Google: Beware of invisible malware

One of Google's security teams he said that he discovered a kind of malware that abuses a new technique to avoid detection by security products by cleverly modifying the digital signature of its files.

0day bw

It was discovered by Neel Mehta, a security researcher in the Google Threat Analysis Group (TAG from Threat Group). This technique was used by an adware strain called OpenSUpdater.

In the samples, the digital signature was processed and the End of Content (EOC) indicator was changed to a NULL tag in the “parameters” element of the SignatureAlgorithm that signs the leaf X.509. EOC pointers terminate encodings of indefinite length, but in this case EOC is used for encoding of definite length (l=13).

The technical explanation given by the researcher is a bit difficult to understand by users who do not know, but Mehta refers to a small edit made by the developers of OpenSUpdater in a small field within the digital signature of its payloads.

On Windows systems, this small edit is invisible to them ς της υπογραφής κάποιου αρχείου του λειτουργικού συστήματος, κάτι που κάνει το invisible. This allows it to run without security warnings.

Mehta reports that security products that use the OpenSSL library to analyze and export the signature information of a file will fail to scan files whose digital signature has been modified by this method.

"This is the first time TAG has discovered hackers who use this technique to avoid detection while maintaining a valid digital signature on PE files," Mehta said today.

The Google researcher contacted Microsoft, and mentioned the security gap to change the digital signature control algorithms.

Files infected with adware OpenSUpdater are currently being distributed through cracked games and software.

Once it infects one , adware is used to download and install unwanted software.

Google reports that most victims of OpenSUpdater are in the United States.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.
google, 0day

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).