On GameSpot: We try out down the PSP Go
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jul 19, 2006 1:35:00 AM

A new Trojan horse is so good at hiding itself that some security researchers claim a new chapter has begun in their battle against malicious-code authors.

The new pest, dubbed "Rustock" by Symantec and "Mailbot.AZ" by F-Secure, uses "rootkit" techniques crafted to avoid the detection technology used by security software, Symantec and F-Secure said in recent analyses.

"It can be considered the first born of the next generation of rootkits," Elia Florio, a security response engineer at Symantec, wrote in a blog late last month. "Rustock.A consists of a mix of old techniques and new ideas that when combined make a malware that is stealthy enough to remain undetected by many rootkit detectors commonly used."

Rootkits are considered an emerging threat. They are used to make system changes to hide software, which may be malicious. In the case of Rustock or Mailbot.AZ, rootkit technology was used to hide a Trojan horse that opens a backdoor on an infected system, putting it at the beck and call of an attacker, according to Symantec.

In their continuing race with security software makers, the creators of this latest rootkit appear to have looked closely at the inner workings of detection tools before crafting their malicious code, said Craig Schmugar, virus research manager at McAfee, which calls the pest "PWS-JM."

"Security companies are trying to stay one step ahead of the bad guys, but the bad guys already have the technology that is available from the security vendors," he said. "A number of techniques have been combined to really strengthen and harden this particular threat. They have done a pretty good job at closing all the doors."

The mixture of cloaking methods makes Rustock "totally invisible on a compromised computer when installed," including on a PC running an early release of Windows Vista, Symantec's Florio wrote. "We consider it to be an advanced example of stealth by design malicious code."

To avoid detection, Rustock runs no system processes, but runs its code inside a driver and kernel threads, Florio wrote. It also uses alternate data streams instead of hidden files and avoids using application programming interfaces (APIs). Today's detection tools look for system processes, hidden files and hooks into APIs, according to Florio's post.

Additionally, Rustock defeats rootkit detectors' checks for the integrity of some kernel structures and the detectors' efforts to detect hidden drivers, Florio wrote. Furthermore the SYS driver the rootkit uses is polymorphic and changes its code from sample to sample, according to the blog posting.

Still, chances of people being attacked by this rootkit and its malicious Trojan horse payload are slim, experts said. "People are blogging about it not because it is highly prevalent, but because of the challenges it poses to existing rootkit detection tools," Schmugar said. Symantec and F-Secure also both state the threat is not widespread.

F-Secure updated its BlackLight rootkit detection tool that can detect current versions of the pest, the company said in a blog. Symantec and McAfee are still working on tools to detect and remove rootkits from computers.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 118 Talkback(s)
Root Kits/ Stealth Trojans, ET AL
I recently obtained what I believe was this root kit. I was running McAfee Firewall, Virus Scan, Privacy, etc. This thing came in and they didn't have a clue. Then I tried to contact them for help. I... (Read the rest)
Posted by: southpaw28 Posted on: 05/16/07 You are currently: a Guest | | Terms of Use
How much ya wanna bet  Linux User 147560 | 07/18/06
Already successful...  Anton Philidor | 07/18/06
You have to give ZDNet credit...  Anton Philidor | 07/18/06
Is that what it was?  Shelendrea | 07/19/06
Nothing to do with the security of Vista  toadlife | 07/18/06
You may be right, but....  bmgoodman | 07/19/06
Linux User  tealcat | 07/19/06
Nope, sorry to disappoint but  Linux User 147560 | 07/19/06
And just to rub salt in your wounds...  Linux User 147560 | 07/19/06
Really? Ya think?  NonZealot | 07/19/06
I'd like to hear the take on this one from the Microsoft fanboys .  Intellihence | 07/18/06
(nt)So you don't have a take on it?  toadlife | 07/18/06
I do , but I want to hear what the others have to say .  Intellihence | 07/18/06
Your side stepping the question.  John Zern | 07/19/06
Rootkits possible in Linux  ristephen@... | 07/19/06
Of course he doesn't  Loverock Davidson | 07/19/06
Oh look Ld speaks of me again ,,,  Intellihence | 07/19/06
Yes I did  Loverock Davidson | 07/19/06
I DON'T THINK SO ,,,  Intellihence | 07/19/06
Don't be a player hater!  Loverock Davidson | 07/19/06
For a personal note you moron ,,,  Intellihence | 07/19/06
The only game you know Lovey  Shelendrea | 07/19/06
That which doesn't kill me makes me stronger  lovvvvie | 07/19/06
Very good  Intellihence | 07/19/06
10.0  John L. Ries | 07/19/06
I'd like to hear the view of those who like rootkits  Boot_Agnostic | 07/19/06
Can they be detected in "safe" mode...?  jinko | 07/19/06
Undetectible  ristephen@... | 07/19/06
Words left out of the headline  Chad_z | 07/19/06
Rootkit are easy to rule out  Quebec-french | 07/19/06
Re: Rootkit are easy to rule out  wanttaberacer | 07/19/06
Rootkits get better at hiding  Loverock Davidson | 07/19/06
get lost you troll  Quebec-french | 07/19/06
Throw him a few bugs to eat ,,,  Intellihence | 07/19/06
But he is so lonely  OhMyGosh | 07/19/06
Hmmm.  John Zern | 07/19/06
RE: get lost you troll  richdave | 07/19/06
You'd have more Loverocks if...  friedcow | 07/19/06
Another Response From The RETARD Troll Loverock  itanalyst | 07/19/06
Then you should correct Wikipedia.org  iavor.raytchev@... | 07/19/06
Originally UNIX  iavor.raytchev@... | 07/19/06
http://en.wikipedia.org/wiki/Rootkit  Bill4 | 07/19/06
That's a given  NonZealot | 07/19/06
You hit the nail on the head  the_seb | 07/19/06
All too true  nucrash | 07/19/06
Which...  zkiwi | 07/19/06
Linux has no Rootkits  OhMyGosh | 07/19/06
Say what?  John L. Ries | 07/19/06
That was the past, we are talking about todays world  OhMyGosh | 07/19/06
Sorry to bust your bubble  zkiwi | 07/19/06
Better check your bubble burster...  Linux User 147560 | 07/19/06
His bubble burster is working just fine  toadlife | 07/19/06
Well...  zkiwi | 07/19/06
Local exploits are hard to accomplish?  NonZealot | 07/19/06
Your first link  Linux User 147560 | 07/19/06
Linux User: what has changed?  NonZealot | 07/19/06
NonZealot: answer to one of your q's..  Speeddymon | 07/19/06
You weren't looking very hard  toadlife | 07/19/06
toadlife, you weren't looking very hard  OhMyGosh | 07/19/06
So I stand corrected...  Linux User 147560 | 07/19/06
You sure LU 147560?  Scrat | 07/20/06
Hey Scrat...  Linux User 147560 | 07/20/06
You are a moron..  widge_z | 07/19/06
...I know u are but what am i?  OhMyGosh | 07/19/06
You seem to be missing a few key concepts...  toadlife | 07/19/06
Still empty handed?  OhMyGosh | 07/19/06
(nt)Still empty headed?  toadlife | 07/19/06
It appears your googling skills leve much to be desired, so....  toadlife | 07/19/06
toadlife, we are talking Linux, not Unix  OhMyGosh | 07/19/06
Are that stupid?  toadlife | 07/19/06
Are you that stupid?  toadlife | 07/19/06
What's your email address..  John Zern | 07/19/06
linuxuser147560@yahoo.com  Linux User 147560 | 07/19/06
linuxuser147560@yahoo.com  Linux User 147560 | 07/19/06
ohmygosh@hotmail.com  OhMyGosh | 07/19/06
Huh?  zkiwi | 07/19/06
WOW. OMG...  John Zern | 07/19/06
Linux and Root Kits  tracy anne | 07/19/06
Assistance from the administrator  John L. Ries | 07/19/06
carelessness and ignorance  tracy anne | 07/20/06
TFS to do your research, eh?  Boomslang | 07/19/06
I think you will find...  zkiwi | 07/19/06
ever heard of package management?  Sxooter_z | 07/19/06
Oohh, where to begin...  handydan918 | 07/19/06
Loverock Davidson, My Hero, you are intellegent  uM0p ap!sdn | 07/19/06
ignorance, stupidity, dumb ???, xoxoxoxoxo  not of this world | 07/19/06
They exist in both, better are very different  xrxca | 07/20/06
Microsoft must REMOVE this capabilty. Period...  BitTwiddler | 07/19/06
Which capability? Be specific, please.  techboy_z | 07/19/06
Might mean the ability to hide stuff  Leria | 07/19/06
Yes, you are correct happy  BitTwiddler | 07/20/06
Rootkits. What else...  BitTwiddler | 07/20/06
So what you are saying...  NonZealot | 07/20/06
Anyone noticed the trolls losing their edge?  NonZealot | 07/19/06
At least trolls know Windows is an OS  OhMyGosh | 07/19/06
Don't be so hard on yourself!  enduser_z | 07/19/06
Uh . . .Zealot . . ? Windows IS the OS  critic-at-arms | 07/19/06
Didn't realize I had to spell it out for the slow ones  NonZealot | 07/19/06
A root canal is in order....  mroonie | 07/19/06
root kits  slow_descent | 07/19/06
Problem is lack of ethics  retiredgeezergeek | 07/19/06
Don't come to me with problems.  Sxooter_z | 07/19/06
Problem is lack of ethics  You are kidding? | 07/19/06
Having read the article....and the 63 current posts  richdave | 07/19/06
Sane...  bargeemike | 07/19/06
This is all very interesting...  graphite | 07/19/06
I'm shocked MS has the stones to sue . . .  njic@... | 07/19/06
Hey nimrod ,,,  Intellihence | 07/20/06
The cry baby responds  njic@... | 07/21/06
Thanks for the chuckle!!  NonZealot | 07/20/06
I laughed myself  njic@... | 07/21/06
What's the best current remover then? or manually?  msianbart@... | 07/20/06
Tripwire can find any rootkit  jdudeck@... | 07/20/06
Once Again...  Your Mom 2.0 | 07/21/06
Something to consider...and soon  znewt | 07/21/06
Microsoft: Unsafe at any speed  AWolfe_II | 07/22/06
Linux users get better at hiding Windows' rootkits  Boot_Agnostic | 07/24/06
Root Kits/ Stealth Trojans, ET AL  southpaw28 | 05/16/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here