Risk

7/10/2008
07:50 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

'Blue Screen of Death' Masks Spyware Invasion

Attack uses fake blue screen of death as cover to inject malware

A new attack imitates the dreaded blue screen of death as cover so it can silently install bundles of spyware onto the machine.

Researchers at FaceTime Security Labs say the attack uses a blue screen of death screensaver and bundles it with the spyware files. “Seems the bad guys are not without a sense of humor. Hiding a blizzard of infection file installs behind a legitimate screensaver created by a security expert is pretty bizarre,” blogged Chris Boyd, director of malware research at FaceTime Labs.

It’s unclear how widespread the infection is so far, Boyd told Dark Reading, but it’s still fairly new. “It's hard to tell what the spread is so far, but it does seem to be popping up more and more on help and support forums, which is a sure sign of an increasing spread,” Boyd says. “It's recent enough that the spread probably is not huge yet, but it's bundled with the screensaver, which has been a popular joke for a few years.”

The attack installs the Fake.AV and Smiddy spyware families, which come with Trojans that give an attacker control of the infected PC. “Fake.AV tricks the user into purchasing various different rogue anti-spyware applications. It produces numerous official-looking advertisements in order to manipulate the user into purchasing the product,” Boyd says. “Smiddy manipulates the victim's computer into using a malicious copy of explorer.exe in order to the let attacker to gain control. It also looks for and deletes critical anti-malware components related to QQDoctor and Eset Nod32.”

When the spyware installation is complete, the screen displays various fake warnings about spyware being detected on the machine, with links to “clean” the machine.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

  • FaceTime Communications Inc.

    Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    Valentine's Emails Laced with Gandcrab Ransomware
    Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
    High Stress Levels Impacting CISOs Physically, Mentally
    Jai Vijayan, Freelance writer,  2/14/2019
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    5 Emerging Cyber Threats to Watch for in 2019
    Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
    Flash Poll
    How Enterprises Are Attacking the Cybersecurity Problem
    How Enterprises Are Attacking the Cybersecurity Problem
    Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-7399
    PUBLISHED: 2019-02-17
    Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.
    CVE-2019-8392
    PUBLISHED: 2019-02-17
    An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to enable Guest Wi-Fi via the SetWLanRadioSettings HNAP API to the web service provided by /bin/goahead.
    CVE-2019-8394
    PUBLISHED: 2019-02-17
    Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
    CVE-2019-8395
    PUBLISHED: 2019-02-17
    An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
    CVE-2019-8389
    PUBLISHED: 2019-02-17
    A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) ...