<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; windows-virus</title>
	<atom:link href="http://www.darknet.org.uk/tag/windows-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Java Based Cross Platform Malware Trojan (Mac/Linux/Windows)</title>
		<link>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/</link>
		<comments>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/#comments</comments>
		<pubDate>Thu, 20 Jan 2011 07:45:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[cross platform malware]]></category>
		<category><![CDATA[cross platform trojan]]></category>
		<category><![CDATA[cross platform virus]]></category>
		<category><![CDATA[java based malware]]></category>
		<category><![CDATA[java based trojan]]></category>
		<category><![CDATA[jnanabot]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[linux malware]]></category>
		<category><![CDATA[linux trojan]]></category>
		<category><![CDATA[mac malware]]></category>
		<category><![CDATA[mac trojan]]></category>
		<category><![CDATA[mac-virus]]></category>
		<category><![CDATA[macbook-pro]]></category>
		<category><![CDATA[osx trojan]]></category>
		<category><![CDATA[osx.koobface]]></category>
		<category><![CDATA[trojan.jnanabot]]></category>
		<category><![CDATA[windows-virus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3031</guid>
		<description><![CDATA[It&#8217;s pretty rare to read about malware on the Linux or Mac OSX platforms and even more rare to read about cross-platform malware which targets both AND Windows by using Java. A neat piece of coding indeed, it targets vulnerabilities in all 3 operating systems &#8211; the sad thing? The malware itself is vulnerable to [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s pretty rare to read about malware on the <a href="http://www.darknet.org.uk/category/linux-hacking/">Linux</a> or <a href="http://www.darknet.org.uk/category/apple-hacking/">Mac OSX</a> platforms and even more rare to read about cross-platform malware which targets both AND Windows by using Java.</p>
<p>A neat piece of coding indeed, it targets vulnerabilities in all 3 operating systems &#8211; the sad thing? The malware itself is vulnerable to a basic <a href="http://www.darknet.org.uk/tag/directory-traversal/">directory traversal</a> exploit, which means rival gangs can actually commandeer the infected targets.</p>
<p>They went to lengths to keep it secure and unseen (encrypted communications etc) &#8211; but didn&#8217;t program the malware itself securely&#8230;</p>
<blockquote><p>From the department of cosmic justice comes this gem, spotted by researchers from Symantec: a trojan that targets Windows, Mac, and Linux computers contains gaping security vulnerabilities that allow rival criminal gangs to commandeer the infected machines.</p>
<p>Known as Trojan.Jnanabot, or alternately as OSX/Koobface.A or trojan.osx.boonana.a, the bot made waves in October when researchers discovered its Java-based makeup allowed it to attack Mac and Linux machines, not just Windows PCs as is the case with most malware. Once installed, the trojan components are stored in an invisible folder and use strong encryption to keep communications private.</p>
<p>The bot can force its host to take instructions through internet relay chat, perform DDoS attacks, and post fraudulent messages to the victim&#8217;s Facebook account, among other things.</p>
<p>Now, Symantec researchers have uncovered weaknesses in the bot&#8217;s peer-to-peer functionality that allow rival criminals to remotely steal or plant files on the victim&#8217;s hard drive. That means the unknown gang that took the trouble to spread the infection in the first place risks having their botnet stolen from under their noses.</p>
<p>“Even though it&#8217;s encrypted and even though it was written in Java to make it cross-platform, it was still vulnerable to basically a directory transversal exploit,” Dean Turner, director of Symantec&#8217;s Global Intelligence Network, told The Reg. “From a technical perspective, it goes to show that even if you have all those things where you&#8217;re building in a secure platform, if you&#8217;re not building application security into your malware, other bad guys will probably take advantage of it.”</p></blockquote>
<p>It&#8217;s somewhat of an odd decision though, in terms of numbers obviously Windows machines far outnumber Linux and OSX desktop installations. On the web-server front perhaps Linux is a valuable target &#8211; but on consumer desktops? Is it really worth the effort for malware creators to make cross-platform trojans? Personally I don&#8217;t think it is, maybe it was just an experiment.</p>
<p>The number of Apple machines is certainly growing, the next big market we are going to see is tablets and smartphones I believe. I&#8217;d be on the lookout for more <a href="http://www.darknet.org.uk/tag/ios/">iOS</a> and <a href="http://www.darknet.org.uk/tag/android/">Android</a> worms/trojans in coming months.</p>
<p>A self-replicating stealthy Android trojan with a previously unpatched zero-day remote root exploit could be devastating.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Jnanabot&#8217;s P2P feature is designed to make botnets harder to take down by providing multiple channels of communication. After sending an infected machine a single GET request, a website can discover all the information needed to upload any file to any location on the host&#8217;s file system. Attackers can then install a simple backdoor on a user&#8217;s machine by, for instance, writing a malicious program to a computer&#8217;s startup directory.</p>
<p>Attackers can use the same vulnerability to steal files on infected machines.</p>
<p>Turner said the number of Jnanabot infections so far is “measured in the thousands,” rather than the hundreds of thousands for some of the better-known trojans. Still, infection statistics gathered by Symantec in December are surprising. They show that about 16 per cent of infections hit Macs. They didn&#8217;t show any infections on Linux machines. Turner said that Jnanabot attacks on the open source platform weren&#8217;t able to survive a reboot.</p>
<p>The bot was discovered spreading over Facebook posts that planted the following message on infected users&#8217; Facebook pages: “As you are on my friends list I thought I would let you know I have decided to end my life.” An included link leads recipients to a cross-platform JAR, or Java Archive file that can run on Windows, Mac, or Linux. Once the recipient is infected, his Facebook page carries the same dire warning.</p></blockquote>
<p>It seems like the trojan theoretically can attack Linux, but so far hasn&#8217;t been seen in the wild and it can&#8217;t survive a reboot. Not that it really matters as from my experience most Linux users never reboot anyway except for kernel upgrades (which isn&#8217;t that often).</p>
<p>Perhaps it just doesn&#8217;t work that well on Linux, or Linux users don&#8217;t believe in installing JVM &#8211; it doesn&#8217;t usually come standard with OS installs as it&#8217;s considered non-free software.</p>
<p>The chosen vector for replication seems to be <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> and a rather dramatic faux-suicide note &#8211; which sadly I think will be very effective.</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/01/19/mac_linux_bot_vulnerabilities/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3031+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;t=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F01%2Fjava-based-cross-platform-malware-trojan-maclinuxwindows%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Fake Microsoft Patch &#8211; BeastPWS-C</title>
		<link>http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/</link>
		<comments>http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/#comments</comments>
		<pubDate>Wed, 31 May 2006 03:32:08 +0000</pubDate>
		<dc:creator>Tiago Faria</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[BeastPWS-C]]></category>
		<category><![CDATA[fake-patch]]></category>
		<category><![CDATA[gouki]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows-virus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/</guid>
		<description><![CDATA[If you receive a e-Mail alert of a new patch for your Windows XP OS, think again before opening the link present on the message. The spammed emails, which purport to come from patch@microsoft.com, claim that a vulnerability has been found &#8216;in the Microsoft WinLogon Service&#8217; and could &#8216;allow a hacker to gain access to [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>If you receive a e-Mail alert of a new patch for your Windows XP OS, think again before opening the link present on the message.</p>
<blockquote><p>The spammed emails, which purport to come from patch@microsoft.com, claim that a vulnerability has been found &#8216;in the Microsoft WinLogon Service&#8217; and could &#8216;allow a hacker to gain access to an unpatched computer&#8217;.</p></blockquote>
<p>The link on the e-Mail will redirect to a non-Microsoft site where you will download a trojan named <strong>BeastPWS-C</strong>, &#8220;which is capable of spying on the infected user and stealing passwords.&#8221;</p>
<blockquote><p>When first installed the Trojan horse displays a bogus message, which reads: &#8216;Microsoft WinLogon Service successfully patched&#8217;. In actual fact, the malware is secretly logging keystrokes and sending them to an email address belonging to the hacker.</p></blockquote>
<p>Well, I wouldn&#8217;t mind receiving this &#8216;Microsoft&#8217; e-Mail and mail-bomb that looser&#8217;s e-Mail address <em>(yeah, the good old mail-bomb attack still works).<br />
</em></p>
<p>For future reference, people need to remember that Microsoft doesn&#8217;t send hotfixes using attachments and not to deploy this patch on their WSUS servers.</p>
<p></p>
<p><strong>Source:</strong> <a href="http://www.net-security.org/secworld.php?id=4009">NHS</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D221+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;t=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;title=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;title=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;title=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;title=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F05%2Ffake-microsoft-patch-beastpws-c%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

