Mac botnets don't mean an increased threat (yet)

Two Symantec researchers have reported what they believe is the first evidence of a major botnet consisting of compromised Macs

Writing in the latest issue of Virus Bulletin (registration required), two Symantec researchers report what they believe is the first evidence of a major botnet consisting of compromised Macs.

However other experts aren't so sure of the increased threat to Mac users. Researchers Mario Ballano Barcena and Alfredo Pesoli found that Mac users who downloaded pirated copies of iWork 09 and Adobe Creative Suite 4 from P2P sites got more than the programs they intended. Added to the binaries were two malware variants--OSX.Iservice and OSX.Iservice.B. The malware executes a PHP script, running as root, that launches distributed denial of service (DDoS) attacks against sites.

One site,, reported a DDoS attack of more than 600Gb of Web traffic at its peak, according to the Washington Post.

While Apple has been successful with advertising that Mac users won't suffer the same number of viral attacks that Windows users endure, "unfortunately Macs offer no protection against the manipulation of emotions by malicious users," said Randy Abrams, director of education at ESET, an antivirus vendor.Whether this is the first Mac-based botnet, Abrams said this probably wasn't the first. He told PC World, "usually the first is done by some really smart people and doesn't get discovered."

Abrams noted that Macs today essentially run on Unix and in his blog he describes the parallels of this Mac malware with the first network Unix worm written by Robert Morris, Jr. back in 1988.Other experts agree the media attention around this particular botnet is unwarranted."The story for Mac malware hasn't changed this week contrary to popular opinion," wrote Adam O'Donnell of Cloudmark in a blog post.

That said, O'Donnell and experts who spoke to PCWorld all cited the need for Mac users to be educated on the threat landscape and at least start thinking about antivirus solutions for their desktops. Each stopped short of saying such purchases were absolutely necessary.Based on this one example, as long as a Mac user avoids pirated software on P2P sites, their desktop remains safe. But O'Donnell writes "when we see what happens every day on the PC side happen once on the Mac side, then we all need to run out and buy anti-virus software."

Robert Vamosi is a freelance computer security writer specializing in covering criminal hackers and malware threats.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags botnetsMac

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert Vamosi

PC World (US online)
Show Comments

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers


This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang


It really doesn’t get more “gaming laptop” than this.

Jack Jeffries


As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr


The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?