Ars Technica has info on a new Mac trojan horse:
The latest version of this trojan, dubbed OSX_JAHLAV.D by Trend Micro, comes from a number of websites like comandtryx.com, simplexdoom.com, and sinisteer.com—all which originate from a server with the IP address 91.214.45.73. When clicking to play the videos on these sites, you’ll be prompted to install a QuickTime update or plug-in. If you agree, a file called QuickTimeUpdate.dmg will be downloaded.
Here’s a hint: do not install this. If for some reason you fall prey to this scheme, a number of scripts are installed which allows a remote hacker to monitor your online activities and possibly key presses. It also redirects DNS requests, sending you to phishing sites and other unsavory areas of the Internet. And, notes Trend Micro researcher Feike Hacquebor, the scripts have been set up in such a way that if the IP addresses used by the hackers are shut down, they can quickly direct them to another one with ease.
The Mac is still the safest platform out there. Don’t be stupid. If you’re installing an update or system software, be sure it’s from Apple. Staying safe really is that simple.