‘Gadget’ in the middle: Flame malware spreading vector identified
Aleks, June 04
In our FAQ on Flame posted on May 28, 2012, we postulated there might be a still undiscovered zero-day vulnerability in Flame:
“At the moment, we haven’t seen use of any 0-days; however, the worm is known to have infected fully-patched Windows 7 systems through the network, which might indicate the presence of a high risk 0-day.”
Our suspicion was heightened because fully patched Windows 7 machines were being infected over the network in a very suspicious manner.
We can now confirm this is the main purpose of a special module of Flame called “Gadget” together with another module called “Munch”.
(NOTE: It’s important to understand that the initial Flame infection could still be happening through zero-day vulnerabilities. The “Gadget” module is simply used to spread within a network from a machine that is already infected with the malware).
The “Gadget” and “Munch” modules implement an interesting man-in-the-middle attack against other computers in a network.
When a machine tries to connect to Microsoft’s Windows Update, it redirects the connection through an infected machine and it sends a fake, malicious Windows Update to the client.
The fake update claims to be the following:
“update description=”Allows you to display gadgets on your desktop.”
displayName=”Desktop Gadget Platform” name=”WindowsGadgetPlatform”[…]
Important information: One June 4th, 2012, Microsoft released a number of blog posts and an Update for Windows which is blocking three fraudulent certificates used by Flame. We recommend that Windows users apply this update immediately.
Microsoft SRD blog:http://blogs.technet.com/b/srd/archive/2012/06/03/microsoft-certification-authority-signing-certificates-added-to-the-untrusted-certificate-store.aspx
Microsoft security advisory 2718704:http://technet.microsoft.com/en-us/security/advisory/2718704
MSRC blog:http://blogs.technet.com/b/msrc/archive/2012/06/03/microsoft-releases-security-advisory-2718704.aspx
SecureList: ‘Gadget’ in the middle: Flame malware spreading vector identified
9 Notes/ Hide
-
netzblockierer reblogged this from lilithlela
-
netzblockierer likes this
-
fivedee reblogged this from anonymissexpress
-
fivedee likes this
-
dom72 reblogged this from anonymissexpress
-
dom72 likes this
-
fromstarstostarfish likes this
-
theamericanbear likes this
-
anonymissexpress reblogged this from lilithlela and added:
Aleks, June 04 SecureList: ‘Gadget’ in the middle: Flame malware spreading vector identified
-
lilithlela posted this