Mac Trojan poses as PDF
Multiple security companies are warning that they have received samples of a new Mac Trojan. It seems that the Trojan has yet to be seen in the wild.
Dubbed Revir.A, the Trojan poses as a PDF file. Masking an executable as a document is a well-known trick.
When run, Revir.A does display a PDF. According to Sophos, the Chinese-language document is about the Diaoyu/Senkaku Islands, which are the subject of a territorial dispute between China and Japan. Revir.A also downloads a backdoor (Imuler.A) which Intego says can take screenshots and send them to a remote server, as well as performing other unspecified actions. F-Secure reports that while the command and control server is online, it is not yet capable of communicating with the backdoor.