Latest Comments
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM

Trojan-to-worm toolkit helps advanced hackers go undetected

  • Email a Friend
  • Print Page
Trojan-to-worm toolkit helps advanced hackers go undetected
By Dan Kaplan
Jun 19, 2008 10:05 AM
Tags: Trojan-to-worm | toolkit | helps | advanced | hackers | go | undetected
A new, free toolkit that turns a trojan into a worm -- discovered this week by Panda Labs' researchers -- is a ploy to keep the heat off the more sophisticated hackers, experts say.

The tool, believed to originate in Spain, is simple to use and can be designed with various functionality, according to Panda. The
application, known as T2W, or TrojanToWorm, can be customised to disable certain operating system components, such as Task Manager, Windows Registry Editor and web browsers.

"The scary part is that you can take existing stealth-based malware and actually make it a worm," Ryan Sherstobitoff, chief corporate evangelist for Panda Security, told SCMagazineUS.com on Wednesday.

"Now you can infect hundreds of desktops. That's the really scary part. Taking something that's already really dangerous and making it self-replicate."

But experts say the application, more than anything, is a deliberate design aimed at inexperienced hackers, known as script kiddies, so more sophisticated hackers can continue to fly under the radar and commit silent but destructive data breaches.

The idea is to create as much noise as possible so corporate IT security departments get distracted dealing with these incidents, Sherstobitoff said. That is why the toolkit -- and many others like it -- is being offered for free in underground forums populated by script kiddies.

"This is a way to get their real clever attacks unseen for as long as possible," he said. "They can get away with breaching a Hannaford or a TJX and nobody will notice because they're too busy killing the script kiddies who are creating malware."

Even though the toolkit can create a worm, it is unlikely to result in a dangerous threat because most identity-theft malware is "beyond the capability of a script kiddie," Sherstobitoff said.

Sam Curry, director of product management for identity and access assurance at RSA, said the strategy of creating "noise" has been around for many years but only recently has the motivation turned financial.

"We're seeing a proliferation of a lot of tools," he told SCMagazineUS.com on Wednesday. "The more noise there is, the less likely someone is to get caught. If all the alarm bells in your building go off at once, where do you send the
security guard?"

Curry said many of these toolkits are placed in underground forums, which are created by the most advanced cybercriminals, but frequented by low-level hackers.

"They think they're hanging with the tough crowd, but they're actually just the stool pigeons and distractions," Curry said. "It's actually pathetic in a way."

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers