Original URL: http://www.channelregister.co.uk/2007/05/08/usb_worm/
Miscreants have created a strain of malware which uses memory sticks as a vector for infection.
The SillyFD-AA worm (http://www.sophos.com/virusinfo/analyses/w32sillyfdaa.html) spreads by copying itself from infected machines onto removable drives such as USB memory sticks before automatically running when the device is next connected to a computer.
The malware, which is also capable of spreading through shared floppy discs, creates a hidden file called autorun.inf that ensures the malware is activated the next time infected media is plugged into a Windows PC.
Infected machines are easily recognised. The title of Internet Explorer windows on infected Windows machines is changed (http://www.sophos.com/pressoffice/news/articles/2007/05/usbstick.html) to include the phrase "Hacked by 1BYTE". In both its mode of infection and its lack of profit-driven motive, the SillyFD-AA worm is a throwback to the days when viruses were written for kudos rather than as part of some money-making scheme.
Net security firm Sophos predicted that the growing use of USB drives in direct mailshots and as freebies at trade shows would make them a growing vector for attack.
"With a significant rise in financially motivated malware it could be an obvious backdoor into a company for criminals bent on targeting a specific business with their malicious code," Sophos senior technology consultant Graham Cluley warned.
Firms should disable the autorun facility of Windows so removable devices such as USB keys and CD ROMs do not automatically launch when they are attached to a PC. In addition, any storage device should be checked for viruses and other malware before use. ®
Gates' spontaneity highlights IE data gap (10 December 2007)
http://www.channelregister.co.uk/2007/12/10/gates_ie8_fire_drill/
Pinch-bum malware creates titters (30 August 2007)
http://www.channelregister.co.uk/2007/08/30/cheeky_trojan/
Memory sticks top security concern for firms (11 May 2007)
http://www.channelregister.co.uk/2007/05/11/memory_sticks_security_concern/
Rivals dismiss MS Forefront security push (3 May 2007)
http://www.channelregister.co.uk/2007/05/03/ms_forefront/
VXers push small coc Trojan on unwilling world (2 May 2007)
http://www.channelregister.co.uk/2007/05/02/small_trojan/
Hackers debut spam and virus sandwich (26 April 2007)
http://www.channelregister.co.uk/2007/04/26/spam_malware_convergence/
Hackers debut malware loaded USB ruse (25 April 2007)
http://www.channelregister.co.uk/2007/04/25/usb_malware/
Attackers improve on JavaScript trickery (20 April 2007)
http://www.channelregister.co.uk/2007/04/20/javascript_obfuscation_attacks/
Adware poses as ActiveX control (17 April 2007)
http://www.channelregister.co.uk/2007/04/17/adware_activex_control/
Zombies infiltrate US military networks (16 April 2007)
http://www.channelregister.co.uk/2007/04/16/military_botnet/
© Copyright 2008