Apple has been slow to respond, as always, to the Mac.BackDoor.iWorm threat uncovered by Dr. Web last week, which reported that there were more than 17,000 unique IP addresses from Mac computers infected with the malware.
Dr. Web revealed in an extensive analysis that “When Mac.BackDoor.iWorm is activated, it stores its configuration data in a separate file and attempts to read the contents of the /Library directory to determine which of the installed applications will not interact with the malware.”
The security firm explained how the malware works, stating: “If no unwanted directories can be found, the bot uses system queries to determine the Mac OS X account’s Home directory, checks for the availability of its configuration file in the directory, and writes the necessary data to continue operating to the file.”
Finally, the virus opens a port, connects to remote servers, and awaits instructions from its creators. Apple sends a security update, a small packet of information in code that adapts Xprotect against malware.
It's worth noting that the malware is unrelated to the Bash UNIX flaw, which was also reported last week. This is a downloadable update for Mac that users will need to install.
Some researchers claim that Apple could do more to protect users, as the OS X Bash Update doesn't fully protect users from hacking. However, there have been no reported cases of data loss due to this vulnerability.

