Home » News » Malware » The Kelihos botnet is down but Macs are still in danger

The Kelihos botnet is down but Macs are still in danger

By Gina on September 29, 2011 | Malware, Microsoft, Kaspersky, shutdown of the Kelihos botnet, cz.cc domain, fake anti-virus, spam sites, Mac Defender malware, Mac, trojan, security software The Kelihos botnet is down but Macs are still in danger

This week was big enough for Microsoft and Kaspersky because of the shutdown of the Kelihos botnet. It was widely discussed because Microsoft was able to initiate an individual defendant in their US court case this time.

Dominique Alexander Piatti, the owner of the cz.cc domain was named and Microsoft got permission to shutdown the entire cz.cc domain. This domain was recently seen abusing other programs with botnets, such as, spreading fake anti-virus, spam sites and for other malicious intentions.

Security researchers have paid an attention, that cz.cc domain was the host of Mac Defender malware . By taking down this site, many thinks Macs are bulletproof again. However, the vanishing of Mac Defender is much more likely the result of cyber criminals being arrested but not disappearance of malware or other infections that target Macs.

Recently, new Trojan was discovered for OS X that can steal sensitive data, like the one was built to look like a PDF file . The fact is that Mac users are targeted more often than they/it used to be and they need to take Even without the threat from cz.cc domains Mac users need to have security software updated for their Mac systems.

More Malware news

Danger! Facebook private messages and Instant Messengers are infected by worm

Danger! Facebook private messages and Instant Messengers are infected by worm

According to TrendLabs, infected messages are spreading on Facebook which contain a malicious link pointing to an archive file “May09-Picture18.JPG_www.facebook.com.zip”. Zipped archive itself has a file titled “May09-Picture18.JPG_www.facebook.com” and uses the extension “.com”. Malware within is able to terminate services and processes related to AV which quickly shuts down AV from detection or removal of the worm. This detected malware is named WORM_STECKCT.EVL. Read more.


News categories

Latest news

Related news