A new Trojan Horse is currently hidden in pirated copies of Apple’s iWork ’09 available via various BitTorrent tracker sites, according to a marketing pitch, uh, report from security software manufacturer Intego.
While the pirated software is complete and functional, the installer contains a “bonus” called iWorkServices.pkg. This software is installed as a startup item where it has read-write-execute permissions for root: in other words, it has all the powers of a system administrator. This malicious software connects to a remote server over the internet, alerts its maker that it has been installed and gives this person the ability to connect to the affected Mac remotely.
Given this alert came from Intego, it is no surprise their software, VirusBarrier X4 and X5, protects you against this Trojan horse as long as your virus definitions are dated January 22, 2009 or later.
Meanwhile, SecureMac, has made a free and handy iWorkServices Trojan Removal Tool that does what its name says it will do.
Of course the very best defense of all against this kind of evilware is to get copies of your software legitimately.