Latest news
This new variant mimics the behavior of previous ones. After getting downloaded and run by the victims who believe they are about to install legitimate software - in this case VKMusic 4 for Mac - the malware presents to them what seems to be a typical installation wizard.
To activate the software, users are urged to enter their mobile phone number, click on the "Send me an SMS" button, then enter the code they receive via SMS into the appropriate field (click on the screenshot to enlarge it):

"But by performing these actions the user agrees to terms of a chargeable subscription and a fee will be debited from their mobile phone account on a regular basis. Such installers usually contain meaningless data or the programs they are supposed to install, which in fact can be downloaded from official sites of their developers free of charge," Dr. Web researchers explain the scheme, and warn users to be wary of installing programs that require them to enter their phone number or send a text message.
As a side note that will be interesting to other malware researchers, the malicious installer has been created with and is being distributed via ZipMonster, a well-known Russian-language affiliate program.
UPDATE: Apple has added the definitions for the Trojan.SMSSend.3666 to its "Xprotect.plist" blacklist. OS X malware tools are updated daily, so the majority of users is now protected from this Trojan variant.


Spotlight

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





