Flashback Trojan Infection Bad as Ever: Is Apple Losing the Malware War?

By Alexandra Burlacu | Apr 21, 2012 01:23 PM EDT

Share This Story

  • Print
  • Email

While many security companies reported that the number of Flashback infected Macs is shrinking, Russian antivirus firm Dr. Web tells a different story. Dr. Web was the first to report the malware attack against Apple's OS X in early April. On Friday, April 20, the Web security firm said that the pool of Flashback-infected Macs is still high around the 650,000 mark, and infections continue to occur.

Follow us

"The botnet statistics acquired by Doctor Web contradict recently published reports indicating a decrease in the number of Macs infected by BackDoor.Flashback.39. The number is still around 650,000," Dr. Web said in its Friday blog post.

American antivirus software company Symantec reported on Tuesday that the Flashback botnet infection has been reduced to just 140,000, a dramatic decrease from the estimated 600,000 in early April.

During a conference call with information-security specialists and journalists on Thursday, Kaspersky Lab, another Russian antivirus company, estimated that the Flashback botnet has dropped to only 30,000 machines. Dr. Web thinks it has found the reason behind such stark discrepancies in numbers.

Reasons for Discrepancy

"Recent publications found in open access report a reduction in the number of BackDoor.Flashback.39 bots. Typically, these materials are based on analysis of statistics acquired from hijacked botnet control servers. Doctor Web's analysts concluded a research to determine the reasons for this discrepancy," reads the company's blog post.

Dr. Web's blog post continues to explain how machines infected by the Flashback malware generate new domain names for command-and-control (C&C) servers. They do this by using pre-arranged algorithms that allow information-security companies to set up "sinkhole" servers, designed to capture and measure botnet traffic.

After running through the list of potential C&C servers, each infected machine then fires a request to a specific server. Instead of using a generated domain name, that server uses a static Internet Protocol (IP) address. The server does reply to the infected machine, but it also keeps the connection open, which means the infected machine cannot communicate with any other C&C servers. According to both Dr. Web and Symantec, a specific sinkhole at IP address 74.207.249.7 was failing to close TCP connections after communicating with infected machines. Dr. Web posted a screenshot to illustrate this. As a result, the infected machine is put in standby.

"Bots switch to the standby mode and wait for the server's reply and no longer respond to further commands," explains the blog post. "As a consequence, they do not communicate with other command centers, many of which have been registered by information security specialists."

Symantec Agrees Dr. Web's Analysis is Accurate

Following the release of Dr. Web's latest estimate, Symantec agreed that Dr. Web's argument was valid, and updated its post. Symantec researchers now believe they "are receiving limited infection counts" for that Flashback Trojan. "We now believe that their analysis is accurate, and that it explains the discrepancies," Liam O Murchu, manager of operations at Symantec's security response center, told Computer World.

Earlier this month, Apple had issued a Flashback removal tool to block the Flashback malware installation and remove any instances of it, but has not commented on the infection. For now, only Apple knows how many Macs have actually applied the software patches. Mac users are advised to apply Apple's software updates and install antivirus software to avoid further infections.

(reported by Alexandra Burlacu, edited by Dave Clark)

 

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
Nokia Lumia 928Verizon Exclusive Nokia Lumia 928 Now $49.99 At Online Retailers
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Leaked
Samsung Galaxy S4 App Contest Boasts $800,000 Total Prizes For Talented Devs
Photo Taken With Samsung Galaxy Note 3 'Leaked' Online
Tablet / Laptop / PC
Samsung Galaxy Tab 3 8.0 Leaked ImageSamsung Galaxy Tab 3 8-Inch Specs, Photo Leak Online
Asus 1015E Ubuntu Notebook To Launch Soon With $215 Price Tag
New MacBook Air To Debut In June With Intel's New Haswell Processor?
Nexus 7 Refresh Teased In Google+ Hangouts Video, Sports Glowing Notification Light
Gadgets
Ouya Android-Powered $99 Game ConsoleOuya Will Be At E3 2013, But Not Where You Think
Next Microsoft Xbox To Sport Dashboard UI Update And Tile Changes
Google Media Streamer Hits FCC To Replace Nexus Q
Google Glass Raises Lawmakers' Concerns: Congress Demands Answers About Privacy
OS / Software
Galaxy S3 Mini Jelly Bean UpdateAndroid 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Leaked
Samsung Galaxy S4 Mega Confirmed By Samsung In WatchOn Change Log?
Android 4.2.2 Jelly Bean Coming Soon For HTC One; Google Edition of HTC One On The Way
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
Internet / Social Media
The Demonstrator Set Up Between Two Skyscrapers In Karlsruhe, West Germany Download 40 GB In A Second: Researchers Set Up World's Fastest Wi-Fi Network In Germany
YouTube Shoppable Videos - Will Google Hit A New Jackpot?
Apple iRadio Reportedly Delayed Over Song Skipping Issue
Yahoo Is Eyeing Tumblr
What's App
Galaxy S4 White FrostSamsung Galaxy S4 App Contest Boasts $800,000 Total Prizes For Talented Devs
Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Itsdagram Available Now For Windows Phone: Best Instagram Client Around

DON'T MISS

A photo allegedly taken with the Samsung Galaxy Note 3
Photo Taken With Samsung Galaxy Note 3 'Leaked' Online
The photo is posted by SamMobile and the screenshot of the EXIF data of the image shows that the
Nokia Lumia 928
Verizon Exclusive Nokia Lumia 928 Now $49.99 At Online Retailers
Want a Lumia 928 on Verizon Wireless? Pick it up from RadioShack or Wirefly for $49.99.
Asus 1015E Notebook
Asus 1015E Ubuntu Notebook To Launch Soon With $215 Price Tag
Asus is offering an alternative to the Windows 8 1015E notebook model: an 1015E-DS03 notebook
YouTube App
YouTube Shoppable Videos - Will Google Hit A New Jackpot?
YouTube is no longer a simple video-sharing site, it now offers consumers the chance to shop
Galaxy S3 Mini Jelly Bean Update
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Leaked
The new firmware comes with some Galaxy S4 features but it is not known whether the camera features
Samsung Galaxy Tab 3 8.0 Leaked Image
Samsung Galaxy Tab 3 8-Inch Specs, Photo Leak Online
Samsung recently announced the Galaxy Tab 3 7.0, but a new report with leaked specs and photo now

Ouya Android-Powered $99 Game Console
Ouya Will Be At E3 2013, But Not Where You Think
The Ouya team might not be on the E3 2013 show floors, but you can still give the console a test
Galaxy S3 Sapphire Black
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
The update comes with some features like Group CastApp and Page Buddy.
MacBook Air
New MacBook Air To Debut In June With Intel's New Haswell Processor?
Apple is expected to update its hardware lineup as soon as June with a new MacBook Air likely
Google Nexus 4 White Version
White Nexus 4 To Launch On June 10 Rocking Latest Android 4.3
The white Nexus 4 that created a lot of buzz among rumor mills recently, finally has a launch date:
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics