This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Researchers warn of image-stealing malware

by Shaun Nichols

07 Nov 2012

View Comments

  • Tweet this
malware virus security threat

Researchers are warning users following the discovery of a malware infection designed to collect and upload image files to a remote server.

The malware, dubbed PixSteal-A by Sophos researchers, infects Windows PCs and then runs a search for all jpeg and dmp file types. The infected systems then establish a connection to a remote server via FTP and then upload the collected files.

While researchers report that the collection server is hosted in Iraq, the location of the individual controlling the operation is unknown and could be anywhere on the globe.

The aim of the operation is currently unknown and researchers are not yet sure how the attacker plans to use the pilfered images.

Chester Wisniewski, a senior security adviser at Sophos had a simple recommendation to users and administrators looking to prevent their image files from being compromised by the malware: simply disable FTP connections at the firewall level.

Wisniewski noted that because FTP does not use encryption measures when transmitting data, the protocol is outdated and leaves users at risk for attacks such as password and credential theft.

"While that might seem extreme, I suggest to you that you shouldn't allow FTP access to begin with," Wisniewski advised users in a post to the Sophos Naked Security blog.

"FTP should have died a long time ago and you can help. Just refuse to use it."

Though the emergence of sophisticated, targeted attacks has dominated headlines recently, malware growth across all levels and sectors is soaring.

While mobile devices such as Android handsets have grown in popularity with malware writers, Windows PCs remain by far the most heavily targeted systems.

Do you agree

blog comments powered by Disqus

Poll

Microsoft v Google

Which productivity tools do you use for work?

38%

6%

2%

2%

21%

31%

Popular Threads

Powered by Disqus
Sony Xperia Z vs Apple iPhone 5

Sony Xperia Z vs Apple iPhone 5 head to head video review

V3 pits Sony's rugged flagship against Apple's premier handset

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Business Analyst - Financial Services

Business Analyst - Financial Services - required for...

QlikView Consultant

QlikView Consultant / QlikView Developer required for...

Business Intelligence Developer

Business Intelligence Developer (SSIS SSAS SSRS) required...

SharePoint Developer

SharePoint Developer (Senior) required for a MS Gold...

To send to more than one email address, simply separate each address with a comma.