{"id":512,"date":"2008-11-18T18:11:30","date_gmt":"2008-11-18T17:11:30","guid":{"rendered":"http:\/\/blog.intego.com\/?p=512"},"modified":"2020-02-05T10:49:22","modified_gmt":"2020-02-05T18:49:22","slug":"intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/","title":{"rendered":"New variant of RSPlug Trojan horse &#8211; Intego issues Security Memo"},"content":{"rendered":"<p>A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See <a href=\"https:\/\/web.archive.org\/web\/20081115150805\/http:\/\/www.intego.com\/news\/ism0705.asp\" target=\"_blank\" rel=\"noopener noreferrer\">Intego\u2019s previous Internet Security Memo of October 31, 2007 <\/a> for more on this Trojan horse.) While this new variant currently performs the same actions as the RSPlug.A Trojan horse, its installer is different: it is a downloader, and it contacts a remote server to download the files it installs. This means that, in the future, the downloader may be able to install other payloads than the one it currently installs.<\/p>\n<p>This new variant, like the initial RSPlug.A Trojan horse, has been found on pornographic web sites. When visiting such a site, a user is alerted that there is a \u201cVideo ActiveX Object Error\u201d and is told that their \u201cBrowser cannot play this video file.\u201d The alert instructs the user to download the \u201cmissing Video ActiveX Object\u201d. If the user clicks OK, a disk image called cleanlive.dmg downloads (this name may be different in the future; with the first version of the RSPlug Trojan horse, a number of different names were found). Depending on the user\u2019s browser settings, this disk image may mount and launch automatically commencing installation. If the user clicks Cancel when the Video ActiveX Object alert displays, however, they receive another alert saying, \u201cPlease install new version of Video ActiveX Object.\u201d This alert only allows the user to click OK, returning them to the first alert. The only way to get rid of these alerts is either to download the infected disk image, or quit the browser.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20081121044211\/http:\/\/www.intego.com\/news\/ism0806.asp\" target=\"_blank\" rel=\"noopener noreferrer\">Read the full security memo<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See Intego\u2019s previous Internet Security Memo of October 31, 2007 for more on this Trojan horse.) While this new variant currently performs the same actions as the RSPlug.A Trojan horse, its installer is different: it is a downloader, and [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":8763,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[13],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See Intego\u2019s previous Internet Security Memo of October 31,\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New variant of RSPlug Trojan horse - Intego issues Security Memo - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See Intego\u2019s previous Internet Security Memo of October 31,\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2008-11-18T17:11:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-02-05T18:49:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg\",\"width\":\"400\",\"height\":\"260\",\"caption\":\"Malware Alert from Intego\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/\",\"name\":\"New variant of RSPlug Trojan horse - Intego issues Security Memo - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#primaryimage\"},\"datePublished\":\"2008-11-18T17:11:30+00:00\",\"dateModified\":\"2020-02-05T18:49:22+00:00\",\"description\":\"A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See Intego\\u2019s previous Internet Security Memo of October 31,\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New variant of RSPlug Trojan horse &#8211; Intego issues Security Memo\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"New variant of RSPlug Trojan horse &#8211; Intego issues Security Memo\",\"datePublished\":\"2008-11-18T17:11:30+00:00\",\"dateModified\":\"2020-02-05T18:49:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#webpage\"},\"wordCount\":275,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg\",\"articleSection\":[\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See Intego\u2019s previous Internet Security Memo of October 31,","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/","og_locale":"en_US","og_type":"article","og_title":"New variant of RSPlug Trojan horse - Intego issues Security Memo - The Mac Security Blog","og_description":"A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See Intego\u2019s previous Internet Security Memo of October 31,","og_url":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/","og_site_name":"The Mac Security Blog","article_published_time":"2008-11-18T17:11:30+00:00","article_modified_time":"2020-02-05T18:49:22+00:00","og_image":[{"width":"400","height":"260","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","width":"400","height":"260","caption":"Malware Alert from Intego"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/","name":"New variant of RSPlug Trojan horse - Intego issues Security Memo - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#primaryimage"},"datePublished":"2008-11-18T17:11:30+00:00","dateModified":"2020-02-05T18:49:22+00:00","description":"A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See Intego\u2019s previous Internet Security Memo of October 31,","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"New variant of RSPlug Trojan horse &#8211; Intego issues Security Memo"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"New variant of RSPlug Trojan horse &#8211; Intego issues Security Memo","datePublished":"2008-11-18T17:11:30+00:00","dateModified":"2020-02-05T18:49:22+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#webpage"},"wordCount":275,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/intego-issues-security-memo-about-new-variant-of-rsplug-trojan-horse\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","articleSection":["Security &amp; Privacy"],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-8g","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/512"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=512"}],"version-history":[{"count":2,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/512\/revisions"}],"predecessor-version":[{"id":90983,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/512\/revisions\/90983"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8763"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}