Five of the Dirtiest Malware Tricks
Thursday, September 27, 2007; 12:19 AM
If the crooks behind viruses, Trojan horses, and other malicious software were as stupid as they are scummy, we'd have a lot less to worry about. But as protective measures get better at stopping the obvious attacks, online creeps respond with underhanded moves to invade your PC. Here are five of their dirtiest tricks, all based on Trojan horses.
Don't mind me--I'm only here to break your PC: It's like sending in a different scout each time to open the gate for the rest of the invaders. The "Glieder Trojan" and many others use a multistage infection process whose first step is a tiny program that the crooks can change constantly so your antivirus watchdog is less likely to recognize it. Once it gets in, the downloader tries to disable your security before pulling down the real payload, which could be a data stealer or anything else the attacker wants.
Locked and encrypted Web sites? No problem: Web sites can and should use secure socket layer (SSL) to encrypt and protect sensitive data such as bank account log-ins. (When a lock icon appears in the address bar, that indicates the site is using SSL.) But the "Gozi Trojan" and its ilk evade SSL protections by making Windows think they're part of the process, so your data leaves IE and goes through Gozi before it's encrypted and sent out on the network. Instead of spying on your keyboard, which many security programs watch for, these apps roll into the OS as fake layered-service providers (LSPs).
The SpamThru, SpyAgent, and Jowspry Threats
Malware that scans your PC for malware: An extra antivirus scan can only be a good thing, right? Not when it just gets rid of rivals to the "SpamThru Trojan." This nasty introduced a pirated, pared-down version of Kaspersky AntiVirus (which Kaspersky has since shut down) to delete other malware so it could have the victim PC to itself to use as a spam sender. If the PC had a real antivirus app, SpamThru would attempt to block its updates, preventing it from identifying new threats.
Equal-opportunity encryption: Encrypting sensitive data and protecting it with a password helps shield it from prying eyes. But the "SpyAgent Trojan" enters the encryption game, too. When installed on a Windows PC with the Encrypting File System (which is included in Windows 2000, XP Pro, 2003 Server, and 2005 Media Center), SpyAgent establishes its own administrator-level user account and uses this account to encrypt its files. You--or your antivirus software--would have to guess the account's random password to decrypt and scan the malicious files to confirm they weren't supposed to be there.
Hi, firewall. I'm Windows Update. Honest: Firewalls protect computers and networks from bad guys' efforts to go in or out. So the "Jowspry Trojan" masquerades as something known and approved--Windows Update. The crafty malware makes its connections look like the Background Intelligent Transfer Service used by Windows Update, and unsuspecting firewalls let it download more attack programs to your PC.
To pull off these sneaky ploys, malware first has to get on your PC. If you keep Windows and other programs up-to-date, avoid opening attachments or clicking links in unsolicited e-mail, and use a good antivirus program, you won't give the crooks a chance to put their Trojan horses to work.
Descriptions based on research and analysis from Peter Gutmann at the University of Auckland, Craig Schmugar and Aditya Kapoor at McAfee's Avert Labs, and Joe Stewart at SecureWorks.
For an inside look at the way Internet attackers buy and sell their insidious tools, read "An Inside Look at Internet Attackers' Black Markets." To ensure that you've closed critical software holes, read "Close the Holes Targeted by the MPack Attack Kit."