{"id":34255,"date":"2014-11-25T11:26:25","date_gmt":"2014-11-25T19:26:25","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=34255"},"modified":"2016-02-12T10:48:10","modified_gmt":"2016-02-12T18:48:10","slug":"mac-users-need-not-worry-about-regin-malware","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/","title":{"rendered":"Mac Users Need Not Worry About Regin Malware"},"content":{"rendered":"<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/backdoor-regin\/\" rel=\"attachment wp-att-34276\"><img loading=\"lazy\" class=\"aligncenter size-full wp-image-34276\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/backdoor.regin_.jpg\" alt=\"Regin Trojan horse malware \" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/backdoor.regin_.jpg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/backdoor.regin_-150x75.jpg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/backdoor.regin_-300x150.jpg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>Security researchers have issued an alert this week upon the discovery of a major backdoor in Windows platforms, a threat currently classified as very low. The threat, called \u201cRegin,\u201d is a Trojan horse that opens a backdoor and steals information from the compromised computer, according to <a title=\"Link to Symantec Report\" href=\"http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2013-121221-3645-99\" target=\"_blank\">Symantec<\/a>.<\/p>\n<p>Systems affected by Regin malware\u2014as detected for now\u2014are: Windows 2000, Windows 7, Windows NT, Windows Vista, and Windows XP.<\/p>\n<p>PCWorld\u2019s Nancy Weil <a title=\"Stealthy, sophisticated 'Regin' malware has been infecting computers since 2008\" href=\"http:\/\/www.pcworld.com\/article\/2851472\/symantec-identifies-sophisticated-stealthy-regin-malware.html\" target=\"_blank\">reported<\/a> that the multistage loading aspect of Regin is comparable to Duqu\/Stuxnet malware, which are related to a surge in <a title=\"Politically Motivated Malware Attacks Increasing Regardless of Operating System\" href=\"https:\/\/www.intego.com\/mac-security-blog\/politically-motivated-malware-attacks-increasing-regardless-of-operating-system\/\" target=\"_blank\">politically motivated malware attacks<\/a>, and that it likely took months\u2014if not years\u2014for its creators to develop.<\/p>\n<blockquote><p>Regin also takes a modular approach, so that custom features of it are specific to its targets\u2014an approach used with other advanced malware families, including Flamer and Weevil. [\u2026] Researchers have identified dozens of payloads, with some specific and advanced payload modules found, including a Microsoft IIS Web server traffic monitor and a traffic sniffer aimed at mobile telephone base-station controllers.<\/p><\/blockquote>\n<p>The long and short of it is, Regin looks like a variant (or maybe the father of) various Windows malware that has cropped up over the years. <span style=\"color: #444444;\">[tweetable hashtag=&#8221;#Regin #Mac&#8221;]<\/span>For Mac users, the most salient takeaway is this: Regin malware is not something we have to worry about.<span style=\"color: #444444;\">[\/tweetable]<\/span><\/p>\n<p>Apple has put more safety measures in place (like requiring kexts to be code signed, and requiring special permissions to code sign kexts, and not allowing code signed kexts to be distributed through the App Store), so the chances of this type of attack affecting the Mac OS X platform decrease with every major operating system release.<\/p>\n<p>Nonetheless, if this threat finds its way on to your Mac, you don\u2019t want to inadvertently forward the malicious file to Windows users. <a title=\"Mac Antivirus and Security - Mac Internet Security X8\" href=\"https:\/\/www.intego.com\/antivirus-internet-security-x8\" target=\"_blank\">Intego VirusBarrier<\/a> with up-to-date virus definitions detects and eradicates this malware as <strong>W32\/Regin<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers have issued an alert this week upon the discovery of a major backdoor in Windows platforms, a threat currently classified as very low. The threat, called \u201cRegin,\u201d is a Trojan horse that opens a backdoor and steals information from the compromised computer, according to Symantec. Systems affected by Regin malware\u2014as detected for now\u2014are: [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":34267,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[190],"tags":[1711,174,86,1708,1714,149],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Security researchers have issued an alert this week upon the discovery of a major backdoor in Windows platforms, a threat currently classified as very\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mac Users Need Not Worry About Regin Malware - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Security researchers have issued an alert this week upon the discovery of a major backdoor in Windows platforms, a threat currently classified as very\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2014-11-25T19:26:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-02-12T18:48:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Derek Erwin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg\",\"width\":400,\"height\":260,\"caption\":\"Regin Windows malware\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/\",\"name\":\"Mac Users Need Not Worry About Regin Malware - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#primaryimage\"},\"datePublished\":\"2014-11-25T19:26:25+00:00\",\"dateModified\":\"2016-02-12T18:48:10+00:00\",\"description\":\"Security researchers have issued an alert this week upon the discovery of a major backdoor in Windows platforms, a threat currently classified as very\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mac Users Need Not Worry About Regin Malware\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d7586ee278e291223dbae05ec1d95812\"},\"headline\":\"Mac Users Need Not Worry About Regin Malware\",\"datePublished\":\"2014-11-25T19:26:25+00:00\",\"dateModified\":\"2016-02-12T18:48:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#webpage\"},\"wordCount\":324,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg\",\"keywords\":[\"Backdoor.Regin\",\"Mac\",\"Malware\",\"Regin\",\"W32\/Regin\",\"Windows\"],\"articleSection\":[\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d7586ee278e291223dbae05ec1d95812\",\"name\":\"Derek Erwin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f88b4bb259f7d5b1d10884ffa4b3c126?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f88b4bb259f7d5b1d10884ffa4b3c126?s=96&d=mm&r=g\",\"caption\":\"Derek Erwin\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Security researchers have issued an alert this week upon the discovery of a major backdoor in Windows platforms, a threat currently classified as very","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/","og_locale":"en_US","og_type":"article","og_title":"Mac Users Need Not Worry About Regin Malware - The Mac Security Blog","og_description":"Security researchers have issued an alert this week upon the discovery of a major backdoor in Windows platforms, a threat currently classified as very","og_url":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/","og_site_name":"The Mac Security Blog","article_published_time":"2014-11-25T19:26:25+00:00","article_modified_time":"2016-02-12T18:48:10+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Derek Erwin","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg","width":400,"height":260,"caption":"Regin Windows malware"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/","name":"Mac Users Need Not Worry About Regin Malware - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#primaryimage"},"datePublished":"2014-11-25T19:26:25+00:00","dateModified":"2016-02-12T18:48:10+00:00","description":"Security researchers have issued an alert this week upon the discovery of a major backdoor in Windows platforms, a threat currently classified as very","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Mac Users Need Not Worry About Regin Malware"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d7586ee278e291223dbae05ec1d95812"},"headline":"Mac Users Need Not Worry About Regin Malware","datePublished":"2014-11-25T19:26:25+00:00","dateModified":"2016-02-12T18:48:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#webpage"},"wordCount":324,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg","keywords":["Backdoor.Regin","Mac","Malware","Regin","W32\/Regin","Windows"],"articleSection":["Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/mac-users-need-not-worry-about-regin-malware\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d7586ee278e291223dbae05ec1d95812","name":"Derek Erwin","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/f88b4bb259f7d5b1d10884ffa4b3c126?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f88b4bb259f7d5b1d10884ffa4b3c126?s=96&d=mm&r=g","caption":"Derek Erwin"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/11\/regin-malware.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-8Uv","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/34255"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=34255"}],"version-history":[{"count":9,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/34255\/revisions"}],"predecessor-version":[{"id":34312,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/34255\/revisions\/34312"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/34267"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=34255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=34255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=34255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}