Interesting USB trojan

Discuss anything related to portable freeware here.
Post Reply
Message
Author
User avatar
webfork
Posts: 10821
Joined: Wed Apr 11, 2007 8:06 pm
Location: US, Texas
Contact:

Interesting USB trojan

#1 Post by webfork »

Some unique malware evidently using USB drives:

http://www.welivesecurity.com/2016/03/2 ... detection/
Each instance of this trojan relies on the particular USB device on which it is installed and it leaves no evidence on the compromised system. Moreover, it uses a very special mechanism to protect itself from being reproduced or copied, which makes it even harder to detect.

... This method depends on the increasingly common practice of storing portable versions of popular applications such as Firefox, NotePad++ and TrueCrypt on USB drives.
I have some doubts about whether this actually works as described as I would think program executable files would need to be modified to access infected DLLs, but I can see this going under some programs' radars. As the first poster suggested, this looks like a "specialized targeted attack tool [that's] clearly not something intended to infect millions of computers".

Regardless, those especially paranoid can check for suspicious DLL changes over time (e.g. via any of the many great batch hashing programs here on the site). Programs like USBFlashCopy can be easily setup to filter those files, which shouldn't change between sessions.
Last edited by webfork on Sun May 15, 2016 6:45 pm, edited 1 time in total.
Reason: (better wording, added a little more to the quote)

Post Reply