A particularly aggressive Trojan is on the loose that infects multimedia files stored on a users hard drive.
Weve not seen such a sophisticated Trojan infecting multimedia files before, says Christoph Alme, lead for the anti-malware team at Secure Computing, which has been studying the Trojan. Weve been seeing infected multimedia files for about a month now and [had been] wondering where they came from.
Like many malware infections, it starts with a visit to a sketchy site -- in this case, a Warez site, where the user downloads what he thinks is a serial key for a copy-protected software package, for example, but instead gets the Trojan that automatically infests all of his multimedia files. When he shares one of those music or video files with another user via a peer-to-peer network, the recipient in turn gets infected by a fake codec: no Warez visit required.
They lead you to a page under their control when you play back the file, and it has a pop-up telling you that you need to download the codec to play the video or audio file, Alme explains. That "codec" is actually the malware.
The Trojan basically uses legitimate multimedia functions -- no vulnerabilities you can patch -- to do its dirty work. It preys on the Advanced Systems Format (ASF) file feature in MP3 and Windows Media Audio (WMA) music files as well as Windows Media Video (WMV) files, for instance. ASF lets you embed script commands in these file. The attackers use that to inject their commands into all of your multimedia files, Alme says.
It also converts MP2 and MP3 files into WMA format so it can infect them as well. If you have a big MP3 collection, it will be completely converted to WME and WMA and you dont even notice that on your own system, he says.
And when the user plays any of the infected files from his hard drive, theres no indication of the infection.
Secure Computings Alme says the Trojans main purpose appears to be to spread a password stealer to get user names and passwords.
Meanwhile, Alme says the initial Trojan infection itself isnt nearly as prevalent as the volume of downstream infected multimedia files. Thats clearly due to P2P spreading it, he says.
Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.