site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
755
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


Stem Bolt
Aka Smiling Bob
Premium
join:2002-11-08
Cleveland, OH
kudos:2

Crisis Trojan Makes Its Way onto Virtual Machines

»threatpost.com/en_us/blogs/crisi···s-082112
quote:
The Windows version of the Crisis Trojan is able to sneak onto VMware implementations, making it possibly the first malware to target such virtual machines. It also has found a way to spread to Windows Mobile devices.

"The threat searches for a VMware virtual machine image on the compromised computer and, if it finds an image, it mounts the image and then copies itself onto the image by using a VMware Player tool," Katsuki said.

He cautioned that Crisis/Morcut does not exploit a vulnerability in VMware specifically; instead, it takes advantage of a characteristic of all virtualization sofware that stores as local files on a host machine. These files are then subject to manipulation, even when the virtual machine isn't running.


DownTheShore
Help Moore Oklahoma
Premium
join:2003-12-02
Beautiful NJ
kudos:12

That's interesting, considering how the folks who use VM usually seem to think that they are safe because of it.



Raphion

join:2000-10-14
Samsara

reply to Stem Bolt
Kind of duh... If your host machine is compromised, game is over, no VM running on it is safe.



Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC
kudos:7

reply to Stem Bolt

Superworm Crisis eats Macs, VMware and - shock - Windows

Security watchers have discovered a virus strain that compromises VMware virtual machines as well as infecting Mac OS X and Windows computers and Windows Mobile devices. It demonstrates previously unseen capabilities in the process.

The Crisis malware typically arrives in a Java archive file (.jar) and is typically installed by posing as a Flash Player Java applet to trick a victim into opening it.

The archive contains executable files targeting Apple and Microsoft operating systems; the malware is able to detect which platform it is running on and serve up the correct variant.

Once launched, the worm puts in place a rootkit to hide itself from view; installs spyware to record the user's every move on the computer; and opens a backdoor to the IP address 176.58.100.37, allowing miscreants to gain further access to the machine, according to a write-up of the threat by Kaspersky Lab. The malicious code also, unsurprisingly, survives across reboots.

The Windows variant can kill off antivirus programs, log keypresses, download and upload files, take screengrabs, lift the contents of the user's clipboard, record from the computer's webcam and mic, and snoop on these applications: Firefox, Internet Explorer, Chrome, Microsoft Messenger, Skype, Google Talk and Yahoo! Messenger.

The Apple-targeting variant is more or less the same: it monitors Adium, Mozilla, Firefox, MSN Messenger (for Mac) and Skype, and records keystrokes. On Mac OS X, at least, the user does not need administrative privileges to install the software although its functionality is affected if the logged-in punter has insufficient rights: with admin-level access, the virus can slot in the rootkit, for instance.

Subsequent analysis of the malware by researchers at Symantec uncovered elaborate techniques in the Windows variants that allow it to spread onto virtual machines and Microsoft-powered smartphones.

»www.theregister.co.uk/2012/08/22···_crisis/
OSX.Crisis.
»www.symantec.com/connect/blogs/c···machines
--
Gladiator Security Forum
»www.gladiator-antivirus.com/


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
kudos:3

reply to Stem Bolt
'Windows Mobile', I thought I was only one left running a Windows Mobile device so this must be a targeted attack against me, bastard.

Blake
--
Vendor: Author of Link Logger which is a traffic analysis and firewall logging tool



StuartMW
Who Is John Galt?
Premium
join:2000-08-06
Galt's Gulch
kudos:2
Reviews:
·CenturyLink

said by Link Logger:

'Windows Mobile', I thought I was only one left running a Windows Mobile device...

Second last
--
Don't feed trolls--it only makes them grow!


sivran
Opera convert
Premium
join:2003-09-15
Arlington, TX
kudos:1

Make that third... or does my ancient Dash with Windows Mobile 6 not count?



siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17
Reviews:
·Bell Sympatico

reply to Stem Bolt
Researchers in "Crisis" mode over virtual spyware find

quote:
Researchers are analyzing a rare piece of malware that is able to spread onto virtual machines from the host operating system.

Known as Crisis, the trojan first was found in July by security firm Intego affecting Mac OS X systems. It's capable of recording keystrokes, recording webcams, tracking web traffic, taking screenshots and stealing data.


shearer
Northern Lights
Premium
join:2002-06-18
Asia

reply to Raphion

said by Raphion:

Kind of duh... If your host machine is compromised, game is over, no VM running on it is safe.

This.

Friday, 24-May 00:06:23 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics