Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Low-Threat Mac OS X Trojan Appears

Add as a preferred source on Google

A Trojan horse aimed at Apple’s Mac OS X operating system has appeared, purporting to be screenshots of the company’s forthcoming Mac OS X 10.5 “Leopard” operating system. Although the Trojan, dubbed “OSX/LeapA” by antivirus firms, can spread itself via the iChat instant messaging program and damage applications on a Mac OS X computer, unlike many Windows Trojans, it spreads by fooling users into launching it manually, rather than by leveraging security flaws in the operating system.

The Trojan was uploaded earlier this week to the MacRumors Forums site under the filename latestpics.tgz. Longtime Macintosh developer Andrew Welch of Ambrosia Software has posted a detailed analysis of the malware, which he initially dubbed “Oompa-Loompa.” When executed, the Trojan attempts to send itself to the user’s iChat contacts and damages applications on the user’s computer in attempts to spread itself. The trojan appears to attempt to spread itself through other applications as the user launches them, but, due to a bug, winds up damaging the applications, which then fail to launch.

Recommended Videos

The overall thread from OSX/LeapA is low. In order to be infected, users must:

  • acquire the Trojan, whether via download, email, iChat, or another means
  • manually decompress the file, and
  • manually open the decompressed file (which, for most users, will entail entering their administrator password)

The Trojan cannot spread between computers using a security loophole or other automatic mechanism: to be “infected,” a user must manually unarchive the file and deliberately open it.

Mac OS X users can easily protect themselves by simply not opening any archive they’re not expecting (especially via email or iChat, or if it’s called latestpics.tgz). Sophos and Symantec have already updated their virus definitions to detect OSX/LeapA, and are collecting information about the Trojan.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
One of the most capable desktop processors available just got $125 cheaper: AMD Ryzen 9 9950X3D down to $573
AMD Ryzen 9 9950X3D drops to $573.99 (18% off): 16-core, 144MB cache, AM5, 3D V-Cache.
AMD Ryzen 9 9950X3D deal

The AMD Ryzen 9 9950X3D is down to $573.99 in a limited-time deal, a $125 saving off its $699 list price, and it represents something AMD hadn't offered before: a 3D V-Cache processor with a high enough core count to handle demanding creative and professional workloads without sacrificing the gaming performance that cache stacking delivers. For anyone running one machine for everything, this is the processor the 9000 series has been building toward.

get the deal

Read more
Adobe Firefly AI is now live publicly, hoping you’ll talk to an AI and get work done
Firefly AI Assistant can to handle your entire creative workflow
adobe-firefly-ai-assitant-public-beta

Adobe just opened up the public beta for Firefly AI Assistant. It is a conversational AI agent that sits across your entire Creative Cloud suite and handles multi-step workflows on your behalf.

You just have to describe what you want, and the assistant will figure out which Adobe tools to use and in what order, including Photoshop, Lightroom, Premiere, Firefly, and others.

Read more
Meta’s latest outrageous deal is getting solar power beamed even at night from satellites
Meta's deal with Overview Energy isn't just about clean power. It's a preview of what keeping AI running sustainably at planetary scale is going to require.
Satellite by Starlink

Out of all the things Meta has ever been accused of, thinking small hasn’t been one of them. 

The company that owns the most popular social media and messaging platforms like Facebook, Instagram, Messenger, and WhatsApp, is now looking at beaming sunlight from space to the Earth’s surface for powering its AI data centers after dark (via TechCrunch). 

Read more