'Mebroot' rootkit slides further under the security radar, researcher says
New variant appears to use more sophisticated techniques to hide itself than first version did
IDG News Service - Thousands of Web sites have been rigged to deliver an updated version of a rootkit that many data security tools may be unprepared to handle, according to U.K.-based security software vendor Prevx Ltd.
The new malware is a variant of a rootkit known as Mebroot, said Jacques Erasmus, Prevx's director of research. Mebroot first appeared in late 2007 and was given its name by researchers at Symantec Corp. Unlike traditional rootkits that install themselves on systems as drivers, it hides deep inside Windows and can be hard to detect.
Mebroot overwrites the master boot record (MBR) on a PC's hard drive. After the system BIOS does its start-up checks, the MBR is the first code that a computer activates when booting up Windows — a fact that effectively makes it invisible to the operating system as well as security software.
And if the MBR on a system falls under a hacker's control, so does the entire computer and all of the data that's stored on it or transmitted via the Internet, Erasmus said.
Since Mebroot was discovered, security vendors have refined their software to detect it. But Erasmus said that the latest version uses much more sophisticated techniques to stay hidden.
For instance, the updated rootkit inserts program hooks into various functions of the Windows kernel. Once Mebroot has taken hold, the malware then makes it appear that the MBR hasn't been tampered with. "When something is trying to scan the MBR, it displays a perfectly good-looking MBR to any security software," Erasmus said.
Each time the computer is booted, he added, Mebroot injects itself into a Windows process in memory, such as svc.host. That means nothing is written to the hard disk, another evasive technique. The rootkit can then steal information and send it to a remote server via HTTP, according to Erasmus. He said that network analysis tools won't notice the data leaking out since Mebroot hides the traffic.
Prevx spotted the new variant of Mebroot after one of the company's consumer customers became infected. It took security analysts at the firm a few days to nail down exactly how the new variant was managing to embed itself in the operating system. "I think everyone at the moment is working on modifying their [anti-malware] engines to find it," Erasmus said.
And security vendors may need to act fast. Erasmus said it appears that thousands of Web sites have been hacked to deliver Mebroot to vulnerable computers that don't have the proper security patches for their Web browsers.
The infection mechanism is known as a drive-by download. It can be activated when a user visits a legitimate Web site that has been hacked to launch an invisible IFrame loaded with an exploit framework, which begins testing to see if the user's browser contains a certain vulnerability. If so, Mebroot is installed on the system, unbeknownst to the user.
"It's pretty wild out there now," Erasmus said. "Everywhere you go, you have a chance to be infected." It's unknown who created Mebroot, but it appears that one aim of the hackers is to simply infect as many computers as possible, he added.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Reducing the Cost and Complexity of Web Vulnerability Management
- Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.
Download this... - Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All Malware and Vulnerabilities White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Malware and Vulnerabilities Webcasts