What does the Flashback malware do

malware

There was a question about removing the Flashback malware from your OS X machine, but I'm still not clear on what it does. What exactly does the Flashback malware do once it is installed on your Mac?

Best Answer

From Wikipedia:

The Trojan [FlashBack] targets a Java vulnerability on Mac OS X. The system is infected after the user is redirected to a compromised bogus site, where JavaScript code causes an applet containing an exploit to load. An executable file is saved on the local machine, which is used to download and run malicious code from a remote location. The malware also switches between various servers for optimised load balancing. Each bot is given a unique ID that is sent to the control server.. The trojan, however, will only infect the user visiting the infected web page, meaning other users on the computer are not infected unless their user accounts have been infected separately, this is due to the UNIX security system.

For a lengthier, more technical description, read this F-Secure article.