• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

About those gangs of Russian hackers targeting Macs

By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
September 27, 2009, 9:53 AM ET
MacCodec.com. Source: SophosLabs

“Hey Dimwitt here’s a pcworld article about russian hackers targeting Macs. http://tiny.cc/dL4Yi.”

I assume that message, sent via Twitter by “chalupatime” Saturday afternoon, was directed at me because I wrote something a few weeks ago called “Why are there no Mac viruses?”

My tortilla-loving friend is correct. There is indeed an article by Gregg Keizer in PC World (as well as in Computerworld) about Apple (AAPL) computers being targeted for malware.

Keizer’s source is Graham Cluley, who quotes Paul Ducklin, who in turn offers a pointer to the source of all this chatter: a presentation at last week’s Virus Bulletin conference in Geneva by Dmitry Samosseiko, a Russian-born researcher for Sophos, the U.K.-based security software vendor.

Samosseiko’s paper, “
The Partnerka — what is it, and why should you care?
,” is available for free as a pdf. It’s a fascinating behind-the-scenes look at the hundreds of well-organized affiliate networks — known in Russian as “partnerkas” — that traffic, in Samosseiko’s words, in “fake watches, fake anti-virus software, fake pills and fake love” for commissions that generate thousands of dollars a day for “webmasters” all around the world.

The six-page paper contains exactly one paragraph about the Mac:

“Mac users are not immune to the scareware threat. In fact, there are ‘codec-partnerka’ dedicated to the sale and promotion of fake Mac software. One of the recent examples is Mac-codec.com. At the time of writing this article, the site is no longer available, but just a few months ago it was offering $0.43 for each install and offered various promo materials in the form of MacOS ‘video players’.”

Although there’s nothing in that paragraph about targeting Macs for malware, that’s the idea. Samosseiko’s paper describes a new kind of Web- and social network-based spam he calls Spam 2.0. Using so-called DNS Changer trojans and other programs designed to exploit loopholes in various Web-traffic-directing and search-engine-optimization systems, the partnerkas flood the Internet with come-ons for the Web equivalent of fake gold watches.

In the case of Mac-codec.com, what they were selling was software that promised to help Mac owners run videos created using Microsoft (MSFT) Windows-based protocols.

Although Cluley and Keizer singled out the Mac paragraph as the most newsworthy thing in Samosseiko’s paper, neither bothered to ask the author how many Mac partnerkas he’d come across. Dan Goodin, writing for The Register, did.

“It’s very infrequent,” Samosseiko told Goodin. “We discover new ones extremely rarely compared to Windows platforms.”

Samosseiko also pointed out in that interview that the $0.43 bounty Mac-codec was offering is slightly lower than the $0.50 to $0.55 typically paid for Windows hits. And although the site was operating in January and February, it disappeared soon after.

“I suspect that it wasn’t as profitable to target the Mac platform at that point,” he told Goodin. “[It] probably closed because it wasn’t commercially viable for them to conduct business.”

As we wrote a few weeks ago, Apple’s computers are not immune to malware. But the threat to Mac OS X pales in comparison to that faced by various Windows platforms.

By the way, Samosseiko’s paper provides a handy list of the products that generate the most traffic for the partnerkas. The biggest draws:

  • Online pharmacies selling generic versions of popular drugs.
  • Networks promoting ‘scareware’, a.k.a. ‘rogue anti-virus’ products.
  • Counterfeit luxury products such as fake Rolex watches.
  • Casinos.
  • Adult sites.
  • Dating services.
  • Affiliate traffic generated via IFRAME insertions.

Note No. 2 on that list: “Scareware” — fake anti-virus software offering to protect computer users from threats that might exist only in the victims’ mind.

Thanks, chalupatime, for the warning.

About the Author
By Philip Elmer-DeWitt
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

U.S. President Donald Trump waves to the media after walking off of Air Force One at Miami International Airport on April 11, 2026 in Miami, Florida.
PoliticsIran
Trump says the Iran war is ‘very close to over’—despite no deal, a live blockade, and threats mounting
By Eva RoytburgApril 15, 2026
2 hours ago
Dow COO Karen Carter wearing a white lab coat and sitting while smiling
NewslettersMPW Daily
What to know about Dow’s next CEO, the Fortune 500’s third Black female chief today who started at the $40 billion chemical maker as an intern
By Emma HinchliffeApril 15, 2026
2 hours ago
Boss has lunch with her workers outside
Successcompany culture
A $24 billion Dutch lender is cutting its workforce—and to get the remaining staff on board, the CEO is having sandwiches with them
By Emma BurleighApril 15, 2026
2 hours ago
Sal Khan
SuccessEducation
This CEO has teamed up with Google, Microsoft, and McKinsey to build an AI degree that could rival Harvard—and it will only cost $10,000 to attend
By Preston ForeApril 15, 2026
3 hours ago
Why insurance giant Travelers’ CTO is placing fewer, bigger bets on AI
NewslettersCIO Intelligence
Why insurance giant Travelers’ CTO is placing fewer, bigger bets on AI
By John KellApril 15, 2026
3 hours ago
horowitz
AIdisruption
a16z’s Ben Horowitz sees ‘AI anxiety’ consuming Silicon Valley founders. Workers’ fear of something else is killing adoption
By Nick LichtenbergApril 15, 2026
3 hours ago

Most Popular

Billionaire philanthropist MacKenzie Scott has donated again—a week after gifting millions to a college, she's just given $70 million to Meals on Wheels America
Success
Billionaire philanthropist MacKenzie Scott has donated again—a week after gifting millions to a college, she's just given $70 million to Meals on Wheels America
By Fortune EditorsApril 13, 2026
2 days ago
Retirees are facing a $345,000 bill they never saw coming — and most aren't prepared
Commentary
Retirees are facing a $345,000 bill they never saw coming — and most aren't prepared
By Fortune EditorsApril 14, 2026
1 day ago
Palantir CEO says working at his $316 billion software company is better than a degree from Harvard or Yale: ‘No one cares about the other stuff’
Success
Palantir CEO says working at his $316 billion software company is better than a degree from Harvard or Yale: ‘No one cares about the other stuff’
By Fortune EditorsApril 14, 2026
1 day ago
Anthropic is facing a wave of user backlash over reports of performance issues with its Claude AI chatbot
AI
Anthropic is facing a wave of user backlash over reports of performance issues with its Claude AI chatbot
By Fortune EditorsApril 14, 2026
1 day ago
Warren Buffett’s first tax return showed $7 owed to the IRS. The then paperboy and former Berkshire Hathaway CEO is now worth $143 billion
Success
Warren Buffett’s first tax return showed $7 owed to the IRS. The then paperboy and former Berkshire Hathaway CEO is now worth $143 billion
By Fortune EditorsApril 14, 2026
1 day ago
He was coding at 12 like Elon Musk and became one of Google’s youngest-ever CMOs—but now says Gen Z is better off ice skating than learning to code
Success
He was coding at 12 like Elon Musk and became one of Google’s youngest-ever CMOs—but now says Gen Z is better off ice skating than learning to code
By Fortune EditorsApril 14, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.