Researchers from F-Secure, Webroot, and Avast have uncovered Janicab.A, a new trojan that was discovered as a threat to Macs last week and Windows users on Monday, with findings being published recently.

For OS X users, Janicab.A was signed with a valid Apple Developer ID and also uses a special unicode character known as a "right-to-left override" (RLO) that is used in email malware attacks. From there, the trojan uses a YouTube page to hijack infected computers, directs them to command-and-control (C&C) servers, and then leaves the server and hides the infection by making the malware appear as a harmless PDF or DOC file.

janicab_2a_malware
Webroot writes:

After a relatively long lag period without seeing any particular new and exciting Mac malware, last week we saw the surfacing of a new and interesting method of compromising the OSX system. Malware authors have taken a new approach by altering file extensions of malicious .app packages in order to trick users into thinking they are opening relatively harmless .pdf or .doc files. Changing file extensions in Mac OSX can be tricky due to a built in security feature of the OS that detects attempts to change the extension and automatically annexes the extension of its correct file or package type.

This news comes after Apple updated security definitions to combat 'Yontoo', an adware trojan this past March, while also regularly dealing with Java-related vulnerabilities. Apple introduced Gatekeeper in OS X Mountain Lion in order to better deal with security threats, offering a way for users to restrict installation of apps to those signed by Apple-issued Developer IDs.

Top Rated Comments

whooleytoo Avatar
151 months ago
Cross-platform malware? And the Mac version was released first? Yaaaay!
Score: 20 Votes (Like | Disagree)
blackcrayon Avatar
151 months ago
If it's signed with a valid developer ID shouldn't that mean Apple should've already revoked it? Which brings up a question, if Apple revokes a developer ID because of malware, does OS X notify you that was the reason? Or do they just say it's "invalid" (in which case lots of people will still right click and open it :)

(I'm guessing the File Quarantine feature should have this added as well by now)
Score: 12 Votes (Like | Disagree)
Michael Scrip Avatar
151 months ago


But what does it actually do? :confused:

It gets an article on MacRumors

:D
Score: 10 Votes (Like | Disagree)
jeznav Avatar
151 months ago
Not all OSX users have Adobe Acrobat Reader installed. Icon FAIL.

Should've used Preview.app PDF icon instead.
Score: 8 Votes (Like | Disagree)
Parasprite Avatar
151 months ago
Malware authors have taken a new approach by altering file extensions of malicious .app packages in order to trick users into thinking they are opening relatively harmless .pdf or .doc files.

New because of the .app part maybe, but .pdf.exe is not a new approach by any means.

Also, who here uses Adobe for PDFs? (beyond filling out that one form that didn't work right in Preview for some reason)
Score: 3 Votes (Like | Disagree)
antonis Avatar
151 months ago
Still, don't get surprised if people that don't even have the adobe reader installed on their mac will still open a "pdf" that is using the acrobat icon. There are users and users.
Score: 2 Votes (Like | Disagree)

Popular Stories

ios 18 4 carplay

iOS 18.4 Includes a Small But Useful Change for CarPlay

Sunday February 23, 2025 2:23 pm PST by
The first beta of iOS 18.4 is now available, and it includes a small but useful change for CarPlay. As we noted in our list of iOS 18.4 features, CarPlay now shows a third row of icons, up from two rows previously. However, this change is only visible in vehicles with a larger center display. For example, a MacRumors Forums member noticed the change in a Toyota Tundra, which can be equipped...
apple watch ultra snow

6 Features Coming to the Apple Watch Ultra 3

Tuesday February 25, 2025 9:00 am PST by
The Apple Watch Ultra 3 is expected to launch later this year, arriving two years after the previous model with a series of improvements. While no noticeable design changes are expected for the third generation since the company tends to stick with the same Apple Watch design through three generations before changing it, there are a series of internal upgrades on the way. By the time the ...
airtag orange

AirTag 2 Rumored to Launch in May or June With These New Features

Monday February 24, 2025 6:11 am PST by
Apple plans to launch a second-generation AirTag in May or June this year, according to a post today from a leaker known as Kosutami. Bloomberg's Mark Gurman previously reported that a new AirTag would be released in mid-2025. May or June would align with that timeframe. Below, we recap three new features rumored for the AirTag 2: With a second-generation Ultra Wideband chip, the...
iphone 17 lineup cad render majin bu

Revealed: Entire iPhone 17 Lineup's Striking New Camera Designs

Monday February 24, 2025 2:49 am PST by
A new CAD render of all the devices in Apple's upcoming iPhone 17 lineup has been shared online by leaker Majin Bu, specifically showing the allegedly different rear camera system designs of the standard iPhone 17, all-new ultra-thin iPhone 17 Air, and the iPhone 17 Pro and Pro Max models. The leaker Majin Bu has had some hits in the past, but some of his information has been wrong,...
iPhone Fold Vertical Feature

Apple's 2026 Foldable iPhone Has No Visible Display Crease – Report

Tuesday February 25, 2025 2:58 am PST by
Apple is making significant headway on its long-rumored foldable iPhone, with a new report suggesting the company has achieved a major breakthrough by effectively eliminating the screen crease that plagues current foldable devices. According to Korean publication ETNews, Apple is finalizing its component suppliers for the foldable iPhone, with the selection process expected to be completed...
trump iphone dictation issue

Apple Fixing 'Trump' Dictation Processing Bug

Tuesday February 25, 2025 1:18 pm PST by
Multiple iPhone owners today noticed a pronunciation processing issue that causes the word "Trump" to momentarily show up when using dictation to send a message with the word "racist." In some cases, when speaking the word racist through the iPhone's built-in dictation feature, the iPhone briefly interprets the spoken word as "Trump" and "Trump" text shows up in the Messages app before being ...
prioritize notifications ios 18 4

Everything New in iOS 18.4 Beta 1

Friday February 21, 2025 1:08 pm PST by
Apple finally released the first beta of iOS 18.4 to developers for testing purposes, and while the beta is lacking some of the Apple Intelligence features we were hoping for, there are some notable new additions. Subscribe to the MacRumors YouTube channel for more videos. Priority Notifications - Apple Intelligence There is a new Priority Notifications feature that can show you your most...
airpods pro purple

Here's When AirPods Pro 3 Are Rumored to Launch

Monday February 24, 2025 9:14 am PST by
According to a post on X today from a leaker known as Kosutami, Apple plans to launch AirPods Pro 3 in May or June this year. The leaker also claimed that an AirTag 2 will launch around the same time. Kosutami is best known as a collector of prototype Apple hardware, but they have occasionally shared accurate information about Apple's future product plans. For example, they accurately...