Mac Defender was a piece of malware that came in with a bang and curiously disappeared just as quickly

Earlier this Summer, a pesky piece of Mac malware called Mac Defender reared its ugly head. WIth SEO tactics in hand, links to Mac Defender appeared high on Google search results and when users clicked through, they were whisked away to a website where javascript began downloading a .zip file.
One of the dangers of Mac Defender is that it, on the surface, appeared to be completely benign by masquerading as a reliable piece of anti-malware software. And while similar programs are easily outed for poor design, Mac Defender was elegant and by all accounts looked to be well thought out and expertly designed Mac software.
Upon being made aware of the malware, Apple issued an OS X security update which was subsequently circumvented in just 8 hours by a new variant of Mac Defender. This resulted in a cat and mouse game where Apple would quickly react to new strains of the malware and Mac Defender would adjust its code accordingly.
But then, all of a sudden, we stopped hearing about Mac Defender and the last time Apple updated its OS X codebase was on June 18.
So what happened?
The long hand of the law, that’s what happened!
Brian Krebs of KrebsonSecurity writes:
On June 23, Russian police arrested Pavel Vrublevsky, the co-founder of Russian online payment giant ChronoPay and a major player in the fake AV market.
In May, I wrote about evidence showing that ChronoPay employees were involved in pushing MacDefender — fake AV software targeting Mac users. ChronoPay later issued a statement denying it had any involvement in the MacDefender scourge.
But last week, Russian cops who raided ChronoPay’s offices in Moscow found otherwise. According to a source who was involved in the raid, police found mountains of evidence that ChronoPay employees were running technical and customer support for a variety of fake AV programs, including MacDefender. The photograph below was taken by police on the scene who discovered Website support credentials and the call records of 1-800 numbers used to operate the support centers.
So the last time Apple updated its malware definitions in OS X was on June 18th and the raid on ChronoPay happened on June 23rd. Since then, it’s been all quiet on the Western (or shall we say Eastern) front.
It’s worth mentioning ChronoPay didn’t just dabble in fake anti virus software. Russian investigators also found evidence linking the company to questionable websites that sold knockoff prescription drugs.
So for the time being, we have a temporary victory over a prominent purveyor of fake anti virus software. But the profitability in selling people software that they don’t need is too alluring to keep folks from trying.
Kreb also relays that many of these bogus antivirus software companies make use of pay per install (PPI) programs whereby they “contract out the deployment of the malware to affiliates who get paid per one thousand installs.”
In other words, a company farms out the malware installation process and then can sit back and relax and let the law of economics do its thing.
If you do the math, it’s almost like you’re printing money,” [Damon] McCoy said. “You could pay the PPI networks $75 to get 1,000 fake AV installs. And if you had an average conversion rate of one in 50, making between $25-$35 on each install, that works out to about 20 sales — or conservatively $500 per one thousand installs. So, you pay someone $75 and you can expect to make four or five times your investment. The economics of this market are ridiculously profitable, and it’s easy to see why fake AV is the go-to method today for monetizing botnets.
With that kind of payoff, you can bet that Mac Defender copycats will sprout up eventually.




