Security Information

Three-pronged Trojan Attack Threatens Security on the Internet


Glieder (Win32.Glieder.AK), Fantibag (Win32.Fantibag.A) and Mitglieder (Win32.Mitglieder.CT) are not names of a modern day version of The Three Musketeers. These are Trojans engineered for a hacker attack that will infect computers and open them for use in further attacks.

"Combating computer viruses is essentially a game of hide and seek," says Govind Rammurthy, CEO, MicroWorld Technologies, among the leading Security Solutions providers. "Hackers riding piggyback on viruses have only a short window of opportunity to maximize their gain before the viruses are detected, neutralized and logged into Virus Definition databases, 'vaccinating' the system against those strains.

Without continuing system vulnerability caused by virus infection there is little they can do to further their malicious ends like stealing personal information, credit card details and other sensitive and vital data. To achieve their ends they need to keep the system vulnerability going for more time. This co-ordinated Trojan threat is an attempt to the keep that 'backdoor' open, essentially buying time," he concludes.

Of the three, Glieder leads the initial charge. It sneaks past anti-virus protection to download and execute files from a long, hard-coded list of URLs and "plant" the infected machine with "hooks" for future use. On Windows 2000 and Windows XP machines, it attempts to stop and disable the Internet Connection Firewall and the Security Center service (introduced with Windows XP Service Pack 2). Then the Trojan accesses the URL list to download Fantibag. The way is now paved to launch the second stage of attack.

Sulabh, a tester with MicroWorld Technologies says of Fantibag, "Now Fantibag goes about attacking the networking feature of the infected system to prevent it from communicating with anti-virus firms and denying access to the Microsoft Windows Update site. It closes your escape route by making it impossible to download an anti-virus solution and any subsequent Windows security patch to your system. Effectively it helps Mitglieder (the third stage Trojan) open the 'backdoor' by shutting the other doors on you."

Mitglieder puts the system under complete control of the attacker by opening the 'backdoor' on a port using which the attacker can update the Trojan, to stay a step ahead of attempts to remove it, download and execute files, initiate an SMTP server to relay spam, execute files on the infected computer and download and execute files via an URL. "This is what makes it scary," say Aarti, Assistant Manager, QA, MicroWorld Technologies. "The fact that the system can now be used as a remote controlled 'soldier' (bot) in an army (botnet) of similarly compromised machines to launch criminally motivated attacks, causing harm to Internet users."

Botnets thus formed can among other things, use your machine to launch Distributed Denial of service attacks which overload servers, making them crash, to send out spam, spread new Malware, plant Keylogger to retrieve your personal information like identity, passwords, account numbers etc., install Spyware, manipulate online polls/games, abuse programs like Google AdSense to cheat advertisers of revenue, and install Advertisement Addons for financial gain as in fake websites advertising services that don't exist.

"Botnets can even encompass over 50,000 host machines. The potential for mischief is huge," reflects Govind Rammurthy. "Such a three-pronged Trojan attack where attackers change their virus code and release viruses quickly to bypass virus signature scanners, then disable network access to deny the user link-ups to anti-virus and Microsoft Windows Update site for protection has huge significance for virus-signature based protection. It is a sign of things to come," he says, remembering the scramble at MicroWorld labs to update their products to detect and remove the three Trojans.

Anti-virus updates for the three-pronged Trojan threat are available at MicroWorld Technologies site. Maybe the time for worrying about some pimply teenager turning out malicious code because they have nothing better to do on a nice sunny morning, is over. The world could be facing a determined organized crime syndicate who'll stop at nothing to get what they want - information precious to you.

MicroWorld Technologies is one of the leading solution providers for Information Technology, Content Security and Communications Software. MicroWorld has established itself as a leader in providing content security, anti-virus and corporate communications software solutions.


MORE RESOURCES:

Hot Hardware

Number Of Bank Customers Affected By Security Breach Soars
Hartford Courant, United States - 10 hours ago
New York Mellon disclosed in May that the security breach affected 497333 Connecticut residents, most of them depositors of People's United Bank in ...
Security breach at bank hits 12M people: BNY Mellon records could ... TMCnet
Bank of NY Mellon says data breach now affects 12M CNNMoney.com
Bank of NY Mellon data breach now affects 12.5 mln Reuters
SC Magazine UK - Dark Reading
all 48 news articles


Homeland Security Capital Corporation's Environmental Remediation ...
MarketWatch - 6 hours ago
an international provider of specialized technology-based radiological, nuclear, environmental, disaster relief and security solutions to government and ...


Proctor & Gamble outsources security to IBM, but keeping security ...
NetworkWorld.com, MA - 4 hours ago
"By teaming with IBM ISS, our objective is to both strengthen our security systems and improve the efficiency and effectiveness of our security operations," ...
Procter and Gamble Selects IBM Internet Security Systems to Help ... CNNMoney.com
Proctor & Gamble Taps IBM ISS For Cyber-Security Contract InformationWeek
Proctor & Gamble Chooses IBM ISS for Cyber Security IT Business Edge
Bizjournals.com
all 17 news articles


ABC News

Communiques from the security front, sir
ZDNet UK, UK - Aug 28, 2008
... easy it was to break into the Nasa systems, or, to quote his dad when I spoke to them both outside the House of Lords in June -- "The security was crap. ...
Space station computer virus raises security concerns New Scientist (subscription)
The IT Security of the ISS Wired News
Ground Control To Major Tom: Check Your Laptop For Worms CRN
InternetNews.com
all 211 news articles


Bank security guard is shot and killed in South LA
Los Angeles Times, CA - 10 hours ago
Two attackers wrested a handgun from a security guard at a Los Angeles bank Thursday, then fatally shot him with his own weapon, police said. ...
Bank Security Guard Shot, in Critical Condition After Robbery MyFox Los Angeles
Security Guard Shot Outside Bank Dies KTLA
Jefferson Park: Bank security guard is fatally shot Los Angeles Times
Los Angeles Times
all 5 news articles


ChattahBox

Apple to Fix iPhone Security Loophole
InternetNews.com - 35 minutes ago
An Apple spokesperson told Reuters via e-mail that Apple was aware of the iPhone security flaw and is preparing a software update to fix the flaw, ...
iPhone Round-Up: Security Fix; Rogers Revamps Prices; AT&T ... Washington Post
Apple promises September fix for iPhone security flaw Macworld
Apple To Fix iPhone Security Flaw CRN
ChattahBox - Bloomberg
all 129 news articles


Pa. sends ID info of 1200 to wrong addresses
The Associated Press - 11 hours ago
(AP) — State officials are hoping to contain any worries about identity theft after more than 1200 mailings containing the Social Security numbers of state ...
Pa. acting to mitigate ID breach Philadelphia Inquirer
all 113 news articles


Fixing Social Security
Washington Post, United States - 16 hours ago
25 editorial "Social Security on Ice" about Democratic presidential nominee Barack Obama's suggestion of a higher FICA tax on earned income of more than ...
Deficit Hawks Rain on Obama’s Parade CQPolitics.com
all 3 news articles


Mesa police to help with security at GOP convention
Arizona Republic, AZ - 10 hours ago
28, 2008 04:24 PM Mesa and Phoenix police are among Arizona agencies that will send officers to St. Paul to assist with security at next week's Republican ...


CTV.ca

Zardari moves into PM's House over security concerns
Hindu, India - 6 hours ago
Islamabad (PTI): Pakistan's presidential front- runner Asif Ali Zardari has moved into the heavily-guarded Prime Minister's House over security fears in the ...
Bhutto widower Zardari moves house over security fears AFP
Zardari shifts to PM house for security reasons Press Trust of India
Zardari staying at PM House for ‘security reasons’ Newspost Online
Minneapolis Star Tribune
all 316 news articles

Security - Google News

home | site map
© 2006