Backdoor:OSX/Imuler.B No Likes Wireshark

A new variant of Mac malware — Imuler.B — has recently surfaced. It’s pretty much the same as Backdoor:OSX/Imuler.A, but with small changes and code optimizations. The current C&C server is ouchmen.com.

One interesting new function: Imuler.B exits if Wireshark is found.

Imuler.B, Wireshark exit

Imuler is thought to be targeting Tibetan rights activists.

In other Mac related news: our Broderick Aquilino will be giving a presentation this Thursday at VB2012 on Flashback OS X malware.

On 24/09/12 At 02:25 PM

Read more: Backdoor:OSX/Imuler.B No Likes Wireshark

Story added 25. September 2012, content source with full text you can find at link above.