THOUSANDS OF FREE BLOGGER TEMPLATES

Friday, June 11, 2010

Increase in USB-based Malware Attacks

Symantec reported increase in malicious applications that use flash drives as a spreading method. Unfortunately portable and easy connected feature of flash drive exposes it to the risk of infection. There are many malicious applications that spread simply by making a copy of themselves on all drives that are attached to a computer. At the moment, there are two popular methods that malicious applications use to infect USB flash drives:



  • Simple file copy method
Malicious application that is installed on an infected computer makes copies of itself to all storage devices that are attached to the computer. Usually the malicious application will also attempt to copy itself to peer-to-peer (P2P) file-sharing folders as well. A malicious file is often named with a sensational file name to attract a victim into launching the file and causing malicious code to be executed. This infection method requires that the victim manually execute the malicious file to become infected.
  • AutoRun.inf modification method
"Autoplay" or "Autorun" is functionality in Microsoft Windows and some other operating systems which is basically designed to perform some actions that are automatically executed when removable media is inserted or removed from a computer.

The "autorun.inf" is the file that contained instructions for the Autorun functionality to use a certain type of icon, for example add menu commands, and start an executable function.




With this infection method, the malicious application modifies or creates an autorun.inf file on all those network shares that are connected to the infected computer. When an infected USB flash drive is inserted into another computer, the copy of the malicious application is automatically executed. This infection method does not require any infection from the victim instead of physically attaching of USB to the computer.
Data resource:
http://www.symantec.com/connect/blogs/increase-usb-based-malware-attacks

0 comments: