Viruses now penetrating deeper

By Victoria Ho, ZDNet Asia
Wednesday, May 13, 2009 04:15 PM

update New malware variants have taken researchers by surprise by adapting new "stealth" methods to penetrate systems deeper so as to avoid detection, according to Kaspersky Lab.

The antivirus company said in a video conference Wednesday, a new variant of botnet, Sinowal--also known as Torpig--marks the first time cybercriminals have used such sophisticated methods.

Kaspersky said Sinowal writes itself to the user's hard drive master boot record (MBR), the operating system's lowest level, and has been successful in avoiding detection by antivirus products.

It said the worm has has over the last month been actively spreading through a number of methods including Web sites exploiting the Neosploit rootkit and a vulnerability in PDF software, Adobe Acrobat Reader.

Konstantin Sapronov, head, virus lab, China, Kaspersky, said new methods of infiltration have also rendered it nearly impossible for users to avoid infection, even if they are careful. Seemingly clean sites can also perform backend redirection to malware-ridden sites.

Sapronov said Web malware authors have favored redirection exploits on Web apps and search fields, like iFrame attacks during 2008, compared to 2007 which saw more Trojan horses and droppers being used.

The Web has also overtaken e-mail as the top transport medium for viruses, with the number of infected sites growing 300 percent in 2008, he said.


WORTHWHILE?

1

1 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Configure Apache to support multiple SSL sites on a single IP address

Open Source

With Apache 2.2.12 and support for the Server Name Indication extension to the SSL protocol, you can configure name-based HTTPS sites, just as you can name-based HTTP sites.


Read more »



Amendments to empower Copyright Tribunal

Blog thumbnail

As a lawyer, I often inform my clients about the need to clear licenses with the various licensing societies whenever they use works belonging to other parties. This is especially..... by Bryan Tan

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web