Slashdot Mirror


Downadup Worm — When Will the Next Shoe Drop?

alphadogg writes "The Downadup worm — also called Conflicker — has now infected an estimated 10 million PCs worldwide, and security experts say they expect to see a dangerous second-stage payload dropped soon. 'It has the potential to infect about 30% of Windows systems online, a potential 300 to 350 million PCs,' says Don Jackson, director of threat intelligence in the counter threat unit at SecureWorks. The worm, first identified in November and suspected to have originated in the Ukraine, is quickly ramping up, and while Downadup today is not malicious in the sense of destroying files — its main trick is to block users from accessing antivirus sites to obtain updates to protect against it — the worm is capable of downloading second-stage code for darker purposes."

36 of 295 comments (clear)

  1. what will it download? by Anonymous Coward · · Score: 5, Funny

    the worm is capable of downloading second-stage code for darker purposes."

    So it might download vista?

    1. Re:what will it download? by hobbit · · Score: 5, Insightful

      while Downadup today is not malicious in the sense of destroying files

      How quaint! The idea that someone might infect millions of PCs just to delete people's files is so 20th century.

      --
      "Wise men talk because they have something to say; fools, because they have to say something" - Plato
    2. Re:what will it download? by Anonymous Coward · · Score: 5, Interesting

      One of the big areas hit by downadup is in the corporate world where PCs are "managed". A lot of those have not been patched and are infected already or probably will be soon. Once it gets a foothold behind a firewall, it uses multiple other strategies to spread - weak passwords, etc.

      In a lot of business environments, deleting files could be crippling because those often times have people who don't back up their files, there isn't really a company policy, etc. It's bad enough when somebody loses a hard drive. Try having everyone "lose their hard drive".

      Another issue is this is the first time I have seen the infection attributed to a Russian-area site. Everywhere else it has been attributed to some one or some group in China.

      Regardless, one of the uses of a botnet is for cyber warfare. In this case the cat is out of the bag and people are watching it closely to see what it is going to do. But if the people who built this are sophisticated enough, or maybe this one spreads laterally and more stealthily than people have yet noticed, it could have a real purpose much more sinister than just deleting files or snagging myspace passwords. Downadup could also just be a decoy.

      It's been said that the first clues that war is coming will be people's computers not working properly as infrastructure and services are knocked out. Anyone starting a war will want a crushing first blow and taking out files, doing DDoS, etc, would be typical.

      Not trying to scaremonger but obviously this thing is illicit and almost guaranteed malicious. It would be naive to disregard a government's hand in it.

    3. Re:what will it download? by Zadaz · · Score: 4, Insightful

      Well of course deleting files could be crippling. Which is exactly why it would be a stupid thing for a hull breach app to do.

      A modern virus/trojan/worm/etc doesn't want to be noticed. It wants to be an available node to be sold to the highest bidder. Just like a biological virus it can't spread if it kills or incapacitates its host.

      Deleting files was something a virus did back in the 80's because hackers didn't have much imagination. That's not to say a terrorist organization couldn't buy the next payload and send out a "secure reformat on boot" app, but it would be a massive waste of a resource (a massive botnet is incredibly powerful/valuable tool not to be thrown away) and a foolishly indiscriminate target, even for terrorists. In any case they'd have to outbid the ordinary criminals who want it to spam, hijack, DoS, keylog, skim and blackmail.

      ...[This] is the first time I have seen the infection attributed to a Russian-area site.

      You really don't get out much, do you.

  2. And now we rediscover by causality · · Score: 5, Funny

    And now we rediscover why monocultures don't work (and are generally not found) in nature.

    --
    It is a miracle that curiosity survives formal education. - Einstein
    1. Re:And now we rediscover by Dzimas · · Score: 4, Funny

      Hmm. Are you alluding to the dominance of computers or humans?

    2. Re:And now we rediscover by Anonymous Coward · · Score: 3, Funny

      Your mac, like all other macs, will die of extinction because of its stubborn refusal to eat meat and mate with the opposite sex. And if that ain't enough, when Mama Jobs dies, all Macs will also die.

  3. its not hard by madcat2c · · Score: 5, Informative

    Use a hardware router, use a real anti-virus program that actually publishes updates everyday (Nod32 for me), and use a browser where you can kill anything that tries to auto install itself (firefox, chrome, etc).

    And don't forward or respond to chain emails!

  4. You'll All Thank Me by hksdot · · Score: 5, Funny

    You'll all thank me when I deploy the second stage to install and run SETI@home and discover alien intelligence.

    -Virus Author

    1. Re:You'll All Thank Me by philspear · · Score: 4, Funny

      that then comes and kills us all before we advance enough to be a threat to them.

      Right before that would happen, he'll deploy "stage three" by handing the aliens a USB drive...

  5. Keep spreading lies by Anonymous Coward · · Score: 5, Funny

    Windows is actually far more secure than Linux. Get the facts, people.

    1. Re:Keep spreading lies by Anonymous Coward · · Score: 3, Informative

      Yeah as if a Microsoft website isn't going to show a bit of one-sidedness and in doing so leave out a metric ton of facts that don't exactly keep their product at best interest.

    2. Re:Keep spreading lies by Anonymous Coward · · Score: 4, Informative

      I prefer this site, its facts are far more accurate ;-)

      Don't click that link!

    3. Re:Keep spreading lies by Anonymous Coward · · Score: 5, Informative

      Be warned - in case you are tempted...

      This is a pretty ingenious script that

      • Opens up windows (or tabs, depending on how you open the link) as fast as your computer can - 100% CPU
      • Each window displays gay porn
      • Plays a loud sound "Hey everybody I'm looking at gay porno"
      • Behind the scenes it also copies the contents of your clipboard to this guy.

      It works in IE and firefox. It is simply a page with an image, a flash movie, and a javascript that copies your clipboard to a field then 'submit()'s' the form, reloading the page.

      Very simple and bypasses popup blockers (at least the ones I have on).

      This has got to be a security hole in firefox, both on the ability to open windows/tabs, and copying the clipboard.

      If you want to have a look, use:

      wget http://getthefacts.on.zoy.org/index.php

      WARNING: dont click on this link, just copy the wget command to a shell. Dont say I didn't warn you...

    4. Re:Keep spreading lies by Penguinshit · · Score: 4, Funny

      It's a dickroll...

    5. Re:Keep spreading lies by jesser · · Score: 4, Insightful

      Firefox doesn't let web sites access your clipboard directly. Flash does. The Flash guys consider it a feature, while the Firefox guys consider it a security hole in Flash (or at least I do).

      I bet the site is using Flash.

      --
      The shareholder is always right.
    6. Re:Keep spreading lies by lordsid · · Score: 3, Insightful

      I don't know where you guys get your information but its pretty easy to access the clipboard from javascript even in firefox.

      Try searching for "javascript clipboard functions" the first link gives an example. All he would have to do is paste the content into a hidden div and wait for it to resubmit itself.

      --
      IMAGE VERIFICATION IS EVIL!
    7. Re:Keep spreading lies by danwesnor · · Score: 4, Funny

      Free porn? SWEET!

    8. Re:Keep spreading lies by NeverVotedBush · · Score: 5, Insightful

      The both of you should probably add "that you know of".

      The reality is that Linux boxes are highly prized. Their owners frequently have high speed connections and Linux can do all sorts of fun things.

      Linux isn't perfect. There have been any number of security issues that would allow a knowledgeable hacker easy access. It all depends on if you kept your systems up to date and patched, didn't set up and allow unnecessary services, had a good firewall policy with a default deny/drop stance, etc.

      Linux comes out of the box now pretty secure but it hasn't always. And individual user habits can also compromise a system. Add to that the fact that one of the big ways into a system now is through add-on things like flash and such, and the knowledge that there have been kernel bugs that let user applications get root with a single command (things like vmsplice), and there is a possibility that your Linux boxes are rooted and you just don't know it.

      For the record, I run Linux almost exclusively and am no fan of Windows. But people need to understand that just running Linux is not a guarantee of safety. I'm also not questioning your capabilities. It's just that blanket statements about Linux security should probably be qualified.

    9. Re:Keep spreading lies by nog_lorp · · Score: 3, Informative

      I don't know where you get your information, but

      Error: document.getElementsByTagName("textarea")[0].createTextRange is not a function
      Source File: javascript:%20document.getElementsByTagName("textarea")[0].focus();%20alert(document.getElementsByTagName("textarea")[0].createTextRange());%20void(0);
      Line: 1

      Yah know why? Because "Firefox doesn't let web sites access your clipboard directly. Flash does. The Flash guys consider it a feature, while the Firefox guys consider it a security hole in Flash"

    10. Re:Keep spreading lies by ozmanjusri · · Score: 5, Insightful
      They know to keep Windows up to date and run a scan at least once a week for any suspicious. They've also learned to not click on every fool link there is just because they can.

      Why bother?

      Linux is free, and it's easier to learn Linux than how to keep Windows clean.

      --
      "I've got more toys than Teruhisa Kitahara."
    11. Re:Keep spreading lies by Spit · · Score: 5, Insightful

      A better counter is not to click links posted by anonymous idiots.

      --
      POKE 36879,8
    12. Re:Keep spreading lies by mlwmohawk · · Score: 4, Informative

      Linux isn't perfect. There have been any number of security issues that would allow a knowledgeable hacker easy access.

      Depending on the methodology of access this is potentially true. There are philosophical differences between the development of Linux, BSD, and Windows.

      I've been around the industry for a while and I have seen first hand the systemic differences. At Microsoft, things like adding executable code to TIFF images and metafiles is neither challenged nor audited. On Linux and FreeBSD the developers wouldn't even dream of doing something idiotic like that, and even if they do, there are legions of people who will scream bloody murder.

      Then there is the nefarious code purposefully put into Microsoft's proprietary code. Be it the NSA key, WGA, or other methodologies of accessing machines remotely. If these systems are in Windows, they WILL be exploited by external entities.

  6. Why is it.. by zmollusc · · Score: 4, Funny

    .. that I can't get windows apps to do what i want without crashing, but it runs teh evil viruses perfectly?

    --
    They whose government reduces their essential liberties for temporary security, receive neither liberty nor security.
    1. Re:Why is it.. by nathan.fulton · · Score: 5, Insightful

      ".. that I can't get windows apps to do what i want without crashing, but it runs teh evil viruses perfectly?"
      Because there is a 100% correlation between a virus crashing and a virus writer's lost profit. With most legitimate software, a crash leaves only one practical option: keep using the crapware and hope it doesn't crash again.

  7. Re:Spyware, Adware, Antivirus, Don't use IE, Use a by Computershack · · Score: 3, Informative

    When will Windows be ready for the desktop? Srsly.

    Microsoft patched this and issued the fix through Windows Update a month before the worm was even in existence. It's only stupid fucks who don't update their OS that've got infected.

    --
    I only please one person per day. Today is not your day. Tomorrow isn't looking good either. - Scott Adams
  8. Could it be hijacked... by TexVex · · Score: 3, Interesting

    If this thing is a malicious software delivery system, wouldn't it be possible to hijack it and have it download something that removes it?

    --
    Fun with Anagarams! LADS HOST, SHALT DOS. HAS DOLTS. AD SLOTHS, HATS SOLD. ASS HO, LTD.
    1. Re:Could it be hijacked... by upuv · · Score: 3, Interesting

      Aside from the potential protections the virus may have for this.

      White hats have a few extra rules to contend with. Since going into someones computer and changing stuff without there approval is illegal in most parts of the globe the white hats would be just as guilty as the virus writer.

      God forbid the white hat actually makes a mistake and the cure is worse than the disease. An analogous problem occurred when Sony installed a root kit that prevented people from breaking the law. Sony thought it was protecting it's IP rites. What really happened was that Sony effectively gave complete and total access to any one who wanted to do stuff on the computer. Sony got slapped hard for this and it cost them a bundle. Many people lost there jobs and the damage to personal computers around the world was rather staggering.

      So it's not as simple as someone taking over the comms with the virus and sending back clean up routine.

      ----
      As an aside. If or when the world comes to accept that white hats are allowed to attack virus in this manor we will see an almost instant response from the virus writers.

      A double payload mechanism would be very effective for example.
      1. Virus infects.
      2. 2nd payload is delivered and hides in stealth.
      3. white hat antivirus clears first virus. As it would take time for the aggressive anti virus to be written. The 2nd payload could easily be delivered well in advance of the white hat action.
      4. 2nd payload is now on the hardware with no need to talk to command and control.

      That is just one possible vector change that would appear.

      ----

      More likely is that if white hats where given the go ahead to attack. The "Bad guys" would simply move to the next soft target. I suspect the next soft target to be the vast numbers of networked devices that are multiplying all running Linux variations. Also since next to no one ever updates the firmware on these appliances once vulnerable they will remain for ever vulnerable.

      ----
      So in the end no it's a BAD idea for the white hats to aggressively attack these things. It's an arms escalation that we simply don't need.

    2. Re:Could it be hijacked... by arkhan_jg · · Score: 3, Informative

      According to this analysis, the writers anticipated the daily domain-generation algorithm it uses to check for updates being reverse engineered, and they put in additional protection so that it would only download code from the original authors - presumably using some kind of key signing.

      --
      Remember kids, it's all fun and games until someone commits wholesale galactic genocide.
  9. Re:The sick truth. by couchslug · · Score: 4, Funny

    "If we were a proper country like Soviet Russia they would get the Siberian wolf blowjob by now."

    Thanks to the internet, not only do I know that for some people that would not be a punishment,
    but that others wish they were the wolf.

    --
    "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
  10. Technical examination by Prune · · Score: 5, Informative
    --
    "Politicians and diapers must be changed often, and for the same reason."
  11. Microsoft... by ConceptJunkie · · Score: 4, Insightful

    "From where do you want to get pwned today?"

    It's 2009... I can't believe we're still dealing with this crap in 2009.

    --
    You are in a maze of twisty little passages, all alike.
  12. A small niggle... by rickb928 · · Score: 3, Interesting

    But it's "Ukraine", not "The Ukraine".

    At least, that's what Ukrainians say.

    Just sayin... And that's what the Ukrainian rocket scientist I know says also.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  13. Complacency is a disease by David+Gerard · · Score: 4, Funny

    A computer worm that spreads through low security networks, memory sticks, and PCs without the latest security updates is posing a growing threat to users blitheringly stupid enough to still think Windows is not ridiculously and unfixably insecure by design.

    Despite many years' warnings that Microsoft regards security as a marketing problem and has only ever done the absolute minimum it can get away with, millions of users who click on any rubbish they see in the hope of pictures of female tennis stars having wardrobe malfunctions still fail to believe that taking Windows out on the Internet is like standing bent over in the street in downtown Gomorrah, naked, arse greased up and carrying a flashing neon sign saying "COME AND GET IT."

    Microsoft cannot believe people have not applied the patch for the problem, just because they keep trying to use Windows Genuine Advantage to break legally-bought systems. "Don't they trust us?" asked marketing marketer Steve Ballmer.

    Millions of smug Mac users and the four hundred smug Linux users pointed and laughed, having long given up trying to convince their Windows-using friends to see sense. "There's a reason the Unix system on Mac OS X is called Darwin," said appallingly smug Mac user Arty Phagge.

    "It can't be stupid if everyone else runs it," said Windows user Joe Beleaguered, who had lost all his email, business files, MP3s and porn again. "Macs cost more than Windows PCs."

    "Yes," said Phagge. "Yes, they do."

    Ubuntu Linux developer Hiram Nerdboy frantically tried to get our attention about something or other, but we can't say we care.

    --
    http://rocknerd.co.uk
  14. It simply does not matter! by erroneus · · Score: 4, Insightful

    It doesn't matter how bad and unsafe Windows is. Microsoft Windows is like the air. People are going to keep breathing it no matter who farted in the room. People live in the most polluted places because that's where they live, that's where they work, that's where they play. I could tell you all day long about this other place... with clean air, that's safe, that's stable and all that... and most people might be intrigued but very few will vacation there and even fewer will actually move there. This is how people work.

    Linux needs an Apple logo before the masses will move to it.

  15. Remove the link then. by HoppQ · · Score: 3, Insightful

    If you're warning against clicking the link, don't include it in your own post. Thank you.

    --
    My sig will be released in 2015 third quarter. Rating pending.