Security Information

Three-pronged Trojan Attack Threatens Security on the Internet


Glieder (Win32.Glieder.AK), Fantibag (Win32.Fantibag.A) and Mitglieder (Win32.Mitglieder.CT) are not names of a modern day version of The Three Musketeers. These are Trojans engineered for a hacker attack that will infect computers and open them for use in further attacks.

"Combating computer viruses is essentially a game of hide and seek," says Govind Rammurthy, CEO, MicroWorld Technologies, among the leading Security Solutions providers. "Hackers riding piggyback on viruses have only a short window of opportunity to maximize their gain before the viruses are detected, neutralized and logged into Virus Definition databases, 'vaccinating' the system against those strains.

Without continuing system vulnerability caused by virus infection there is little they can do to further their malicious ends like stealing personal information, credit card details and other sensitive and vital data. To achieve their ends they need to keep the system vulnerability going for more time. This co-ordinated Trojan threat is an attempt to the keep that 'backdoor' open, essentially buying time," he concludes.

Of the three, Glieder leads the initial charge. It sneaks past anti-virus protection to download and execute files from a long, hard-coded list of URLs and "plant" the infected machine with "hooks" for future use. On Windows 2000 and Windows XP machines, it attempts to stop and disable the Internet Connection Firewall and the Security Center service (introduced with Windows XP Service Pack 2). Then the Trojan accesses the URL list to download Fantibag. The way is now paved to launch the second stage of attack.

Sulabh, a tester with MicroWorld Technologies says of Fantibag, "Now Fantibag goes about attacking the networking feature of the infected system to prevent it from communicating with anti-virus firms and denying access to the Microsoft Windows Update site. It closes your escape route by making it impossible to download an anti-virus solution and any subsequent Windows security patch to your system. Effectively it helps Mitglieder (the third stage Trojan) open the 'backdoor' by shutting the other doors on you."

Mitglieder puts the system under complete control of the attacker by opening the 'backdoor' on a port using which the attacker can update the Trojan, to stay a step ahead of attempts to remove it, download and execute files, initiate an SMTP server to relay spam, execute files on the infected computer and download and execute files via an URL. "This is what makes it scary," say Aarti, Assistant Manager, QA, MicroWorld Technologies. "The fact that the system can now be used as a remote controlled 'soldier' (bot) in an army (botnet) of similarly compromised machines to launch criminally motivated attacks, causing harm to Internet users."

Botnets thus formed can among other things, use your machine to launch Distributed Denial of service attacks which overload servers, making them crash, to send out spam, spread new Malware, plant Keylogger to retrieve your personal information like identity, passwords, account numbers etc., install Spyware, manipulate online polls/games, abuse programs like Google AdSense to cheat advertisers of revenue, and install Advertisement Addons for financial gain as in fake websites advertising services that don't exist.

"Botnets can even encompass over 50,000 host machines. The potential for mischief is huge," reflects Govind Rammurthy. "Such a three-pronged Trojan attack where attackers change their virus code and release viruses quickly to bypass virus signature scanners, then disable network access to deny the user link-ups to anti-virus and Microsoft Windows Update site for protection has huge significance for virus-signature based protection. It is a sign of things to come," he says, remembering the scramble at MicroWorld labs to update their products to detect and remove the three Trojans.

Anti-virus updates for the three-pronged Trojan threat are available at MicroWorld Technologies site. Maybe the time for worrying about some pimply teenager turning out malicious code because they have nothing better to do on a nice sunny morning, is over. The world could be facing a determined organized crime syndicate who'll stop at nothing to get what they want - information precious to you.

MicroWorld Technologies is one of the leading solution providers for Information Technology, Content Security and Communications Software. MicroWorld has established itself as a leader in providing content security, anti-virus and corporate communications software solutions.


MORE RESOURCES:

eFluxMedia

Top immigration official outlines security database changes
Chicago Tribune, United States - 8 hours ago
AP CHICAGO - A top US Immigration official says it's necessary to increase fees to fund a security database that tracks foreign students. ...
Video: ICE Agents Raid Meat Packing Plant AssociatedPress
US: Nearly 400 immigrant workers arrested in slaughterhouse raid World Socialist Web Site
Iowa immigration raid is largest in US history Arizona Republic
Waterloo Cedar Falls Courier - Kansas City Star
all 648 news articles


Mock attack defeats lab security
San Jose Mercury News,  USA - 3 hours ago
By SCOTT LINDLAW AP Writer SAN FRANCISCO—Mock terrorists defeated security personnel in a recent drill at Lawrence Livermore National Laboratory, ...


Malaysia Star

'Iran will not give up enrichment'
Jerusalem Post, Israel - 1 hour ago
Iranian President Mahmoud Ahmadinejad "is quite prepared, as is the rest of the leadership, to ignore the various security council resolutions that require ...
Iran Won't Negotiate Its Lawful Atomic Energy Rights Bernama
US: Iran proposals not to settle woes PRESS TV
5+1 should revise views on Iran: MP Tehran Times
IranMania News - Antiwar.com
all 254 news articles


CTV.ca

Harper Must Answer Canadians’ Questions on National Security
Liberal.ca (press release), Canada - 7 hours ago
Prime Minister Stephen Harper must assure Canadians that all possible security checks were followed with regard to the latest gaffe of Minister of Foreign ...
Security Check On Port Workers Tighter Than That For Cabinet Members AHN
Port workers and their spouses face more scrutiny than cabinet ... Globe and Mail
Bloc calls for Bernier security probe Toronto Star
The Canadian Press - Globe and Mail
all 371 news articles


AFP

US: Security Council should address Lebanon fighting
AFP - 3 hours ago
ABOARD AIR FORCE ONE (AFP) — The United States is expecting the UN Security Council to take action next week on the issue of unrest in Lebanon, ...


AFP

US expects little from Iran on world problems
AFP - 5 hours ago
Iran must in any case yield to UN Security Council resolutions, which demand it halt the enrichment of uranium, McCormack added. ...
Iran says puts package of proposals to EU's Solana Reuters UK
Iran will not halt uranium enrichment: envoy Tehran Times
US declines to help present nuclear deal to Iran International Herald Tribune
The Associated Press - AFP
all 154 news articles


Security Officer
Seattle Times, United States - 4 hours ago
The role of the Medical Center Security Officer is to assure a safe and secure environment for the patients, visitors, staff and property of Swedish Medical ...


Eruces gains US patent for security software
Bizjournals.com, NC - 8 hours ago
A Lenexa-based software company has garnered its first US patent for its data security software. The US Patent and Trademark Office granted Eruces Inc. a ...
ERUCES Awarded US Patent for its Cryptographic Key Management Emediawire (press release)
all 9 news articles


Canada.com

Security Council strongly condemns rebel attack near Khartoum
International Herald Tribune, France - 3 hours ago
AP UNITED NATIONS: The UN Security Council on Tuesday strongly condemned the rebel attack near Khartoum, warning against any retaliation and urging Sudan ...
UN Security Council condemns rebel attack on Khartoum Xinhua
Security Council condemns JEM attack against Sudan’s govt Sudan Tribune
Security Council slates weekend attacks by Darfur rebels near ... UN News Centre
Monsters and Critics.com - International Herald Tribune
all 2,354 news articles


Seagate Secure(TM) Self-Encrypting Laptop Hard Drives Earn ...
FOXBusiness - 15 hours ago
NSTISSP No.11 defines requirements for a wide variety of products that "satisfy a diversity of security requirements to include providing confidentiality ...
Wave Q1 2008 Revenues Rose 32% to $1.7 Million on Continued Growth ... Business Wire (press release)
all 14 news articles

Security - Google News

home | site map

Visit our other sites:
GamesBlog | GamingDepot | GimmeaRide | GimmeNetwork | Golf Biz | HotorNotGame | I Want Computers | I Want Games | I Want Hosting | I Want Music | I Want Security | JokeBox | ScriptShock | Wantedfonts | Webalize
© 2006