On CBSSports.com: Centerfold hotties make their NFL picks
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jul 19, 2006 1:35:00 AM

A new Trojan horse is so good at hiding itself that some security researchers claim a new chapter has begun in their battle against malicious-code authors.

The new pest, dubbed "Rustock" by Symantec and "Mailbot.AZ" by F-Secure, uses "rootkit" techniques crafted to avoid the detection technology used by security software, Symantec and F-Secure said in recent analyses.

"It can be considered the first born of the next generation of rootkits," Elia Florio, a security response engineer at Symantec, wrote in a blog late last month. "Rustock.A consists of a mix of old techniques and new ideas that when combined make a malware that is stealthy enough to remain undetected by many rootkit detectors commonly used."

Rootkits are considered an emerging threat. They are used to make system changes to hide software, which may be malicious. In the case of Rustock or Mailbot.AZ, rootkit technology was used to hide a Trojan horse that opens a backdoor on an infected system, putting it at the beck and call of an attacker, according to Symantec.

In their continuing race with security software makers, the creators of this latest rootkit appear to have looked closely at the inner workings of detection tools before crafting their malicious code, said Craig Schmugar, virus research manager at McAfee, which calls the pest "PWS-JM."

"Security companies are trying to stay one step ahead of the bad guys, but the bad guys already have the technology that is available from the security vendors," he said. "A number of techniques have been combined to really strengthen and harden this particular threat. They have done a pretty good job at closing all the doors."

The mixture of cloaking methods makes Rustock "totally invisible on a compromised computer when installed," including on a PC running an early release of Windows Vista, Symantec's Florio wrote. "We consider it to be an advanced example of stealth by design malicious code."

To avoid detection, Rustock runs no system processes, but runs its code inside a driver and kernel threads, Florio wrote. It also uses alternate data streams instead of hidden files and avoids using application programming interfaces (APIs). Today's detection tools look for system processes, hidden files and hooks into APIs, according to Florio's post.

Additionally, Rustock defeats rootkit detectors' checks for the integrity of some kernel structures and the detectors' efforts to detect hidden drivers, Florio wrote. Furthermore the SYS driver the rootkit uses is polymorphic and changes its code from sample to sample, according to the blog posting.

Still, chances of people being attacked by this rootkit and its malicious Trojan horse payload are slim, experts said. "People are blogging about it not because it is highly prevalent, but because of the challenges it poses to existing rootkit detection tools," Schmugar said. Symantec and F-Secure also both state the threat is not widespread.

F-Secure updated its BlackLight rootkit detection tool that can detect current versions of the pest, the company said in a blog. Symantec and McAfee are still working on tools to detect and remove rootkits from computers.

  • Talkback
  • Most Recent of 118 Talkback(s)
Root Kits/ Stealth Trojans, ET AL
I recently obtained what I believe was this root kit. I was running McAfee Firewall, Virus Scan, Privacy, etc. This thing came in and they didn't have a clue. Then I tried to contact them for help. I... (Read the rest)
Posted by: southpaw28 Posted on: 05/16/07 You are currently: Logged In | Log out
How much ya wanna bet Linux User 147560   | 07/18/06
Already successful... Anton Philidor   | 07/18/06
You have to give ZDNet credit... Anton Philidor   | 07/18/06
Is that what it was? Shelendrea   | 07/19/06
Nothing to do with the security of Vista toadlife   | 07/18/06
You may be right, but.... bmgoodman   | 07/19/06
Linux User tealcat   | 07/19/06
Nope, sorry to disappoint but Linux User 147560   | 07/19/06
And just to rub salt in your wounds... Linux User 147560   | 07/19/06
Really? Ya think? NonZealot   | 07/19/06
I'd like to hear the take on this one from the Microsoft fanboys . Intellihence   | 07/18/06
(nt)So you don't have a take on it? toadlife   | 07/18/06
I do , but I want to hear what the others have to say . Intellihence   | 07/18/06
Your side stepping the question. John Zern   | 07/19/06
Rootkits possible in Linux ristephen@...   | 07/19/06
Of course he doesn't Loverock Davidson   | 07/19/06
Oh look Ld speaks of me again ,,, Intellihence   | 07/19/06
Yes I did Loverock Davidson   | 07/19/06
I DON'T THINK SO ,,, Intellihence   | 07/19/06
Don't be a player hater! Loverock Davidson   | 07/19/06
For a personal note you moron ,,, Intellihence   | 07/19/06
The only game you know Lovey Shelendrea   | 07/19/06
That which doesn't kill me makes me stronger lovvvvie   | 07/19/06
Very good Intellihence   | 07/19/06
10.0 John L. Ries   | 07/19/06
I'd like to hear the view of those who like rootkits Boot_Agnostic   | 07/19/06
Can they be detected in "safe" mode...? jinko   | 07/19/06
Undetectible ristephen@...   | 07/19/06
Words left out of the headline Chad_z   | 07/19/06
Rootkit are easy to rule out Quebec-french   | 07/19/06
Re: Rootkit are easy to rule out wanttaberacer   | 07/19/06
Rootkits get better at hiding Loverock Davidson   | 07/19/06
get lost you troll Quebec-french   | 07/19/06
Throw him a few bugs to eat ,,, Intellihence   | 07/19/06
But he is so lonely OhMyGosh   | 07/19/06
Hmmm. John Zern   | 07/19/06
RE: get lost you troll richdave   | 07/19/06
You'd have more Loverocks if... friedcow   | 07/19/06
Another Response From The RETARD Troll Loverock itanalyst   | 07/19/06
Then you should correct Wikipedia.org iavor.raytchev@...   | 07/19/06
Originally UNIX iavor.raytchev@...   | 07/19/06
http://en.wikipedia.org/wiki/Rootkit Bill4   | 07/19/06
That's a given NonZealot   | 07/19/06
You hit the nail on the head the_seb   | 07/19/06
All too true nucrash   | 07/19/06
Which... zkiwi   | 07/19/06
Linux has no Rootkits OhMyGosh   | 07/19/06
Say what? John L. Ries   | 07/19/06
That was the past, we are talking about todays world OhMyGosh   | 07/19/06
Sorry to bust your bubble zkiwi   | 07/19/06
Better check your bubble burster... Linux User 147560   | 07/19/06
His bubble burster is working just fine toadlife   | 07/19/06
Well... zkiwi   | 07/19/06
Local exploits are hard to accomplish? NonZealot   | 07/19/06
Your first link Linux User 147560   | 07/19/06
Linux User: what has changed? NonZealot   | 07/19/06
NonZealot: answer to one of your q's.. Speeddymon   | 07/19/06
You weren't looking very hard toadlife   | 07/19/06
toadlife, you weren't looking very hard OhMyGosh   | 07/19/06
So I stand corrected... Linux User 147560   | 07/19/06
You sure LU 147560? Scrat   | 07/20/06
Hey Scrat... Linux User 147560   | 07/20/06
You are a moron.. widge_z   | 07/19/06
...I know u are but what am i? OhMyGosh   | 07/19/06
You seem to be missing a few key concepts... toadlife   | 07/19/06
Still empty handed? OhMyGosh   | 07/19/06
(nt)Still empty headed? toadlife   | 07/19/06
It appears your googling skills leve much to be desired, so.... toadlife   | 07/19/06
toadlife, we are talking Linux, not Unix OhMyGosh   | 07/19/06
Are that stupid? toadlife   | 07/19/06
Are you that stupid? toadlife   | 07/19/06
What's your email address.. John Zern   | 07/19/06
linuxuser147560@yahoo.com Linux User 147560   | 07/19/06
linuxuser147560@yahoo.com Linux User 147560   | 07/19/06
ohmygosh@hotmail.com OhMyGosh   | 07/19/06
Huh? zkiwi   | 07/19/06
WOW. OMG... John Zern   | 07/19/06
Linux and Root Kits tracy anne   | 07/19/06
Assistance from the administrator John L. Ries   | 07/19/06
carelessness and ignorance tracy anne   | 07/20/06
TFS to do your research, eh? Boomslang   | 07/19/06
I think you will find... zkiwi   | 07/19/06
ever heard of package management? Sxooter_z   | 07/19/06
Oohh, where to begin... handydan918   | 07/19/06
Loverock Davidson, My Hero, you are intellegent uM0p ap!sdn   | 07/19/06
ignorance, stupidity, dumb ???, xoxoxoxoxo not of this world   | 07/19/06
They exist in both, better are very different xrxca   | 07/20/06
Microsoft must REMOVE this capabilty. Period... BitTwiddler   | 07/19/06
Which capability? Be specific, please. <eom> techboy_z   | 07/19/06
Might mean the ability to hide stuff Leria   | 07/19/06
Yes, you are correct :) BitTwiddler   | 07/20/06
Rootkits. What else... BitTwiddler   | 07/20/06
So what you are saying... NonZealot   | 07/20/06
Anyone noticed the trolls losing their edge? NonZealot   | 07/19/06
At least trolls know Windows is an OS OhMyGosh   | 07/19/06
Don't be so hard on yourself! enduser_z   | 07/19/06
Uh . . .Zealot . . ? Windows IS the OS critic-at-arms   | 07/19/06
Didn't realize I had to spell it out for the slow ones NonZealot   | 07/19/06
A root canal is in order.... mroonie   | 07/19/06
root kits slow_descent   | 07/19/06
Problem is lack of ethics retiredgeezergeek   | 07/19/06
Don't come to me with problems. Sxooter_z   | 07/19/06
Problem is lack of ethics You are kidding?   | 07/19/06
Having read the article....and the 63 current posts richdave   | 07/19/06
Sane... bargeemike   | 07/19/06
This is all very interesting... graphite   | 07/19/06
I'm shocked MS has the stones to sue . . . njic@...   | 07/19/06
Hey nimrod ,,, Intellihence   | 07/20/06
The cry baby responds njic@...   | 07/21/06
Thanks for the chuckle!! NonZealot   | 07/20/06
I laughed myself njic@...   | 07/21/06
What's the best current remover then? or manually? msianbart@...   | 07/20/06
Tripwire can find any rootkit jdudeck@...   | 07/20/06
Once Again... Your Mom 2.0   | 07/21/06
Something to consider...and soon znewt   | 07/21/06
Microsoft: Unsafe at any speed AWolfe_II   | 07/22/06
Linux users get better at hiding Windows' rootkits Boot_Agnostic   | 07/24/06
Root Kits/ Stealth Trojans, ET AL southpaw28   | 05/16/07

What do you think?

advertisement
advertisement

Fusion

advertisement
Click Here