ds store wrote:
Right, it does look like it's attacking the Finder, how else can it display red circles in a Finder window?
Or is this just a fake image displayed?
It is just a browser page that fakes a Finder window. It doesn't do that all that well (since among other things it can only guess what is in a user's sidebar) but it is convincing enough if you aren't that familiar with the Mac GUI or aren't paying close enough attention to notice things like the fact that the app shown in the menu bar is the browser & not Finder.
It is a TROJAN !!! It has no way of doing anything unless & until it convinces a user to install it. Without that, the most malicious thing it can do is take up a few MB of HD space.
In terms of the attack vector, it can't "evolve" into anything "more deadlier," with or without any alterations script kiddies add to it. In more general terms, it most certainly can't do exotic stuff like get into keyboard firmware & lurk there ready to reinfect the system because a) there is nowhere near enough room in the keyboard's onboard storage to hold a copy of the code, even if it was highly compressed, b) there is no mechanism by which the OS would retrieve the code & run or install it, & c) it would have to somehow bypass a number of security API's built into the OS even if a) & b) were not true.
It most certainly would not survive a hard drive erase, if that is what you mean by "a hard drive extraction." Files live on hard drives, not in firmware, & the OS is quite picky about how it performs firmware updates for hardware (which for peripherals it identifies early in the startup process from product & vendor ID's that are burned into ROM).
Don't get me wrong. The OS is not bulletproof. It isn't inconceivable that some really clever malware author could find an attack vector that did not require the "help" of users to do malicious things. But that would require far, far more sophisticated methods of attack than any variants of this type of malware (an ordinary trojan) could manage. Saying that the author could evolve this into something that could is like saying that someone who built a good bicycle could evolve it into a rocket ship to take people to the moon.