Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Whoa, it aborts infection if you have XCode installed?

Is this just to prevent itself from infecting someone's computer that might be able to study it?



According to some malware researchers I've talked to it is not unusual to find that kind of hardcoded exceptions. I thought that it was to avoid infecting "clever" users, but they told me sometimes malware coders bundle those to avoid infecting their own computers (or their clients') without being to obvious about it. It's apparently not unusual to also find exceptions for IP blocks of whole countries or ISPs.


That would be my guess. Perhaps it wanted to stay un-detected, and un-reverse engineered as long as possible? It just played the numbers game in terms of time until discovery, and gave Xcode users some respect? Hence deleting itself in the presence of anti-virus software as well?


It just played the numbers game in terms of time until discovery, and gave Xcode users some respect?

I guess false negative was ok in this case. ;)


Haha, yeah, I wrote the sentence as it appeared in my head, realized it was incomplete and would make no sense to anyone, then just kinda slid the rest in....


I read that it also aborts and removes itself if Little Snitch is installed.

I take requests from LS pretty seriously so it makes sense that they would do it. I would google the process and port if a random request occured.


That is really clever.


I personally have XCode installed at /Applications/Xcode.app/Contents/MacOS/Xcode, so I ran the command at https://www.f-secure.com/v-descs/trojan-downloader_osx_flash...

I got the "does not exist" result anyway, despite not having any of the software listed installed except for Java.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: