Posted by: David Harley | April 3, 2013

Krebs on Flashback

Brian Krebs offers some useful research and insight into “Who Wrote the Flashback OS X Worm?“. The F-Secure report he cites in that article, by the way, is this one.

The comparison with Conficker is interesting, but it’s not a perfect fit, even if you measure ‘success’ by the number of machines infected, which seems a slightly old-fashioned way of looking at it. Conficker infections are very much still there, even though the botnet itself is defunct. Apple’s inclusion of known malware detection in OS X, while not perfect, does tend to reduce the attack surface once malware is known. Improvements in the company’s communication with the security/AV industry probably doesn’t do any harm, either.

David Harley

