Crisis Trojan Makes Its Way Onto Virtual Machines
Trailrunner7 writes "The Windows version of the Crisis Trojan is able to sneak onto VMware implementations, making it possibly the first malware to target such virtual machines. It also has found a way to spread to Windows Mobile devices. Samples of Crisis, also called Morcut, were first discovered about a month ago targeting Mac machines running various versions of OS X. The Trojan spies on users by intercepting e-mail and instant messenger exchanges and eavesdropping on webcam conversations. Launching as a Java archive (JAR) file made to look like an Adobe Flash Installer, Crisis scans an infected machine and drops an OS-specific executable to open a backdoor and monitor activity. This week, researchers also discovered W32.Crisis was capable of infecting VMware virtual machines and Windows Mobile devices."
like any one else? The attack surface is not the same as any other windows physical machine? What is the point, there's an anti-virus vendor waiting to sell vmware specific software?
First Mac, then Windows... Windows Mobile... What if it mutates and becomes human-human transmissible??!!! SAVE US!!!
#include <disclaimer.h>
once again its Java that the exploit uses, its a security risk out of the box, remove java and adobes PDF reader and 95% of this crap stops.
Oracle need to be spanked in the wallet for anything to change, it comes pre-installed on so many desktops and as soon as you connect to the web and hit the wrong site you are pwned.
exploitable from the start
Firefox/Opera need to disable Java in the browser permanently, its just too risky to have it installed
So it searches a compromised system for resident VMimages and then copies its self to the disk image so when it runs that image is already compromised. This is different than saying its infecting VMware, like ESXi. Which should have no images stored on an infected machine. so this is to infect VM workstation or player images?
STOP READING SLASHDORT NOW or things will be worse and money.
...but I want money, so I will read Slashdort.
You do not have a moral or legal right to do absolutely anything you want.
+1 to redundancy in the summary
Where is this Slashdort that bestows wealth upon its readers?
I like money
I can't believe you like money too. We should hang out.
Presumably this means that the affected host systems must have Java installed. Seems to me a brilliant example of the "Write Once, Run Anywhere" paradigm!
You never know what is enough unless you know what is more than enough. - Blake
So as it turns out, yes, VMWare can run Crysis. Er, Crisis.
If the host is already infected, what's the advantage to be gained by infecting the images?
N^HLeo just needs to wake up before the van hits the water. Right?
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
Do we have time to go to Starbucks? I'd like a Gentleman's Latte with full release.
This will be disasterous for tens of people!
The major problem with this is VMware View with Local Mode, which places use as it's more secure for laptop users on a BYOD deal or external contractors.