Latest news

It is being distributed by a downloader Trojan, which is picked up by users when they try to download a video from a bogus Chinese adult site.
The bootkit saves the old master boot record (MBR) to the third sector and replaces it with its own. It also installs an encrypted driver and the rest of the code from the fourth sector onwards.
Once the computer boots, the malicious code executes itself and restores the original MBR in order for Windows to be loaded without revealing the existence of the bootkit.
"Once a specific part of the system has been booted, the bootkit intercepts the function ExVerifySuite. The installed hook replaces the system driver fips.sys with the malicious driver which was written to the start of the hard drive in an encrypted format," explains Kaspersky Lab expert Vyacheslav Zakorzhevsky. "It should be noted that the driver fips.sys is not required for the operating system to run correctly, so the system won’t crash when it is replaced."
This driver detects a number of AV solutions and prevents them from working as they should. Among them are solutions from Trend Micro, BitDefender, AVG, Symantec, Kaspersky Lab, ESET and half a dozen Chinese ones.
Having done that, the driver compromises the explorer.exe process and injects into the machine a variant of the bootkit that is also a downloader. "The malicious program sends a request to the server in which it communicates information about the victim computer’s operating system, IP address, MAC address, etc," says Zakorzhevsky.
Among other things, this variant of the rootkit proceeds to download a keylogger and a Trojan that steals account data for the online game LineAge2.


Spotlight

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Is Microsoft is reading your Skype communications?
Posted on 15 May 2013. | The question of whether Skype allows U.S. intelligence and law enforcement agencies to access the communications exchanged by its users has still not been adequately answered by Microsoft.

Internet Explorer best at blocking malware
Posted on 14 May 2013. | While Chrome’s malware download protection improved significantly, Internet Explorer 10 continues to outperform the other browsers with a block rate of 99.96%.

Researcher refuses to help Saudi telco to spy on people
Posted on 14 May 2013. | You would think that a Saudi Arabian telecom firm interested in monitoring its users' mobile communications would not be asking a well-known pro-privacy researcher for help, but you would be wrong.

Malicious browser extensions are hijacking Facebook accounts
Posted on 13 May 2013. | Facebook users - especially those in Brazil - are being targeted with malicious browser extensions trying to hijack Facebook profiles, warns Microsoft.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





