View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
  2. Cybersecurity
October 6, 2014

Hackers convert 17,000 Macs into malware botnet

Reddit's search and comment functions used for the attack.

By CBR Staff Writer

A new botnet in Mac OS X is being exploited by hackers to spread a malware called Mac.BackDoor.iWorm.

The malware has already infected more than 17,000 Macs around the world, reported Russian antivirus company Dr Web.

US users are the most affected with more than 4,610 computers infected, followed by Canada with 1,235 units, and the UK with 1,227 units as of September 26, 2014.

It is not known how the virus spreads, but reports suggest that iWorm uses the search function of Reddit to find comments given by criminals in Minecraft discussion section, to connect to the server addresses listed in the section’s subreddit.

Dr Web said in a statement: "It is worth mentioning that in order to acquire a control server address list, the bot uses the search service at reddit.com, and — as a search query — specifies hexadecimal values of the first 8 bytes of the MD5 hash of the current date.

"The reddit.com search returns a web page containing a list of botnet C&C servers and ports published by criminals in comments to the post minecraftserverlists under the account vtnhiaovyd.

"The bot picks a random server from the first 29 addresses on the list and sends queries to each of them. Search requests to acquire the list are sent to reddit.com in five-minute intervals."

Content from our partners
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline

After connecting, hackers spread spam campaigns, bombard websites with traffic resulting in crash and spread more malware using the botnet of infected computers.

The malware is suspected to have been created using C++ and Lua.

The infected computers are currently not being used for attack, indicating that attackers are growing the network to intensify the scale of the attack.

Security watcher Graham Cluley’s blog cited that Reditt will not be able to stop the attacks by shutting down the accounts that are communicating with the botnets, because it will result in creation of new accounts and alternative services to communicate with the infected devices.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU