The Achaean Bulletins and FAQs
Q: I've heard that Indigo (the company that "discovered" the first MP3 trojan) made everything up and there aren't any real media trojans. Is that true?
A: The particular MP3 trojan Indigo refers to is a harmless proof-of-concept created by a third-party. Malicious trojans based on the same concept are technologically possible, however none have yet to be found "in the wide". This is likely because the area of the media file where the arbitrary code is stored (the "resource fork") is stripped from the file whenever it is copied to a non-Macintosh computer, making it very hard for such a trojan or virus to actually spread in the wild. For more information see this article at John Gruber's blog.