New Trojan Disguised as Windows IME
There's a new attack technique in use right now that enables attackers to inject Trojan code onto victims' machines by disguising it as a Windows input method editor (IME).
The technique is a twist on the classic attack vector of making malicious code look like something benign. In this case, the attack code is being disguised as an IME, which is a component of Windows that's designed to allow users with one type of keyboard to input characters from other alphabets. The payload in the new attack is a Trojan.
This specific Trojan, when run on a victim's machine, creates a new file in the System folder, named winnea.ime, according to an analysis by Websense researchers. Once it's running on the PC, the Trojan then disables any antimalware software that's present and attempts to delete the executable files associated with the antimalware product, as well.
Editor's Pick
Windows IME Trojan
The winnea.ime file itself is a DLL, but in the sample analyzed by Websense it is presented as an IME file and is installed that way, as well. The Trojan also changes the user's profile in order to set the default IME type to the malicious code. Once the user runs the IME file, the Trojan loads a file that looks for any running AV processes.
From there, the malware loads another file as a driver process and then calls it in an attempt to stop the antimalware software.
Commenting on this Article is closed.
Today's Most Popular
- Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit
- New Tool Will Automate Password Cracks on Common SCADA Product
- How Offensive Research Drives Down the Cost of Attacks
- Researchers Dump Trove of 0Days For Popular Android Applications
- Citadel Malware Authors Adopt Open-Source Development Model
Most Commented Stories
-
Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit (7)
-
Apple Ships Huge Set of Patches for OS X (7)
-
Privacy Fail: Is Uncle Sam Encouraging Bad Security? (8)
-
Flash With Sandbox in the Works for Firefox (4)
-
Twenty Something Asks Facebook For His File And Gets It - All 1,200 Pages (55)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



