All the latest UK technology news, reviews and analysis

Hackers writing zero-day malware to order

by William Eazel

04 Feb 2006

Be the first to comment

  • Tweet this
Exploits for the Windows .wmf vulnerability are being developed for the Russian market
Hackers are tailoring and selling zero-day malware for specific markets

Russian security company Kaspersky Lab has discovered a worrying phenomenon in the wake of Microsoft's security gaffe over the .wmf exploit at the end of last year, claiming that hackers are tailoring and selling zero-day malware for specific markets.

Kaspersky claims that exploits for the .wmf vulnerability that emerged over Christmas were being developed specifically for the Russian market, away from the eyes of security companies.

"Around the middle of December, this exploit could be bought from a number of specialised sites," the company said.

"It seems that two or three competing hacker groups from Russia were selling this exploit for $4,000. One of the purchasers is involved in the criminal adware/spyware business, and it seems likely that this was how the exploit became public."

A watershed was reached at the end of 2005, according to Kaspersky. There were two critical vulnerabilities in Windows, a month apart, which were publicised before a patch was made available. Both vulnerabilities were exploited by malicious programs almost immediately.

In November, a research group known as 'Computer Terrorism' published a proof of concept exploit for the JavaScript processing function 'window()', which would run on a fully patched version of Internet Explorer.

Microsoft had known about the bug, but had not rated it a priority as it had discovered no serious exploit.

However, Computer Terrorism understood the vulnerability better than Microsoft and tweaked the code to install and execute a file on a victim system without the knowledge or consent of the user.

A week later, exploits surfaced on the internet. "This was the first case in which a Trojan exploited a vulnerability in Windows for which no patch existed, " Kaspersky said.

The situation was repeated in late December when the .wmf exploit surfaced. "It was clear that this was the latest zero-day vulnerability, and Microsoft knew nothing about it," said Kaspersky.

"The most worrying thing is that the virus writing community not only detected this vulnerability before Microsoft, but before any other major company specialising in the identification of vulnerabilities."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

29%

1%

12%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

PHP Software Developers/Programmers- Automated Trading - London

PHP Software Developers/Programmers- Automated Trading...

1st Level Application Support - Southampton, Hampshire - £20K

1st Level Application Support required to join a leading...

Helpdesk Adviser; Service desk Analyst; Northeast’s; £Neg on Experienc

Helpdesk adviser required for a major organisation in...

.NET Developer

.NET Developer is needed for a financial services...

To send to more than one email address, simply separate each address with a comma.