Skip the navigation
News

'Mebroot' rootkit slides further under the security radar, researcher says

New variant appears to use more sophisticated techniques to hide itself than first version did

By Jeremy Kirk
April 15, 2009 12:00 PM ET

IDG News Service - Thousands of Web sites have been rigged to deliver an updated version of a rootkit that many data security tools may be unprepared to handle, according to U.K.-based security software vendor Prevx Ltd.

The new malware is a variant of a rootkit known as Mebroot, said Jacques Erasmus, Prevx's director of research. Mebroot first appeared in late 2007 and was given its name by researchers at Symantec Corp. Unlike traditional rootkits that install themselves on systems as drivers, it hides deep inside Windows and can be hard to detect.

Mebroot overwrites the master boot record (MBR) on a PC's hard drive. After the system BIOS does its start-up checks, the MBR is the first code that a computer activates when booting up Windows — a fact that effectively makes it invisible to the operating system as well as security software.

And if the MBR on a system falls under a hacker's control, so does the entire computer and all of the data that's stored on it or transmitted via the Internet, Erasmus said.

Since Mebroot was discovered, security vendors have refined their software to detect it. But Erasmus said that the latest version uses much more sophisticated techniques to stay hidden.

For instance, the updated rootkit inserts program hooks into various functions of the Windows kernel. Once Mebroot has taken hold, the malware then makes it appear that the MBR hasn't been tampered with. "When something is trying to scan the MBR, it displays a perfectly good-looking MBR to any security software," Erasmus said.

Each time the computer is booted, he added, Mebroot injects itself into a Windows process in memory, such as svc.host. That means nothing is written to the hard disk, another evasive technique. The rootkit can then steal information and send it to a remote server via HTTP, according to Erasmus. He said that network analysis tools won't notice the data leaking out since Mebroot hides the traffic.

Prevx spotted the new variant of Mebroot after one of the company's consumer customers became infected. It took security analysts at the firm a few days to nail down exactly how the new variant was managing to embed itself in the operating system. "I think everyone at the moment is working on modifying their [anti-malware] engines to find it," Erasmus said.

And security vendors may need to act fast. Erasmus said it appears that thousands of Web sites have been hacked to deliver Mebroot to vulnerable computers that don't have the proper security patches for their Web browsers.

The infection mechanism is known as a drive-by download. It can be activated when a user visits a legitimate Web site that has been hacked to launch an invisible IFrame loaded with an exploit framework, which begins testing to see if the user's browser contains a certain vulnerability. If so, Mebroot is installed on the system, unbeknownst to the user.

"It's pretty wild out there now," Erasmus said. "Everywhere you go, you have a chance to be infected." It's unknown who created Mebroot, but it appears that one aim of the hackers is to simply infect as many computers as possible, he added.

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Malware and Vulnerabilities White Papers
Reducing the Cost and Complexity of Web Vulnerability Management
Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.

Download this...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Malware and Vulnerabilities White Papers
Malware and Vulnerabilities Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Malware and Vulnerabilities Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs