A new trojan for the OS X has been discovered. When the Trojan is executed, it creates the following file:
/Applications/ezmal
The Trojan then opens a command shell, which allows a user to select an application and a port number. The chosen application can then be used as a back door, which allows a remote attacker to gain access to the compromised computer. The Trojan copies the executable file for the chosen application to the following location:
/Applications/[CHOSEN APPLICATION]/Contents/MacOS/2 OSX.Lamzev.A






{ 1 trackback }