Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

'Mebroot' rootkit slides further under the security radar, researcher says

New variant appears to use more sophisticated techniques to hide itself than first version did

April 15, 2009 12:00 PM ET

Active Comments
Anonymous says: was this for, again? Oh, never mind. Microsoft tax. Microsoft tax. Microsoft tax. Microsoft tax. Microsoft tax. Microsoft tax. Microsoft...
Maggie says: Does anyone know if this would also affect a dual-boot Debian/XP system using Grub a the boot loader? If so,...


IDG News Service - Thousands of Web sites have been rigged to deliver an updated version of a rootkit that many data security tools may be unprepared to handle, according to U.K.-based security software vendor Prevx Ltd.

The new malware is a variant of a rootkit known as Mebroot, said Jacques Erasmus, Prevx's director of research. Mebroot first appeared in late 2007 and was given its name by researchers at Symantec Corp. Unlike traditional rootkits that install themselves on systems as drivers, it hides deep inside Windows and can be hard to detect.

Mebroot overwrites the master boot record (MBR) on a PC's hard drive. After the system BIOS does its start-up checks, the MBR is the first code that a computer activates when booting up Windows — a fact that effectively makes it invisible to the operating system as well as security software.

And if the MBR on a system falls under a hacker's control, so does the entire computer and all of the data that's stored on it or transmitted via the Internet, Erasmus said.

Since Mebroot was discovered, security vendors have refined their software to detect it. But Erasmus said that the latest version uses much more sophisticated techniques to stay hidden.

For instance, the updated rootkit inserts program hooks into various functions of the Windows kernel. Once Mebroot has taken hold, the malware then makes it appear that the MBR hasn't been tampered with. "When something is trying to scan the MBR, it displays a perfectly good-looking MBR to any security software," Erasmus said.

Each time the computer is booted, he added, Mebroot injects itself into a Windows process in memory, such as svc.host. That means nothing is written to the hard disk, another evasive technique. The rootkit can then steal information and send it to a remote server via HTTP, according to Erasmus. He said that network analysis tools won't notice the data leaking out since Mebroot hides the traffic.

Prevx spotted the new variant of Mebroot after one of the company's consumer customers became infected. It took security analysts at the firm a few days to nail down exactly how the new variant was managing to embed itself in the operating system. "I think everyone at the moment is working on modifying their [anti-malware] engines to find it," Erasmus said.

And security vendors may need to act fast. Erasmus said it appears that thousands of Web sites have been hacked to deliver Mebroot to vulnerable computers that don't have the proper security patches for their Web browsers.

The infection mechanism is known as a drive-by download. It can be activated when a user visits a legitimate Web site that has been hacked to launch an invisible IFrame loaded with an exploit framework, which begins testing to see if the user's browser contains a certain vulnerability. If so, Mebroot is installed on the system, unbeknownst to the user.

"It's pretty wild out there now," Erasmus said. "Everywhere you go, you have a chance to be infected." It's unknown who created Mebroot, but it appears that one aim of the hackers is to simply infect as many computers as possible, he added.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Mebroot

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.  

Employee Web Use and Misuse
Download this new White Paper today!  

The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.

Get More from Your IT Budget
Download this new white paper today!  

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!


IT Jobs