Beijing Olympics
A series of attacks have tried to take advantage of the upcoming Olympic games

Malware writers cash in on Olympics

Rootkit-laden video is latest to exploit Tibet protests

Shaun Nichols in California

A video file laced with a malicious rootkit is the latest attempt by hackers to cash in on the Beijing Olympics.

The video appears to be a simple protest cartoon packaged in an executable file. But the 'Race for Tibet' movie also contains a piece of key-logging malware that installs itself as a driver.

Advertisement

The cartoon shows a Chinese gymnast performing in an event along with images from the recent riots and government crackdowns in Tibet. The user is then urged to join a 'race for Tibet' protest.

McAfee researcher Patrick Comiotto warned that the movie initially infects the user with a malicious driver. The file is installed in the '%windir%/system32/' driver folder under the name 'dopydwi.sys'.

The file then proceeds to create a .dll file that logs keystrokes which are later uploaded to a server in China.

The cartoon is the latest in a series of attacks that have tried to take advantage of the recent events in Tibet and the upcoming Olympic games in Beijing.

Malware-laden fake petitions and press releases were sent out to pro-Tibet groups in early March following initial rioting in the region.

By last week, the Trojan involved in those attacks was linked to a larger series of SQL website attacks.

Piggybacking on current events has become a common social-engineering tactic for malware distributors.

Events ranging from the Virginia Tech shootings to the execution of Saddam Hussein have been exploited by hackers to infect unwitting users.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Tibet attack Trojan identified

'Fribet' also connected to SQL attacks

US surfers 'alarmingly' ignorant over botnet danger

NCSA warns over danger posed by cyber criminals' weapon of choice

Underworld economy runs on bots and spam

Market for hijacked PCs fuels online crime

Eight April patches from Microsoft

Five critical fixes in this month's update

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Top 10 cup

Top 10 technologies in a death spiral

A look at some technologies that may soon be departed

Thunderbird

Thunderbird 3 out this month

Open source email system gets a makeover

Best Buy to storm Blighty's stores

Now that Circuit City is gone, Best Buy's ruling the...

Internet Explorer

Europe's browser war heats up again

Mozilla and Opera demand changes to Microsoft's proposed ballot system

Primary Navigation