Vulnerabilities / Threats
2/27/2014
10:55 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Bitcoin-Stealing Malware: Now In 100 Flavors

Specialized malware empties electronic wallets of digital currency, and antivirus often misses it, say researchers at RSA Conference.

RSA CONFERENCE 2014 -- San Francisco -- For just $35, you can buy a popular, specialized malware tool that steals Bitcoins and other such electronic currency -- and researchers have unearthed more than 100 different malware families that specialize in this form of theft.

Dell SecureWorks researchers Joe Stewart and Pat Litke discovered 80 of those cryptocurrency-stealing malware families in the past year as thieves clamor to cash in on the growing use of digital currency. Some of the malware variants are custom, while others are cranked out via malware-generator tools, but, either way, the average rate of detection across all antivirus tools is just below 50%, the researchers said at the RSA Conference this week.

[For more from RSA, see RSA Conference 2014: Complete Coverage.]

"[Bitcoins and digital currency] are very easy to steal," said Joe Stewart, director of malware research for SecureWorks. While some sophisticated hackers are stealing the currency, many of the thieves are novice "script kiddies" who get the cheap tools to snatch the currency from unsuspecting victims.

Read the rest of this story on Dark Reading.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9676
Published: 2015-02-27
The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free.

CVE-2014-9682
Published: 2015-02-27
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.

CVE-2015-0655
Published: 2015-02-27
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.

CVE-2015-0884
Published: 2015-02-27
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

CVE-2015-0885
Published: 2015-02-27
checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.