OSX/Flashback.K exploits a known weakness in Java SE6. Trojan is capable of installing itself onto a host system without the need for an admin password. Once infected the malware hijacks the Safari browser every time it launches and redirects the user to a targeted website. The only time that Flashback.k aborts its infection is when it encounters paths for MS Word, MS Office 2008, or Skype. The exploit was patched in February for Windows systems, however Apple has yet to release a patch.”]
Source: https://gizmodo.com/new-flashback-trojan-variant-doesnt-need-a-password-to-5898516

