New Trojan Disguised as Windows IME
There's a new attack technique in use right now that enables attackers to inject Trojan code onto victims' machines by disguising it as a Windows input method editor (IME).
The technique is a twist on the classic attack vector of making malicious code look like something benign. In this case, the attack code is being disguised as an IME, which is a component of Windows that's designed to allow users with one type of keyboard to input characters from other alphabets. The payload in the new attack is a Trojan.
This specific Trojan, when run on a victim's machine, creates a new file in the System folder, named winnea.ime, according to an analysis by Websense researchers. Once it's running on the PC, the Trojan then disables any antimalware software that's present and attempts to delete the executable files associated with the antimalware product, as well.
Editor's Pick
Windows IME Trojan
The winnea.ime file itself is a DLL, but in the sample analyzed by Websense it is presented as an IME file and is installed that way, as well. The Trojan also changes the user's profile in order to set the default IME type to the malicious code. Once the user runs the IME file, the Trojan loads a file that looks for any running AV processes.
From there, the malware loads another file as a driver process and then calls it in an attempt to stop the antimalware software.
Commenting on this Article is closed.
Today's Most Popular
- Yahoo Includes Private Key in Source File For Axis Chrome Extension
- Researchers Unveil New Way to Trust Certificates
- FBI Warns Top Firms Of Anonymous Protest Hacks on May 25
- DNSChanger Lingers: 330k Systems Still Infected, 77,000 In The U.S.
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (10)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (14)
-
DNSChanger Lingers: 330k Systems Still Infected, 77,000 In The U.S. (3)
-
FBI Warns Top Firms Of Anonymous Protest Hacks on May 25 (2)
-
New York Lawmakers Want Anonymous Comments Banned (3)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



