Brazilian Coders Are Pioneering the First Cross-OS Malware Using JAR Files
An anonymous reader writes: Criminal gangs in Brazil are experimenting with the first malware families that are packaged as JAR files, capable of being deployed to Windows, Linux, Mac, and even Android from the same codebase, instead of relying on 4 different versions. Right now, only the malware dropper, a component used to infect computers with banking trojans, seems to have been coded in Java, but security experts expect a full-blown banking trojan to soon follow.
Does anyone actually install a JRE any more?
Yeah, I didn't think it was very many.
OK of those who have one installed, you you allow it to run as a browser plugin?
Yeah, I didn't think so.
There's no Java for CP/M-Z80, so I'm safe from being target by cross platform malware [or being targeted by applications in general].
But perhaps some day you'll need permission from Oracle to run the malwarez. That'd progress.
Guess all those memories of viruses from the 80's containing executable code valid on multiple processors are all my fevered imagination. Who knew that the first cross-OS malware was definitely only being written now, in 2016, in Java.
Wait, no, just the dropper. Congrats guys, you've discovered a platform-independent way of opening a stream from somewhere on the internet and dumping it to a file. Definitely pushing the envelope of Java to do that, I mean it's not like it comes with any sockets or file API specifically designed for stuff like that.
Give me a break. I was hoping to hear about something actually creative, like PDF or jpeg with multiple exploits for common Windows/Mac/Linux viewers or decode libraries, that causes a jump into the appropriate shellcode for each platform depending on what it's viewed on. This story is a non-event.
is to strip out all of the Java shit for each new session. Lots of Java shit probably for i2p but I don't believe in having Java on any system, Live or Installed.
"First Cross-OS Malware Using JAR Files"
I used to have that one. It was developed by Sun, and called the Java plugin.
How exactly does this JAR file get downloaded and executed on a Linux system, without enduser action.
Kinda like writing,
German auto workers are faking emissions
or
Catholic priests are molesting children in London
or
Dice employees used to be the lowest form of life
If you catch my drift. If not, the next elevator fart you smell was mine.
I haven't had Java installed for years, so good luck with the JAR.
"Java: write once, run anywhere"
Sorry, couldn't help.
I don't think so.
http://virus.wikidot.com/esperanto
another reason to uninstall java.
Unicode killed the ASCII-art *
Write once, pwn everwhere!
Monstar L
2008: http://citeseerx.ist.psu.edu/v...
2009: https://en.wikipedia.org/wiki/...
2010: https://nakedsecurity.sophos.c...
Look what some moron said about the same subject back in 2011:
http://www.developers.slashdot...
2012: https://www.intego.com/mac-sec...
2012: http://www.zdnet.com/article/c...
2012: http://www.infosecisland.com/b...
etc., etc.
Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
That's a lot of coders. Gonna be a hard project to manage.
I'm a Brazillian that works with IT, and it's the first time that I'm hearing something about it: it seems to me like a pretty bad-made SCAM :/
* I may be wrong, but I doubt it :P
Who cares.
This is why OS architectures like Qubes are important. This is why Linux systems (and everything else) should work more like that. It is also why the principle of least authority needs to make its way out of textbooks and into real life. Malware like this can work because it is given permission to work. There is no reason things need to be that way, except for laziness of programmers.
John_Chalisque
It's written like a piece on an OSS project. When I got to the end, I was thinking, "Why are these researchers making malware?" Had to go back and re-read the first two words.
Download some Minecraft mods, take a peek inside.
All the more insidious because generally it is children installing said mods.
I am very small, utmostly microscopic.
Well, at least it is an upgrade from MS Word macros.
So here we go,
mods for minecraft are jar files, I suppose this "hackers" will target the plethora of kids that install mods without checking if they come from proper source.
Don't mind the little fact that Macs don't even come with Java pre-installed anymore.
...anything would smell bad to a person living near Guanabara Bay.
jar files will work in some places, but plenty of things' containers don't use anything written in Java, so they don't have Java installed.
The container that runs the web browser and email client would be a good example of one that doesn't need Java. Maybe this malware would be compatible with the OpenHAB container, though. Good luck, guys!
There are plenty of malware packages in PHP, Perl, Python, and Ruby that will search for vulnerable web apps, infiltrate a hosting account, then set up web-accessible shells written in the same languages and continue on to find more vulnerable apps and accounts.
This is false
it is a lie . WHY have about 2500 cross os malware......and some as old as 1999, in fact enjoy all the zombies and bots people....waves, they were made cross OS via hard work......
all your stupid is belong to publshers
There existed for a while a packed program that appeared as a DMG and EXE using Alternate Data streams. On execution it would use assembly to determine the OS ran on and jump to affected payload (INTEL ONLY, not RISC/PowerPC). On MAC would prompt with OpenGL commands, in Windows, visual basic or the like did the same "please put in password" attempts. This virus which I played with personally - was later blocked as Unknown packager in most AVs, and never really shined... But windows and MAC cross platform is still one of the most interesting viruses I have seen. Inspection of the executable showed the packing application was based on an android/iphone SDk platform - heavily tweaked and made to produce the "XZ" file. I saw this in 2012... and did run on both (MAC/windows) and appeared as different file names on each platform.
automatically converts and runs JRE files in Android?
I don't believe it.
If we assume they are written in Java... then certainly we can do some profiling... just look for people with less hair.
All the more reason to quit using Java. The only thing that even uses it is Minecraft, and THAT game runs like molasses compared to the Mobile/Console versions which aren't Java.
Isn't that sweet of them? I bet they like to boil babies for a hobby.