New Malware Variant Uses Google Docs As a Proxy To Phone Home
An anonymous reader writes "Windows 8 may block most malware out of the box, but there is still malware out there that thwarts Microsoft's latest and greatest. A new Trojan variant, detected as Backdoor.Makadocs and spread via RTF and Microsoft Word document marked as Trojan.Dropper, has been discovered that not only adds a clause to target Windows 8 and Windows Server 2012, but also uses Google Docs as a proxy server to phone home to its Command & Control (C&C) server."
must be an apple patent somewhere
Even when Microsoft makes something bulletproof, these tech assholes have to blame a Google problem on Microsoft.
(looking at picture in article) I really have to wonder why malware authors use command and control servers covered in rust...
#fuckbeta #iamslashdot #dicemustdie
So, what happens when google suspends the account?
"The malware interprets security as damage and routes around it."
Because of all the downtime on Google docs, the communication with the C&C server is intermittent and therefore difficult to pinpoint by law enforcement. Security by instability.
lucm, indeed.
WTF is microsoft giving system access to RTF files? I bet these MS idiots can make .txt vulnerable if you just give them the opportunity.
Sounds just like all the other malware which used to connect to IRC to take its orders. Only difference is the protocol now.
How does it work exactly, and does it affect XP users?
I am really not in the mood for trying to read the information in the article. What idiot webmaster thought it would be a good idea to put a giant frame on the left side of the screen so you'd have to scroll left and right repeatedly to read the information in the right frame?
Which part of "Microsoft Product" did you not understand?
> A new Trojan variant, detected as Backdoor.Makadocs and
> spread via RTF and Microsoft Word document marked as Trojan.Dropper
Ahhh, hackers are following good coding conventions about meaningful names (Object) dot (Verb). This is reassuring.
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
I had no idea what RTF is until I used Yahoo search. RTF stands for Rich Text Format that has been in use since around 1989. Do people still use RTF? Just asking because no one I know uses it. My friends and family use .doc and open office text .odt.
Yes, I am showing my age. lol
I wonder if Backdoor.Makadocs runs on older versions of Windows like Windows 7.
What the C&C servers are? It doesn't help much if it doesn't.
Update at 4:30PM EST: “Using any Google product to conduct this kind of activity is a violation of our product policies,” a Google spokesperson said in a statement.
In a related development, Microsoft fixed all its vulnerabilities by issuing a very simple patch. It is basically a statement issued by its spokesperson:"Using the vulnerabilities in Microsoft software is a violation of the our product policies".
Yale lock company and the Chubb safe companies too issued a joint statement saying, "picking our locks is a violation of our product policies".
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
..and it can happen in EVERY data format. Including all flavours of XML and HTML. Maybe it is time for you to learn about stuff (virus tradecraft) before posting.
Apparently virus writers are reading on this site. People have been predicting C&C and ex-filtration traffic via Google Mail and Google Docs (and all similar services) for quite some time.
So - corporate network security must have the ability to inspect ANY SSL traffic going through the firewall (done via corporate certificate in the browser). Including your conversations via Google Talk and your communications with financial services. Employees charged with traffic inspection must handle all intelligence gathered responsibly and have to keep it a secret, as long as no misuse is detected. Collection/Inspection systems must be properly secured.
We all expect police and customs officers to do similar things, and as long as they are well-trained professionals it is quite universally accepted.
If you still don't like this - bring your own crap with a UMTS modem into your workplace.
..then they will use a large number of (fake) Google user ids to facilitate their data extraction and C&C. Maybe they already have hundreds if users embedded in an encrypted fashion into the malware, to be used in future weeks. The same goes with the "documents" used.
Also, they will use TOR and other captured PCs to connect to Google Docs. Google can't even blacklist all TOR exit routers.
The C&C server will poll documents on Google docs which have been "filled" by the infected PCs. Sounds more you don't have a clue.
Now where's that guy who wanted to move an old document system over to Google Docs?
new idea, doesnt use man in the middle. But by now, i learned all i need to know from " the darkside" no point in making such kiddy toys
I will not disclose a 0 day again I will not disclose a 0 day again I will not disclose a 0 day again I will not disc
I have to admit I am impressed. Using Google Docs as an infection vector is ingenious. Why would anyone want to work out of "the cloud."
Since Google Docs is blocked by the Great Firewall, those of us in China are safe!