Mac OS X OSX/Flashback Trojan Detection

Critical Nessus Plugin ID 58619


The remote Mac OS X host appears to have been compromised.


Using the supplied credentials, Nessus has found evidence that the remote Mac OS X host has been compromised by a trojan in the OSX/Flashback family of trojans.

The software is typically installed by means of a malicious Java applet or Flash Player installer. Depending on the variant, the trojan may disable antivirus, inject a binary into every application launched by the user, or modifies the contents of certain web pages based on configuration information retrieved from a remote server.


Restore the system from a known set of good backups.

See Also

Plugin Details

Severity: Critical

ID: 58619

File Name: macosx_flashback_i_trojan.nasl

Version: 1.4

Type: local

Agent: macosx

Published: 2012/04/06

Modified: 2017/05/30

Dependencies: 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version