iTnews
  • Home
  • News
  • Technology
  • Security

New variant of mebroot detected, as vendors criticised for inaction

By Dan Raywood on Jun 4, 2009 11:16AM

Security vendors have been criticised for failing to react to the MBR rootkit and offer protection against it.

Prevx malware technology specialist Marco Giuliani claimed in his blog that in the two months since a new variant of the MBR rootkit was detected and isolated there has been hardly any response.

 

Giuliani said: “Unfortunately only a couple of security vendors and independent researchers implemented a working detector for it. This is not good, especially if we are talking about the same threat that has infected tens of thousands of PC around the globe last year, stealing password, bank accounts and personal information.

 

“Actually, as written in one of my previous posts, first version of MBR rootkit could have still been used with a large success by its creators. In fact, the main problem for the attacker is the dropper because of anti-virus detections. Anyway MBR rootkit droppers have been able to evade signature and heuristic detections of most of anti-virus softwares - their creators know quite well how to do their dirty job.”

 

He further claimed that after a dropper infected the system, only a small amount of anti-rootkit software is able to detect it.

 

Prevx has also claimed that a new variant has been detected that includes a much stronger filtering engine and is able to filter out more in depth every attempt done by security software to read the Master Boot Record.

 

Giuliani claimed that the company had checked how many anti-rootkits are already able to detect the new version of MBR rootkit isolated two months ago, and only five were fully able to detect the threat.

 

“As written before, we started seeing this new MBR rootkit quickly spreading on internet as it is dropped by compromised websites that host malicious iframes and obfuscated javascripts. Security vendors should take care of this threat instead of waiting until the end of 2009 and claiming that MBR rootkit has been the worst threat of the year, as happened last year”, said Giuliani.
 


See original article on scmagazineuk.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
detectedmalwarembrmebrootrootkitsecurity

Partner Content

Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
How to turn digital complexity into competitive advantage
Promoted Content How to turn digital complexity into competitive advantage
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
Digital signatures propel Australian Unity with rapid time to value
Digital signatures propel Australian Unity with rapid time to value

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Dan Raywood
Jun 4 2009
11:16AM
0 Comments

Related Articles

  • Australian businesses lose $227 million to BEC-like scams
  • Global police operation takes down Flubot infrastructure
  • VMware, F5, Log4j added to EnemyBot attack targets
  • Google adds phishing protection to Workspace apps
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia sets changeover date for myGov

Services Australia sets changeover date for myGov

Google Cloud IoT Core goes on the end-of-life list

Google Cloud IoT Core goes on the end-of-life list

NBN Co proposes to axe CVC across all plans by mid-2026

NBN Co proposes to axe CVC across all plans by mid-2026

Bunnings assembles a tech team of 700 in four years

Bunnings assembles a tech team of 700 in four years

Digital Nation

Crypto losses to crime surge to $1.9 B in first half of 2022: Chainalysis
Crypto losses to crime surge to $1.9 B in first half of 2022: Chainalysis
Edge and IoT critical to Web3 infrastructure
Edge and IoT critical to Web3 infrastructure
Save the Date — Digital Nation Live launches on October 25
Save the Date — Digital Nation Live launches on October 25
Stakes are higher for cybersecurity in Web3: Gal Tal-Hochberg, CTO at Team8
Stakes are higher for cybersecurity in Web3: Gal Tal-Hochberg, CTO at Team8
CommBank’s mobile banking app beats ANZ, NAB, Suncorp and Westpac: Forrester
CommBank’s mobile banking app beats ANZ, NAB, Suncorp and Westpac: Forrester
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.