Conficker gets new lease of life
By Stuart Turton
Posted on 24 Feb 2009 at 10:24
Malware writers have created a new version of the Conficker worm that no longer needs to phone home to download its malware package.
Dubbed Conficker B++, the new strain opens a backdoor on the infected machine allowing hackers to push out updates directly to the worm, without it needing to contact a remote server first.
Or in the words of Microsoft's advisory: "We've discovered that the new variant no longer patches netapi32.dll against all attempts to exploit it. Instead, it now checks for a specific pattern in the incoming shellcode and for a URL to an updated payload."
This was the unusual tactic of the original Conficker. However it has been frustrated by the Microsoft-led alliance of security companies which is busily taking down sites associated with the worm.
Malware creators have also taken steps to shield Conficker B++ from the patches put in place to fend off its predecessor.
On the bright side, Microsoft claims that there's no easy way for hackers to upgrade the original Conficker to its new and improved brethren, which means it will need to spread from scratch.
Microsoft has a $250,000 bounty out for the Conficker creator. Pick up next month's PC Pro for our investigation into whether the reward is likely to do more harm than good.
From around the web
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Why virtualisation hasn't slowed the growth of data
- How to make Google AdWords work for your business
- The curse of sloppily written software
- Paying for your crimes with Bitcoin
- Behind the scenes: tech support for Formula 1
- The security risk of fat fingers
- Why Windows Phone 7 isn't quite ready for business
- When will Microsoft stop fiddling with Windows 8?
- Flash down the pan?
- Metro Style apps vs desktop applications
advertisement
