As noted by The Register and other places, there's a new cross-platform vulnerability out that installs via a piece of Java that does a check for "Windows or Mac" and then installs the malware suitable for the platform.

The Mac malware it installs, called either OSX/Morcut or OSX/Crisis - depending on the AV researcher - is most easily detected and blocked by seeing where it tries to go. Intego reports that it calls home every 5 minutes to a single IP address ( to get instructions and upload anything it may have found.

ThreatSTOP has added this IP address to our feeds and so all ThreatSTOP customers are protected from this malware.

