Showing posts with label Trojan horse. Show all posts
Showing posts with label Trojan horse. Show all posts

Friday, January 23, 2009

iWork 2009 Trojan building a botnet

This week security researchers reported that pirated copies of iWork 2009 may contain a Trojan horse. Experts note that with Mac OS X threats, you have to be fooled into installing them. In this case, the chance to own iWork 2009 on the cheap is the potential draw. Most antivirus programs for the Mac are capable of stopping this threat.

But hasn't been widely reported is what happens after a machine is infected.

Jose Nazario of Arbor Networks today posted an interesting blog on the iWork Trojan. He found that it's creating a botnet (of course).

Earlier this week I speculated that the Downadup/Conficker worm might be doing the same.

Nazario says, like other botnets, it keeps trying until it connects to the command and control server. "It also grabs a list of seed P2P peers from the file itself by decrypting the running file (thwarting static analysis) and managing the known peers as you would expect. It generates a port to listen on as needed (although it’s not quite clear to me how it would handle being behind a NAT device)…. What’s more is that there is an embedded Lua interpreter, giving a very sophisticated command language some additional structure."

What is this new botnet been up to? So far, Nazario reports it has been creating distributed denial of service (DDoS) attacks.

Wednesday, December 17, 2008

Emergency IE patch due today

On Wednesday, Microsoft will issue an emergency, out-of-cycle security bulletin for a critical flaw affecting all versions of Internet Explorer.


The bulletin is in response to a growing threat. Since the first week in December, the AZN Trojan has been exploiting a known flaw in IE. Visitors to infected Web sites could become infected with a Trojan horse that can download malware onto a user's system.


Microsoft normally issues patches on the second Tuesday of each month, "Patch Tuesday." But out-of-cycle patches are not without precedent. Recent examples include the flaw in how Windows handles remote procedure calls (RPC) in October,the Windows Animated Cursor Remote Code Execution Vulnerability in April 2007, a vulnerability in Vector Markup Language in September 2006, and a vulnerability in the Graphics Rendering Engine in January 2006.


The patch will be automatically distributed to Windows users with Automatic Updates enabled. The patch is also available via Microsoft Update or the individual bulletin for MS08-078 (available after 11 a.m.Pacific Wednesday).