Saturday, 1 March 2014
On
04:04
by
Unknown
No comments
The German computer security and antivirus detection company G Data Security has alleged that the Russian government is behind the newly detected malware known as "Uroburos."
G Data bases its case for Russian government involvement on the complexity of the malware and the presence of Cyrillic words in the malware sample. G Data blog author "MN" points to file names, encryption keys, and behavior of Uroburos as evidence that the Russian government played a role in the creation of the malware.
Another key component, said MN, is that Uroburos looks for a previous piece of malware that's been tied to Russia, but not its government conclusively.
"Uroburos checks for the presence of Agent.BTZ and remains inactive if it is installed," said MN. Agent.BTZ is extremely damaging malware linked to a severe attack against the Pentagon in 2008.
Just yesterday, at the TrustyCon conference for trustworthy technology, Mikko Hypponen, the chief technology officer at security firm F-Secure, said there are few governments actively involved in writing and distributing malware.
"Ten years ago this would've been science fiction," he said. Arguably the most famous example of government-sourced malware is the Stuxnet worm, which targeted a specific kind of software that controls nuclear facilities. The United States and Israel have been implicated in the creation and distribution of Stuxnet.
Uroburos is a rootkit made of two files, "a driver and an encrypted virtual file system," that can "take control of an infected computer, execute arbitrary commands, and hide system activities." The malware is highly dangerous, MN alleges, because its structure is "modular" and "flexible," meaning that new malicious functions can be added to it easily.
"Uroburos' driver part is extremely complex and is designed to be very discrete and very difficult to identify," MN said. In the Uroburos sample discussed by G Data, the malware is designed to steal files and monitor network traffic.
The malware name is a variant spelling for Ouroboros, the ancient Greek symbol of a snake or dragon eating its own tail.
GData says that Uroburos is "one of the most advanced rootkits we have ever analyzed" and pegs its origins to 2011, the earliest year that its driver was compiled. It works on both x86 and x64 Windows computers.
According to G Data, it operates by commanding one infected computer with an Internet connection to infect other networked computers, even those without a direct connection to the Internet. Uroburos gathers whatever data it's been instructed to collect, then surreptitiously sends it back to the malware authors using the same method of hopping from machine to machine until it finds one with an Internet connection.
"This malware behavior is typical for propagation in networks of huge companies or public authorities. The attackers expect that their target does have computers cut off from the Internet and uses this technique as a kind of workaround to achieve their goal," said MN.
Neither G Data nor the Russian consulate in San Francisco returned requests for comment. CNET will update the story when we hear back.
Subscribe to:
Post Comments
(
Atom
)
Search
Popular Posts
-
Hello friends, today we have something special for pc beginners. We have some keyboard shortcut which will really help you to operate any ...
-
Embattled Bitcoin exchange Mt. Gox has resigned from the board of the Bitcoin Foundation, the organization that manages the crypto-curren...
-
Ultra HD, colloquially known as "4K," is the latest buzzword, and the latest push from TV manufacturers. While your next TV mig...
-
BlackBerry CEO John Chen confirmed two new phones were on their way this year. The first, codenamed "Jakarta," but known as the...
-
Amazon is developing its drone service in both Seattle (US) and Cambridge (UK) UK drone experts are being sought by Am...
-
Obidike, the leader of the warriors is sent out in the company of other warriors to fetch seven virgins with which to bury the king. Incid...
-
M icrosoft has patched a critical bug in its software that had existed for 19 years. IBM researchers discovered the flaw, which affect...
-
If BitTorrent has its way, you'll be paying for some torrented content before the end of the year thanks to the integration of BitTo...
-
New photos of Nokia’s upcoming Android handset, code named Normandy, have leaked — and rather oddly, it appears the standard Android UI...
-
Nick Statt/CNET A large part of Hyperlapse's cha...
Recent Posts
Sample Text
Blog Archive
-
▼
2014
(
367
)
-
▼
March
(
75
)
- BlackBerry sales tumble 64% amid weak BB10 adoption
- Amazon launches new way to work in the cloud
- Microsoft 'EMS' biz suite due, for 'bring your own...
- NASA spots Washington mudslide from space
- Box builds out platform with first standalone serv...
- Microsoft's new CEO to host press event on Thursday
- Android app pirates plead guilty to copyright infr...
- Tumblr boosts security with two-factor authentication
- 3 Spritz-like speed-reading apps for Android
- Obama said to announce legislation halting NSA’s p...
- Firefox 28 aims for easier media playback
- iPad with Retina Display makes $399 comeback, knoc...
- Moga iPhone controller makes unique gift
- Facebook makes wrong call on anti-Semitic page
- What are the biggest issues with Wii U, PS4, Xbox ...
- US government begins loosening decades-old grip on...
- Transcend gives Mac Pro a 128GB memory upgrade option
- Mozilla kills Metro version of Firefox, citing low...
- Apple's 'spaceship' campus architect dishes details
- Snowden at SXSW: The NSA set fire to the future of...
- HOW TO ROOT TECNO P3 AND P5 ANDROID PHONES
- Aviate organizes the Android apps you want, when y...
- Use EasyDownloader to save Instagram photos, videos
- Disney Interactive lays off 700 workers, adios soc...
- Microsoft leaks Windows 8.1 update early
- Drones allowed to fly the US skies, for now
- Microsoft plans to patch critical Windows, IE bugs...
- Android 4.4.2 KitKat N900TUVUCNB4 Official Firmwar...
- Beats Music opens up, making its API public
- Gmail on iOS just got a lot faster
- Google Barge arriving in Stockton this morning
- D. Satoshi Nakamoto denies being father of Bitcoin
- Privacy groups ask FTC to block Facebook-WhatsApp ...
- NASA discovers 715 new planets
- How To Get Android 4.2 Emoji Keyboard On Any Device
- Xbox 360 Kinect For Spying? Microsoft Responds To ...
- Cortana Windows Phone: Check Out The Microsoft Per...
- Mobile apps overtake PC Internet usage in U.S.
- Key trends from the world's biggest mobile technol...
- Clinton adviser to lead Microsoft strategy
- Boeing to sell phone that can self-destruct
- Disney deal blazes trail for Dish without the dish
- RadioShack to close 1,100 'underperforming' US stores
- Apple CFO role to change hands in June
- Facebook Paper users can now share stories with an...
- Windows 8.1 update reportedly hits final stage
- US sues Sprint for allegedly overcharging on wiretaps
- Skype rolls out to Outlook.com users worldwide
- Sony PlayStation 4 racks up 6 million sales
- Facebook reportedly in talks for drone maker Titan...
- Android beat Apple in tablet sales last year
- Google, Samsung diss MicroNokia in China -- report
- How to get a no-contract iPhone 5c for $299.99 and...
- Kickstarter pledges surpass $1 billion; half pledg...
- Windows XP starts countdown to end-of-support on A...
- Samsung's new Chromebook to get leather makeover?
- Microsoft to lose execs Bates and Reller, report says
- Apple CarPlay to bring iPhone experience to your n...
- Google Glass updates slow down ahead of KitKat upg...
- Wave your hand to control smart devices -- even if...
- Storm-tracking NOAA satellite system gets a techno...
- Ultra HD 4K TV Cheat Sheet
- Google donates $6.8 million to San Francisco youth...
- California court: Drivers can use smartphone maps,...
- Google Maps Gallery debuts as Web's interactive di...
- Scientists capture first super-res X-rays of livin...
- Daughter's Facebook foghorn blows dad's $80,000
- Security firm claims Russian government makes malware
- Yahoo taps TrustyCon co-founder Alex Stamos for ch...
- Stool sample sausage: Poop probiotics might make m...
- Avoid spam calls, find numbers faster with Current...
- Why Facebook is suddenly smitten with Groups
- Imagination, Apple graphics tech supplier, talks f...
- Colbert turns his funny gun on Snowden in RSA keynote
-
▼
March
(
75
)
Copyright © 2014 Harry Jacks All Rights Reserved. Powered by Blogger.
About Me
Copyright Text
Copyright © 2014 Harry Jacks
All Rights Reserved
All Rights Reserved
0 comments :
Post a Comment