New Malware Emerges to Exploit Windows LNK Flaw
Researchers have found two distinct new malware families that are exploiting the newly discovered Windows shell LNK vulnerability, leading to concerns that the development of a worm could be in the offing.
One of the new pieces of malware, dubbed Chymine by researchers at Eset, exploits the LNK vulnerability to infect new machines and then tries to connect to a remote server and download another piece of malicious code. That piece of malware is a keylogger, designed to monitor an infected PC's input and look for high-value data such as online banking passwords. Chymine does not create new, malicious LNK files on its own, however.
Another piece of malware, known as Autorun.VB.RP, does have the ability to produce malicious LNK files that contain an exploit for the Windows shell vulnerability. That means that the malware has the ability to spread on its own and could become a more serious problem.
Editor's Pick
The appearance of Chymine and the adaptation of Autorun.VB.RP to exploit the LNK flaw follow the emergence of Stuxnet, the worm that was first seen last month and has been making headlines for exploiting the previously unknown LNK vulnerability. Microsoft has said that it is working on a patch for the flaw, which can be exploited via infected USB drives, via WebDAV or possibly through drive-by downloads, experts say.
"These new families represent a major transition: Win32/Stuxnet demonstrates a number of novel and interesting features apart from the original 0-day LNK vulnerability, such as its association with the targeting of Siemens control software on SCADA sites and the use of stolen digital certificates, However, the new malware we're seeing is far less sophisticated, and suggests bottom feeders seizing on techniques developed by others," the Eset researchers said.
Commenting on this Article is closed.
Today's Most Popular
- Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit
- New Tool Will Automate Password Cracks on Common SCADA Product
- How Offensive Research Drives Down the Cost of Attacks
- Researchers Dump Trove of 0Days For Popular Android Applications
- Citadel Malware Authors Adopt Open-Source Development Model
Most Commented Stories
-
Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit (7)
-
Apple Ships Huge Set of Patches for OS X (7)
-
Privacy Fail: Is Uncle Sam Encouraging Bad Security? (8)
-
Flash With Sandbox in the Works for Firefox (4)
-
Twenty Something Asks Facebook For His File And Gets It - All 1,200 Pages (55)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



