Friday, March 22, 2013, 11:40 am PT (02:40 pm ET)
Apple updates XProtect.plist to block YontooShortly after news emerged of a new adware trojan targeting OS X web browsers, Apple has updated its malware and adware detections list to block Yontoo.
Intego's Mac Security Blog noted (via MacRumors) on Friday that Apple had updated its "XProtect" anti-malware system. XProtect.plist will now recognize Yontoo and warn users that attempt to install the software on their computers.
Intego's post notes that the XProtect detection "is very specific and potentially location-dependent." The extra specificity, Intego supposes, may be there in order to stop only indirect installations of the file.
News of the Yontoo trojan emerged recently when a Russian anti-virus company pointed out its existence. Yontoo asks users if they want to install a browser plugin, media player, download accelerator, or other video-oriented program. Upon agreeing to the download, the plugin begins transmitting browsing data to an off-site server. User browsing data is processed, and the server sends back a file embedding third-party code into webpages visited by the user. The viewing or clicking of embedded ads then generates ad affiliate network profits for the criminals behind the adware.
On Topic: Mac OS X
- Apple releases OS X 10.9.5 Mavericks with reliability enhancements, includes Safari 7.0.6
- Apple releases new OS X Yosemite betas for developers, public beta participants
- Apple Watch, AirDrop, iBeacon & Continuity coax advanced features from Bluetooth & WiFi
- VMWare releases Fusion 7 with support for OS X Yosemite and Retina optimization
- Apple issues first iCloud for Windows beta with iCloud Drive support