AutoCAD Worm Medre.A Stealing Designs, Blueprints
Trailrunner7 writes, quoting Threat Post: "Security researchers have come across a worm that is meant specifically to steal blueprints, design documents and other files created with the AutoCAD software. The worm, known as ACAD/Medre.A, is spreading through infected AutoCAD templates and is sending tens of thousands of stolen documents to email addresses in China. However, experts say that the worm's infection rates are dropping at this point and it doesn't seem to be part of a targeted attack campaign. ... [They] discovered that not only was the worm highly customized and well-constructed, it seemed to be targeting mostly machines in Peru for some reason. ... They found that ACAD/Medre.A was written in AutoLISP, a specialized version of the LISP scripting language that's used in AutoCAD."
Because it's written in LISP.
also most Autodesk software needs local admin to run right or at least the older ver of it did.
It's just sharing. Information wants to be free! Remember?
My company uses the comparitively archaic Microstation! Victory at last!
That it's finally expanded into the virus industry!
Why else would they take their designs?
It makes cloning villages much eaier if you have the blue-prints.
I bet these guys http://idle.slashdot.org/story/12/06/22/0022251/china-pirates-austrian-village would have loved the blue-prints before they started
. .
It's been known for many years that China is engaging in wide-scale corporate cyber-espionage. Anyone who got caught by this deserves what they got.
I'm sorry I no longer have the link handy, but Chinese nationals caught performing in-person corporate espionage in various countries have admitted straight out that such espionage is a top priority of the government there. It funds stays abroad and you are expected to "bring something back" to China when you return. That's not to say they all do it - lots of them are honest and intentionally return worthless data or otherwise subvert the intent. But also, lots do it too, and it's really easy any more now that we have multi-gigabyte micro-SD cards. Combined with the cyber-espionage, China is finding shortcuts to go from an agrarian society just a generation ago, to competing with the best technology from the west and Japan. That might not be a bad thing, either - increases their standard of living for instance and helps with the problems they had formerly with widespread starvation.
Anyway point is this should not be a surprise to ANY western company.
Just arrest all LISP programmers and beat them up until they talk. There aren't many anyways.
...And the information that wants to be free the most is who wrote it, why, and where they live.
Then some angry engineers with metal meter-sticks and such want to share some kinesthetic/tactile information with the perpetrator. At length. (Precisely measured.)
I think the best thing to do would be to flood those addresses with AutoCAD blue-prints of the Tibetan flag.
You see, we were using AutoCAd to design this Moon based "LASER" called the Allen Parson's Project.
This "LASER" and its subsequent installation was designed on AutoCad. I can't really state what I - er, - We were going to do with this "LASER" . All I can say it that the Chinese now have it.
I'd also like to report that a whole tankful of Sharked - with let;s say "devices" - strapped to their head have gone missing.
That is all,
S. Evil; MS (I haven't gotten my doctorate yet,) Bwahahahahahahhahahahah! AHAHAHAHAHAHAHAHAHHAAHHAHAH@! AHHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAAHAH!
I'm SHOCKED that Chinese email addresses seem to be involved. SHOCKED... and we will continue to do business with these lying cheating bastards who are waging economic warfare with the US until we send our last dollar there.
BUT AMERICA!!! (AS ALWAYS...)
I thought so !!
use the email addresses to send flawed data to china so they end up trying to build impossible things like what is found in Escher's drawings
Politics is Treachery, Religion is Brainwashing
Well my copy of 2012 does, otherwise it won't work at all. I don't know if 2013 does. Maybe someone who's company has sprung for the new version can chime in. Nothing like "gaping ass wide security hole" to make your day is there? Err never mind...that could probably lead to a 13 year old joke.
Om, nomnomnom...
A brand new install of Autocad costs $3,995 and up. It produces files that have a distinctive extension, making them easy to identify and to tell from other types of documents without even having to examine internal code. Any file produced by a legal autocad install was made by somebody who paid serious money to be able to do so. Ergo, if someone can harvest a thousand Autocad files at random, a high proportion of them will be of valuable, useful stuff.
Fighting warez sites distributing Autocad means, if the company is successful, a higher percentage of the documents made with it will be the valuable stuff. At 4K a legitimate copy, actually stopping a high percentage of 'pirates' means increasing the danger to your own legitimate users.
If going through 10,000 autocad documents means finding, say, a dozen new patent filings and diagrams, two trade secret process designs for million dollar product lines, a few archetectural blueprint packages, and such, it becomes worth a government paying a programming team to write the software and putting three or four fulltime engineers and a few technicians on just evaluating those documents for the 'good' ones. If there were a thousand bootleg copies of the software for every legitimate one, that government might not bother to go through 10 million documents for about the same haul, as most of the bootleg copies won't be producing anything worth that much.
Who is John Cabal?
I'm going to ball CS, I install Autocad for many of my customer's users, and I haven't needed to give them admin privileges since version 2007 I think.
If he explores all forms and substances Straight homeward to their symbol-essences; He shall not die.
Run it in a VM, using a fresh VM image before each use.
Or does AutoCAD have some horrible DRM system that would get in the way of that approach?
Palm trees and 8
Revit doesn't. At least 2010, 2011, 2012 and 2013 haven't.
But then they will be building the impossible while we only build the possible. They will have assumed that we have working Poiuyts and attempt to build them themselves, not knowing that they don't work. The biggest problem in not getting something done is assuming it can't be done. The Chinese will assume it can be done, and do it.
We will then be having generals and captains of industry bemoaning the Poiuyt Gap, which must be closed and we will spend trillions building Poiuyts.
--
BMO - What, me worry?
auto cad needs a better then video card what most vm have. Also can use a lot of cpu power.
Option 2 for the win
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
Well for us 2012 does not seem to need admin to run; although you need to run as admin once to do the performance optimization/video card thing.
what the chinese will mostly get is many, many house floorplans, elevations and relfected ceiling plans
"Security researchers have come across a worm that is meant specifically to steal .. files created with the AutoCAD software. The worm, known as ACAD/Medre.A, is spreading through infected AutoCAD templates .. ACAD/Medre.A was written in AutoLISP, a specialized version of the LISP scripting language that's used in AutoCAD".
Does this 'worm` run on any other system except Microsoft Windows?
AccountKiller
If you are infected with this, please please make bogus plans for exotic weapons, marital aides and artistic expressions.
Please salt those wounds!
http://www.aisnota.com/slashdot/ Welcome to Logic and the Future
LISP is not a scripting language.
-------
My other car is a cdr.
If it can steal blueprints, that is one sophisticated piece of software. It would have to fold them, stuff and seal envelopes, calculate and affix postage and deposit them in the outgoing mail. Wow!
"Computers are useless. They can only give you answers."
-- Pablo Picasso
It used to. I still have a dongle for the way overpriced student version that was still crippled in other ways.
Hello,
Somewhat surprised to see that the original research on the worm by ESET has not been mentioned yet on Slashdot. For all those who are interested, here it is:
From speaking with some of the ESET folks involved in the above, it seems there may be additional details forthcoming.
Regards,
Aryeh Goretsky
Dexter is a good dog.
Maybe it's just some local corporate espionage using Chinese mailboxes to cover their tracks.
also most Autodesk software needs local admin to run right or at least the older ver of it did.
AutoCAD 2013 (and 2012, and at least a few more versions back) run fine without admin rights. It helps to have write permissions opened up on various AutoCad folders (Program Files\AutoDesk, ProgramData\Autodesk, etc.) to allow for customization, but the application will run fine. Admin rights are only needed at the time of initial installation.
This is why I buy ESET products. :P
- Satisfied Enterprise ESET Customer... even if ERAC sucks
The original sin was allowing by design programs and operating systems to connect to distant sites to re-validate license keys and download files, however clever it may have seemed at the start. Regardless of what kind of firewalls and other protections we may have put in place, this feature provides a built-in backdoor to be exploited by anyone. And with much of this, the user has little control over who accesses their system. This kind of software promiscuity at the design level needs to be curtailed.
I cannot remember any version of AutoCAD (and I am started administrating AutoCAD systems from version 10) needing local admin rights to run. AutoCAD has been one of the few apps to support non-admin users as soon as windows enabled that feature (windows NT3.5 anyone?). Only if you seriously mess up your AutoCAD settings inside your user profile or the registry will this happen. Of course you're messing with those if you don't pay for the software you use...
Hello,
Somewhat surprised to see that the original research on the worm by ESET has not been mentioned yet on Slashdot. For all those who are interested, here it is:
From speaking with some of the ESET folks involved in the above, it seems there may be additional details forthcoming.
Regards,
Aryeh Goretsky
Thanks for this..up until your post I actually thought it was called Merde.A...
blindly antisocialist = antisocial
A friend of mine told me about a studio he worked for where they got explicit permission from Autodeks to use cracks for Maya so they wouldn't have to deal with the copy protection.
They mention that the SMTP relay that the Malware was reporting to has now been shut-down, after contacting the service provider.
Nice one ESET.
I checked the technical analysis document: the file involved is a fas file, that is compiled lisp. It's called acad.fas , maybe this increases the chances it gets executed automatically. The source in this case a mixture of vbs and lisp,probably the lisp file writes vbs scripts.
I think it can be made by a single person.
Yes, an acad.fas file next to a drawing will be loaded automatically if you open the drawing by doubleclicking on it.
This is not the first time AutoCAD has been hit. If I remember correctly, this problem also had some links to China. http://usa.autodesk.com/adsk/servlet/ps/dl/item?siteID=123112&id=13717811&linkID=9240617
you see, we actually WANT you to share blueprints and designs.