{"id":4383,"date":"2012-04-05T13:34:37","date_gmt":"2012-04-05T20:34:37","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=4383"},"modified":"2016-02-12T10:16:13","modified_gmt":"2016-02-12T18:16:13","slug":"hundreds-of-thousands-of-macs-infected-by-flashback-malware","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/","title":{"rendered":"Hundreds of Thousands of Macs Infected by Flashback Malware"},"content":{"rendered":"<p>Since the <a href=\"https:\/\/www.intego.com\/mac-security-blog\/new-flashback-variant-takes-advantage-of-unpatched-java-vulnerability\/\">latest variants of the Flashback malware<\/a> have appeared, this malware has been very effective in infecting Macs. Exploiting a Java vulnerability, infections occurred, in many cases, with no user intervention. Russian security company Dr. Web, which analyzed server traffic to the Flashback command and control severs, <a href=\"http:\/\/news.drweb.com\/show\/?i=2341&amp;lng=en\">estimates that more than 500,000 Macs are infected<\/a>.<\/p>\n<p>Apple has since <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-releases-java-update-includes-fix-for-vulnerability-exploited-by-flashback-malware\/\">released a Java update<\/a>, patching the vulnerability that Flashback was using, and <b>it is essential that all Mac users apply this update<\/b>. If you have Java on your Mac &#8211; included with OS X 10.6, and download on OS X 10.7 if you have tried to launch a Java applet &#8211; you will see the update in Software Update. Choose Software Update from the Apple menu on your Mac to check for the update.<\/p>\n<p>Intego&#8217;s Malware Research Team has seen dozens of variants of the Flashback malware in the past week, showing a rarely seen level of activity for Mac malware. As of today, however, all of the servers that were providing the Flashback malware seem to be off-line; this is likely to do the activities of the many security companies that have worked on exposing this malware and the servers it uses. However, the command and control servers are still active, so those Macs that are infected are still vulnerable to data theft and more.<\/p>\n<p>This malware has changed greatly from its first incarnation. Initially a fake Adobe Flash installer (hence the name Flashback), it later changed to <a href=\"https:\/\/www.intego.com\/mac-security-blog\/new-flashback-variant-changes-tack-to-infect-macs\/\">impersonate a Software Update dialog<\/a>, before using <a href=\"https:\/\/www.intego.com\/mac-security-blog\/new-flashback-variant-takes-advantage-of-unpatched-java-vulnerability\/\">Java vulnerabilities<\/a> to install. It is likely that this malware will be back in another guise in the future. But for now, the most important thing users can do is make sure that they update Java &#8211; as well as apply any other security updates that they haven&#8217;t installed yet &#8211; to be protected in case the Flashback servers come back online.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/virusbarrier\/\">Intego VirusBarrier X6<\/a> protects against Flashback and all other Mac malware. The Intego Malware Research Center is ensuring that regular updates to the program&#8217;s threat filters include new malware definitions for the latest variants of the Flashback malware.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Estimates suggest that more than a half-million Macs have been infected by the Flashback malware.<\/p>\n","protected":false},"author":3,"featured_media":8755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[190],"tags":[505,153,75,174,86,119],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Estimates suggest that more than a half-million Macs have been infected by the Flashback malware.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hundreds of Thousands of Macs Infected by Flashback Malware - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Estimates suggest that more than a half-million Macs have been infected by the Flashback malware.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2012-04-05T20:34:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-02-12T18:16:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png\",\"width\":\"400\",\"height\":\"260\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/\",\"name\":\"Hundreds of Thousands of Macs Infected by Flashback Malware - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#primaryimage\"},\"datePublished\":\"2012-04-05T20:34:37+00:00\",\"dateModified\":\"2016-02-12T18:16:13+00:00\",\"description\":\"Estimates suggest that more than a half-million Macs have been infected by the Flashback malware.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hundreds of Thousands of Macs Infected by Flashback Malware\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"Hundreds of Thousands of Macs Infected by Flashback Malware\",\"datePublished\":\"2012-04-05T20:34:37+00:00\",\"dateModified\":\"2016-02-12T18:16:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#webpage\"},\"wordCount\":361,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png\",\"keywords\":[\"Botnet\",\"Flashback\",\"Java\",\"Mac\",\"Malware\",\"Security Update\"],\"articleSection\":[\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Estimates suggest that more than a half-million Macs have been infected by the Flashback malware.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/","og_locale":"en_US","og_type":"article","og_title":"Hundreds of Thousands of Macs Infected by Flashback Malware - The Mac Security Blog","og_description":"Estimates suggest that more than a half-million Macs have been infected by the Flashback malware.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/","og_site_name":"The Mac Security Blog","article_published_time":"2012-04-05T20:34:37+00:00","article_modified_time":"2016-02-12T18:16:13+00:00","og_image":[{"width":"400","height":"260","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","width":"400","height":"260"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/","name":"Hundreds of Thousands of Macs Infected by Flashback Malware - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#primaryimage"},"datePublished":"2012-04-05T20:34:37+00:00","dateModified":"2016-02-12T18:16:13+00:00","description":"Estimates suggest that more than a half-million Macs have been infected by the Flashback malware.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Hundreds of Thousands of Macs Infected by Flashback Malware"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"Hundreds of Thousands of Macs Infected by Flashback Malware","datePublished":"2012-04-05T20:34:37+00:00","dateModified":"2016-02-12T18:16:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#webpage"},"wordCount":361,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","keywords":["Botnet","Flashback","Java","Mac","Malware","Security Update"],"articleSection":["Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/hundreds-of-thousands-of-macs-infected-by-flashback-malware\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-18H","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/4383"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=4383"}],"version-history":[{"count":7,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/4383\/revisions"}],"predecessor-version":[{"id":36871,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/4383\/revisions\/36871"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8755"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=4383"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=4383"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=4383"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}