Flashback trojan reportedly controls half a million Macs and counting
Variations of the Flashback trojan have reportedly infected more than half a million Macs around the globe, according to Russian antivirus company Dr. Web. The company made an announcement on Wednesday …
Context & Ripple Effects
The Flashback story has been building for more than a year: Sophos flagged an OS X backdoor Trojan in beta back in February 2011, and on Monday Ars Technica detailed how current variants exploit an unpatched Java vulnerability to install with no password prompt. What changes today is scale — Russian antivirus firm Dr. Web's estimate of more than half a million infected machines worldwide, a figure that remains the company's own report rather than independently confirmed.
The breadth of same-day pickup is itself notable: BBC, the Telegraph, Forbes, Computerworld, The Register and MacRumors all carried the Dr. Web numbers, pushing Mac malware out of the security-trade press and into general news for what appears to be the first time at this scale.
First-order effects
- Mac users running unpatched Java face drive-by infection with no password prompt, meaning the usual user-consent defense against OS X malware does not apply.
- Dr. Web's half-million-machine estimate turns Flashback from a curiosity into one of the largest reported botnets on any platform, forcing Apple to treat OS X malware as a volume problem rather than isolated incidents.
Second-order effects
- Antivirus vendors gain their strongest market argument in years for selling OS X protection, directly challenging Apple's long-standing position that built-in defenses suffice.
- Enterprise IT departments weighing Mac deployments must now account for endpoint-security tooling and patch cadence on OS X, costs previously assumed away.
Third-order effects
- If botnet-scale infections on the Mac persist, security expectations converge across platforms — 'Macs don't get viruses' stops functioning as a purchasing rationale, and Apple comes under pressure to match Windows-style rapid patching and cleanup tooling.
The trend: Malware development is following market share: as Mac installed bases grow large enough to monetize, OS X is being pulled into the same industrialized botnet economy as Windows.