Risk

7/10/2008
07:50 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

'Blue Screen of Death' Masks Spyware Invasion

Attack uses fake blue screen of death as cover to inject malware

A new attack imitates the dreaded blue screen of death as cover so it can silently install bundles of spyware onto the machine.

Researchers at FaceTime Security Labs say the attack uses a blue screen of death screensaver and bundles it with the spyware files. “Seems the bad guys are not without a sense of humor. Hiding a blizzard of infection file installs behind a legitimate screensaver created by a security expert is pretty bizarre,” blogged Chris Boyd, director of malware research at FaceTime Labs.

It’s unclear how widespread the infection is so far, Boyd told Dark Reading, but it’s still fairly new. “It's hard to tell what the spread is so far, but it does seem to be popping up more and more on help and support forums, which is a sure sign of an increasing spread,” Boyd says. “It's recent enough that the spread probably is not huge yet, but it's bundled with the screensaver, which has been a popular joke for a few years.”

The attack installs the Fake.AV and Smiddy spyware families, which come with Trojans that give an attacker control of the infected PC. “Fake.AV tricks the user into purchasing various different rogue anti-spyware applications. It produces numerous official-looking advertisements in order to manipulate the user into purchasing the product,” Boyd says. “Smiddy manipulates the victim's computer into using a malicious copy of explorer.exe in order to the let attacker to gain control. It also looks for and deletes critical anti-malware components related to QQDoctor and Eset Nod32.”

When the spyware installation is complete, the screen displays various fake warnings about spyware being detected on the machine, with links to “clean” the machine.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

  • FaceTime Communications Inc.

    Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    Russia Hacked Clinton's Computers Five Hours After Trump's Call
    Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
    Tips for the Aftermath of a Cyberattack
    Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    5 Emerging Cyber Threats to Watch for in 2019
    Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
    Flash Poll
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-11378
    PUBLISHED: 2019-04-20
    An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
    CVE-2019-11372
    PUBLISHED: 2019-04-20
    An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
    CVE-2019-11373
    PUBLISHED: 2019-04-20
    An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
    CVE-2019-11374
    PUBLISHED: 2019-04-20
    74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
    CVE-2019-11375
    PUBLISHED: 2019-04-20
    Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.