Shruggle virus hits 64-bit Windows

By
Follow google news

The author of the proof-of-concept Chiton virus family has claimed another first by writing the first virus to attack a Windows 64-bit executable file running on AMD systems.

The virus is another proof-of-concept virus by virus writer "Roy G Biv" aimed at showing how the 64-bit version of the operating system is just as prone to attack as its 32-bit brethren. The author normally writes virus code with no malicious payload and then submits his work to anti-virus firms rather than releasing them into the world.


The Shruggle virus tries to infect 64-bit executables files in the same folder it was run in, and explores sub-folders looking to infect files there. The virus then appends itself to the file, including dll files.

According to researchers at anti-virus firm Symantec, the code looks a lot like previous viruses Rugrat and Shrug and unusually for a virus it is written in AMD 64-bit assembly code rather than a high-level language.

The Rugrat virus was the first virus to attack 64-bit Windows Portable executable files using Thread Local Storage structures to execute the viral code..

http://securityresponse.symantec.com/avcenter/venc/data/w64.shruggle.1318.html

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Supply chain attack hits 100 million-download Axios npm package

Supply chain attack hits 100 million-download Axios npm package

NAB is co-designing a SIEM with Databricks

NAB is co-designing a SIEM with Databricks

APRA pulls data submission system after security pentest

APRA pulls data submission system after security pentest

Councils push for federal shared security centre funding

Councils push for federal shared security centre funding

Log In

  |  Forgot your password?