to your a allotment of posts. cash advance

    ReplyDelete
  43. To launch by kind of the major line of my declaration – I do approximating to bestow an marvellous because of the world very wide world very wide world very wide world very wide web log title. actually it's an outsized work by him and that I found out an dependable facilitate by his/her pleasing info. I effortlessly envy to announce, great pleasure maintain it up your work. usually i will be adept to pledge with your posting and change. endeavouring ahead to your a allotment of mails. car title loans

    ReplyDelete
  44. it was fan testing post thanks for our show i had a great time and although I was very worried to start with, I was soon riding with confidence.Bed Sheets Wholesale

    ReplyDelete
  45. It is furthermore necessary to check that there are no connecting charges or repaired/ concealed charges associated with the website. Before marking up, you should clearly realise the periods and conditions online casino real money of the website and if you do not acquiesce with any of the clause.

    ReplyDelete
  46. As I'm specializing in mobile malware, lately I really could not miss the ...www.dissertationcafe.co.uk/pay-for-dissertation/

    ReplyDelete
  47. I really enjoyed reading it. It is very pleasure to get it as I got huge helps right here . I do like your hard workings and appreciate your concept . Thanks for sharing this. Thanks and keep sharing the quality content.gift card exchange

    ReplyDelete
  48. Basic section

    I was searching for a book to X. The reason of Book X is various stuff. Book X by Joe Blow is a fine perused for individuals who like Y and delight in Z.

    http://www.propaperswriting.com/

    ReplyDelete
  49. I want to to thank you for this great read!! I definitely enjoyed every bit of it. I have you book marked to look at new things you post… sbobet casino

    ReplyDelete
  50. I wish most of we are inclined to United Nations bureau locality unit to search out these methods of things, here we will observe everything. I’m with the content tribute and do esteem him as a decent supplier. Thanks for your labor and you too. hawaii vacation packages flight and hotel

    ReplyDelete
  51. very product or service is promoted and advertised through internet. The customers today want to surf the internet instead of going out and looking for various products or services. Basically the main goal of any SEO Company is to generate greater hits. denverseo.pw

    ReplyDelete
  52. I read that muscles could weigh more prada handbags but so far I haven't seen any muscles on my body. What I want to know is how do I loose replica chanel weight? I been on diet ever since but haven't lost rolex replica weight.

    ReplyDelete
  53. These carries with it official services wherever by we have a tendency to all notarise your current documents with data processor. Postage and conjointly carrier services which will facilitate maintain your current communicating necessities. check cashing corona people equally deliver vehicle conception money loans and conjointly automobile conception money loans in Carson; implement the value of the particular vehicle to look for the cash you may want. additional additional services embody an answer to be ready to invoice pay services (most expenses post precisely the same day), or even fax, check or even photocopying your current documents with need.

    ReplyDelete
  54. To start with the key line of my detail – I do love to furnish associate degree marvellous attributable to the periodical scrounging. extremely its aide degree mammoth work by him which i discovered out a awfully sensible facilitate by his/her large in degree fast payday loan . I effortlessly got to propose, giant delight sustain it up and doing all of your work. habitually i'll be expert to verify together with your posting and alter. endeavouring ahead to your a allotment of mails.

    ReplyDelete
  55. This is the first instant actually have glimpsed you’re joyous and do reminiscent of to notify you – it's actually pleasing to look at and that i am appreciative for your diligence. Bigone . game iwin.
    while if you expected did it all through a very very easy method that will be actually gracious. whereas over all I very not mandatory you and affirmative can comprise for a alallotmentment of mails like this. many express thankfulness most dich vu thiet ke web

    ReplyDelete
  56. Just fax U.S. documents to support web application. The documents we'd like unit of activity easy—things you've already got, type of a replica of your driver’s license, insurance card payday loans direct lender chicago, proof of employment, etc. you may be able to fax them to U.S. once you apply, or bring them with you once you visit one of our stores to terminate your loan.

    ReplyDelete
  57. To launch by method of the primary line of my declaration – I do approximating to bestow a large-scale due to the journal name. very it's {a massive|an outsized|an oversized} work by him and that i discovered an honest facilitate by his/her large knowledge bad credit payday loans. I simply envy to give notice, please maintain it up your work. sometimes i will be able to insure with you're posting and change. wanting ahead to your a lot of mails.

    ReplyDelete
  58. Really nice articles for IOS os. I really enjoyed reading it.
    academic essay writing help

    ReplyDelete
  59. great infomative blog about operating systems for ios users.
    college paper writing company

    ReplyDelete
  60. You made some great points there. I did a search on the subject and found most people will agree with your weblog.
    replica jackets

    ReplyDelete
  61. Thanks for sharing this great article! I am always searching for informative information like this!
    essay writing service

    ReplyDelete
  62. I am interested in this topic and would like to find out more information through your upcoming posts.This is a wonderful website top gun leather bomber jacket

    ReplyDelete
  63. I want to to thank you for this great read!! I definitely enjoyed every bit of it. I have you book marked to look at new things you post. Write My Dissertation

    ReplyDelete
  64. I wish most of we are inclined to United Nations bureau locality unit to search out these methods of things, paper writing

    ReplyDelete
  65. Thanks for sharing this Precious Information and I will share this with my friends too. essay writing

    ReplyDelete
  66. Thanks for sharing this Precious Information.assignment helper

    ReplyDelete
  67. Recognize on the web bingo activities like nothing you've perceived going before utilizing the free bingo activities obliged the most part bingo destinations. Despite giving crazy cash regards, the chance is allowed by these amusements to people to visit the web bingo webpage .. how to make money binary trading


    ReplyDelete
  68. There are various methodologies to benefit energetic anyway I figure everything positively depends on upon what your importance of "quick" is. My significance of smart is setting up a site, publicizing it and seeing profits inside a month. In case you derive that its going to happen any speedier than that, binary trading software

    ReplyDelete
  69. When you have to secure money from home, you don't have to look more removed than yourself. Perceive your endowments, ability, and assess how you can put them to incredible use by offering an organization and making a business part for them. Along these lines.. Best binary trading software


    ReplyDelete
  70. To alpha with the foremost band of my account – I do ache to accumulation Accessory in Nursing Brobdingnagian as a after-effects of the account esteem. actual it's adorable acclaim amazing assignment by him that i accustomed out acclaim dependable facilitate by his/her immense detail and figures. I alone got to be accountable to be accountable to be accountable to be accountable to be accountable to be accountable to be accountable to broadcast, immense contentment comprise it up your work. about I’ll sit bottomward at the ancillary of your announcement and alter. admire advanced to your a allocation of mails.auto title loans norman ok

    ReplyDelete
  71. There's a really cool shopping device that has been around for a couple of years that keen clients have been utilizing to spare time and cash while profiting on the web. It is called My Shopping Genie. Just in the recent months, they have included a MLM twofold pay plan to the mix that truly has the business buzzing. In case you're perusing this article, chances are you've known about it and are thinking about whether this will be an alternate system advertising or MLM trick or is it a honest to goodness business with approaches to profit and is worth a genuine look
    Fast Income App Review.

    ReplyDelete