RSPlug


title: "RSPlug" type: doc version: 1 created: 2026-02-28 author: "Wikipedia contributors" status: active scope: public tags: ["trojan-horses", "macos-malware"] topic_path: "technology/operating-systems" source: "https://en.wikipedia.org/wiki/RSPlug" license: "CC BY-SA 4.0" wikipedia_page_id: 0 wikipedia_revision_id: 0

::data[format=table title="Infobox computer virus"]

FieldValue
technical_nameOSX.RSPlug Trojan
familyDNSChanger
typeTrojan horse
isolation_dateNovember 9, 2011
::

| technical_name = OSX.RSPlug Trojan | alias =

Variants

Several variants of the RSPlug trojan were found primarily on pornographic sites disguised as video codecs, and some variants were spotted on sites offering game downloads. When OSX.RSPlug.A was installed, the system's DNS settings were changed to redirect web browsing to phishing web sites, or to web pages displaying ads for other pornographic web sites.

There is also a version of the OSX.RSPlug Trojan which targets the Windows platform, and it was this version that led a technical manager at F-Secure to suggest that the group behind the DNS-changing Mac Trojan is the same group behind the Zlob trojan. However, Intego noted that those behind the RSPlug Trojan horse stopped their activities before those controlling Windows malware, and that it is likely that these were not the same people.

Isolation

As part of Operation Ghost Click, in November 2009 the FBI brought down "a sophisticated Internet fraud ring that infected millions of computers worldwide with a virus and enabled the thieves to manipulate the multi-billion-dollar Internet advertising industry." The FBI estimated that more than four million computers in over 100 countries were infected by DNSChanger. One variant of DNSChanger was the RSPlug Trojan horse, which spawned a number of other variants and infected many Macs.

References

References

  1. "Mac OS malware targets porn surfers". CNET.
  2. (2007-10-31). "INTEGO SECURITY ALERT - October 31, 2007". Intego.
  3. "Multiplying Mac Trojan not epidemic yet". CNET.
  4. (2011-11-10). "FBI Shuts Down DNSChanger Ring". The Mac Security Blog.

::callout[type=info title="Wikipedia Source"] This article was imported from Wikipedia and is available under the Creative Commons Attribution-ShareAlike 4.0 License. Content has been adapted to SurfDoc format. Original contributors can be found on the article history page. ::

trojan-horsesmacos-malware