Bernhard Warner
Download your 2 for 1 Pizza Express voucher
For the second time in the past two months, a nasty new computer threat has quietly spread across the web infecting countless computers with a key-logging Trojan. Bank log-ins, PIN codes and credit card details are among the booty this piece of malware is designed to Hoover up.
What makes it so worrisome is the target: it’s infecting popular websites – 10,000 at the last count, but the number could be ten times that – according to new research by network security specialists at Finjan.
This technique of creating a minefield of infected websites that can ensnare unsuspecting surfers first emerged in late 2007. In that case, hackers temporarily turned high-profile sites belonging to the likes of The Economist and Major League Baseball into traps. A primary link to the outbreak, it was determined, was DoubleClick, the ad-serving specialist that Google is in the process of acquiring. Unbeknown to DoubleClick, the company was serving up not just banner adverts, but specially designed malware as well. The intrusion was identified and eradicated, and now DoubleClick does an extra scan of its inventory to ensure it’s only sending out adverts.
Still, the genie, it was feared then, was out of the bottle. And sure enough the latest method of installing malware on legitimate websites also involved infiltrating an ad-serving firm that serves up more than two million banner ads per day, Finjan researchers reported. (Not all of the 10,000 known infections stemmed from this ad-serving specialist, Finjan points out. Their researchers still don’t know how the remaining sites fell prey to the malware).
Finjan will not say who the ad-targeting firm is, but the firm says the victimised company is in the process of ridding the contagion from its servers. It does name two other infected sites, which illustrate the indiscriminate approach this contagion takes to infiltrating its hosts. One of the victims was the University of California, Berkeley; the other is a popular computer gaming site, Teagames.com, Finjan says. (They named these two companies out of a list of 10,000 because they quickly combed through their servers and removed the malware. There are thousands more that are in the process of doing the same.)
The malware – dubbed “random jsrootkit” by Finjan – has been ingeniously designed. The payload – in essence, the key-logging Trojan – is encrypted, making it virtually undetectable for just about all antivirus scanners. For an added level of cover, the random jsrootkit constantly changes names every time it embeds itself inside an infected host. The aim of creating so many calling cards is to circumvent being placed on a malware blacklist. For good measure, it is programmed to infect a computer user just once, again to avoid triggering any red flags among malware sentinels.
“This is a very smart program,” Yuval Ben-Itzhak, chief technology officer of the San Jose-based IT security firm, says. It’s really trying to fool everybody and hide itself from everything that is out there today in the anti-virus market.
“The goal for these hackers is to have the malicious code up and running for as long as possible so they can continue to infect machines and collect information,” Mr Ben-Itzhak says.
It’s the primary difference of today’s hacking scourge: the stealthy approach is more valuable to crime gangs who can quietly bide their time and collect as much detail as they can before detection. It has given rise to a new name in security circles: malware as “crimeware”.
The biggest problem with fighting crimeware of this nature is that we are armed with the wrong kind of defence. Antivirus software is designed to identify and quarantine known threats, but constantly morphing Trojans, or worse, ones with encrypted payloads, will slip through filters nearly every time.
This is beginning to generate a new discussion in network security circles about how best to fortify internet users and websites from these types of intrusions. The conclusion many are drawing is that antivirus software is simply not enough, a worrying sign when you consider that so many personal computers continue to run without any type of antivirus software at all.
While security experts debate the best approach, you can be sure the crimeware gangs will be busy too, developing yet another sneaky piece of code that quietly slips by our defences and bides its time until its master instructs it to go to work.
---
Bernhard Warner, a freelance journalist and media consultant, writes about technology, the internet and media industries. He can be reached at techscribe@gmail.com
Industry sectors news at a glance. Interactive heatmap, video and podcast
Get ready for the winter sports season, with our resort guides and snow reports
We are backing British business, what is the confidence of the nation and what businesses are succeeding?
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
2006/06
£POA
Surrey
2009
£114,950
Derbyshire
The best policy at the
best price
Be Wiser Insurance
£POA
Surrey
Highly competitive six figure
Nationwide
Swindon
Competitive benefits package
Chartered Institute of Builders
Ascot
Competitive salary + benefits
NHS Direct
London
£125K
Meltwater News
Nationwide Positions
With Part Exchange Crest Nicholson could get you moving.
Award-winning riverside development, SW11.
Luxury apartments for sale from £350,000.
Find out more about our luxurious apartments and houses for sale in the heart of Sussex.
for sale in the French Alps
from E189,000.
We're offering extra savings on Voyager & Adventure of the seas Mediterranean Cruises fr £549.
Book by 28 Feb!
Includes 3* accommodation throughout, a 15 minute Apollo night helicopter flight down the Las Vegas strip and United Airlines flights from Heathrow.
Same break by air costs £189. Valid for weekend travel until 31 Aug 10.
Get covered on your travels with a superb range of policies at great prices
Visit InsureandGo.com
Family friendly villas with Quality Villas. Book with the specialists.
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Milkround
Copyright 2010 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.