{"id":3348,"date":"2011-09-28T09:57:01","date_gmt":"2011-09-28T16:57:01","guid":{"rendered":"http:\/\/blog.intego.com\/?p=3348"},"modified":"2016-02-12T10:07:46","modified_gmt":"2016-02-12T18:07:46","slug":"flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/","title":{"rendered":"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers"},"content":{"rendered":"<p>Following our recent <a href=\"https:\/\/www.intego.com\/mac-security-blog\/intego-security-memo-september-26-2011-mac-flashback-trojan-horse-masquerades-as-flash-player-installer-package\/\">security memo about the Mac Flashback Trojan horse<\/a>, Intego has seen an increase in the number of Mac users infected by this malware. After publicizing this threat, many users have posted both in the comments on this blog, and on other blogs and forums about having either seen this malware download, or actually installing it. <\/p>\n<p>If you end up on a site that is serving this malware, you will see something similar to this:<\/p>\n<p><img loading=\"lazy\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web-600x353.png\" alt=\"\" title=\"flashback-web\" width=\"600\" height=\"353\" class=\"aligncenter size-medium wp-image-3349\" \/><br \/>\nThe first things you see are the crashed plugin graphic and the purported error messages. After this, the fake Adobe Flash installer screen pops up, and then the Flashback Trojan horse installation package downloads. At this point, if you have the default Safari settings &#8211; which allow &#8220;safe&#8221; downloads to open automatically &#8211; you will see an Installer window open. <\/p>\n<p>This is effective social engineering. Savvy Mac users will not be fooled, because they know that a Flash installer would never appear in this manner, but two things make this approach believable. First, Flash Player is not installed on Mac OS X Lion, so users will need to install it themselves if they want to view Flash content on the web. Second, if they do have Flash Player installed, and have set the Flash Player preference pane (in System Preferences) to automatically check for updates, they may think that this is an update alert. (We have never had any such alerts, in spite of having checked that setting.) So this can easily fool many Mac users into downloading the malware.<\/p>\n<p>For these reasons, Intego is raising the risk level of this malware to medium.<\/p>\n<p>If you see a web page similar to that shown above, do not run any installer, and if the Installer window does not open, check your Downloads folder for any package file that contains the name Flash, then delete it. Only download Flash Player installers from the <a href=\"http:\/\/www.adobe.com\/products\/flashplayer\/\">Adobe web site<\/a>. <\/p>\n<p>Note: if anyone who has been infected by this Trojan horse knows the URL at which they got it, or has a sample, please send an e-mail (with sample attached, and zipped, if possible) to sample@virusbarrier.com. Thanks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Flashback Trojan horse is spreading, and Mac users should be wary of Flash Player installers not downloaded from Adobe&#8217;s web site.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[190],"tags":[153,86],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"The Flashback Trojan horse is spreading, and Mac users should be wary of Flash Player installers not downloaded from Adobe&#039;s web site.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"The Flashback Trojan horse is spreading, and Mac users should be wary of Flash Player installers not downloaded from Adobe&#039;s web site.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2011-09-28T16:57:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-02-12T18:07:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web-600x353.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web.png\",\"width\":\"909\",\"height\":\"536\",\"caption\":\"The fake Adobe Flash installer screen pops up after the site displayed a crashed plugin graphic and purported error messages.\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/\",\"name\":\"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#primaryimage\"},\"datePublished\":\"2011-09-28T16:57:01+00:00\",\"dateModified\":\"2016-02-12T18:07:46+00:00\",\"description\":\"The Flashback Trojan horse is spreading, and Mac users should be wary of Flash Player installers not downloaded from Adobe's web site.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers\",\"datePublished\":\"2011-09-28T16:57:01+00:00\",\"dateModified\":\"2016-02-12T18:07:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#webpage\"},\"wordCount\":371,\"commentCount\":24,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web-600x353.png\",\"keywords\":[\"Flashback\",\"Malware\"],\"articleSection\":[\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"The Flashback Trojan horse is spreading, and Mac users should be wary of Flash Player installers not downloaded from Adobe's web site.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/","og_locale":"en_US","og_type":"article","og_title":"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers - The Mac Security Blog","og_description":"The Flashback Trojan horse is spreading, and Mac users should be wary of Flash Player installers not downloaded from Adobe's web site.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/","og_site_name":"The Mac Security Blog","article_published_time":"2011-09-28T16:57:01+00:00","article_modified_time":"2016-02-12T18:07:46+00:00","og_image":[{"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web-600x353.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web.png","width":"909","height":"536","caption":"The fake Adobe Flash installer screen pops up after the site displayed a crashed plugin graphic and purported error messages."},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/","name":"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#primaryimage"},"datePublished":"2011-09-28T16:57:01+00:00","dateModified":"2016-02-12T18:07:46+00:00","description":"The Flashback Trojan horse is spreading, and Mac users should be wary of Flash Player installers not downloaded from Adobe's web site.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers","datePublished":"2011-09-28T16:57:01+00:00","dateModified":"2016-02-12T18:07:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#webpage"},"wordCount":371,"commentCount":24,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/09\/flashback-web-600x353.png","keywords":["Flashback","Malware"],"articleSection":["Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/flashback-trojan-spreading-mac-users-should-be-wary-of-flash-installers\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-S0","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/3348"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=3348"}],"version-history":[{"count":1,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/3348\/revisions"}],"predecessor-version":[{"id":50155,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/3348\/revisions\/50155"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=3348"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=3348"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=3348"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}