Categorized | Antivirus

Malware Targets Security Software in China and Taiwan

The Bohu family of Trojans has recently earned some media attention. It’s a common malware family that is prevalent in Chinese-speaking part of the world, as can be seen in the spread of one variant, TROJ_FKEPLAYR.CH:

Recently, however, we’ve seen the Bohu family packaged with another malware family: the Goriadu family, which is used to hijack network traffic. In this particular attack, Goriadu malware was used to block the network traffic related to the in-the-cloud features of certain antivirus products.

TROJ_FKEPLAYR.CH drops a package which contains several malicious files. These are detected as TROJ_GORIADU.SMC , TROJ_GORIADU.SMM, and TROJ_GORIADU.SMX.

TROJ_GORIADU.SMM is the component responsible for hijacking the affected system’s network traffic. The targeted applications appear to be popular Chinese antivirus solutions. Trend Micro products and URLs are not on the list of targeted products and URLs.

In the past, many malware variants have blocked URLs related to antivirus companies. However, they usually did so fairly indiscriminately, blocking the entire domains of companies (i.e., for Trend Micro the entire trendmicro.com domain would be blocked.) However, this was fairly easy to detect.

Instead, TROJ_GORIADU.SMM’s blocking specifically targets “in the cloud” functionality by blocking only the servers used for these services. It does this by blocking very specific URLs, such that one could access the websites of the targeted products yet their “cloud” features would not work.

Trend Micro researchers are digging deeper into this issue. These particular behaviors meant to evade detection (appending of garbage code and blocking access to antivirus sites and related services) are definitely not unheard of but they do highlight the importance of protecting computers at all possible levels, such as the URL and file level.

Special thanks to Jamz Yaneza, Patrick Estavillo, Edgardo Diaz, Jr., Jasper Manuel and King Viray for contributing to this post.

Post from: TrendLabs | Malware Blog – by Trend Micro

Malware Targets Security Software in China and Taiwan

Full story: TrendLabs | Malware Blog – by Trend Micro

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago