Exploits for the Windows .wmf vulnerability are being developed for the Russian market
Hackers are tailoring and selling zero-day malware for specific markets

Hackers writing zero-day malware to order

2005 was watershed year for zero-day exploits, warns security firm

Written by William Eazel

Advertisement

Russian security company Kaspersky Lab has discovered a worrying phenomenon in the wake of Microsoft's security gaffe over the .wmf exploit at the end of last year, claiming that hackers are tailoring and selling zero-day malware for specific markets.

Kaspersky claims that exploits for the .wmf vulnerability that emerged over Christmas were being developed specifically for the Russian market, away from the eyes of security companies.

"Around the middle of December, this exploit could be bought from a number of specialised sites," the company said.

"It seems that two or three competing hacker groups from Russia were selling this exploit for $4,000. One of the purchasers is involved in the criminal adware/spyware business, and it seems likely that this was how the exploit became public."

A watershed was reached at the end of 2005, according to Kaspersky. There were two critical vulnerabilities in Windows, a month apart, which were publicised before a patch was made available. Both vulnerabilities were exploited by malicious programs almost immediately.

In November, a research group known as 'Computer Terrorism' published a proof of concept exploit for the JavaScript processing function 'window()', which would run on a fully patched version of Internet Explorer.

Microsoft had known about the bug, but had not rated it a priority as it had discovered no serious exploit.

However, Computer Terrorism understood the vulnerability better than Microsoft and tweaked the code to install and execute a file on a victim system without the knowledge or consent of the user.

A week later, exploits surfaced on the internet. "This was the first case in which a Trojan exploited a vulnerability in Windows for which no patch existed, " Kaspersky said.

The situation was repeated in late December when the .wmf exploit surfaced. "It was clear that this was the latest zero-day vulnerability, and Microsoft knew nothing about it," said Kaspersky.

"The most worrying thing is that the virus writing community not only detected this vulnerability before Microsoft, but before any other major company specialising in the identification of vulnerabilities."

Tags:

Further reading

Related whitepapers

Related jobs

Do you agree?

Most commented stories

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

05 Sep 2008

8.64 MBPodcast Special: Views from the Valley More...

Podcast image

04 Sep 2008

12.7 MBComputing podcast 4 September 2008 More...

Podcast logo

02 Sep 2008

8.39 MBEco-Entrepreneur Podcast: Bulldog More...

Poll

INTERNET EXPLORER 8

INTERNET EXPLORER 8

Are you intending to download Internet Explorer 8 when it becomes available?

Previous poll results

Spotlight

LogMeIn Rescue+Mobile

BlackBerry gets LogMeIn remote support

Rescue+Mobile lets a support technician take control of the handset   More...

Dell manufacturing plant

Dell planning factory closures to cut costs

Report claims that PC maker is looking to sell off...  More...

Google Chrome

More growing pains for Chrome

Google wrestles with licensing and security problems   More...

Smartphone

US takes 3G crown from Europe

Americans finally catch up with Europeans in adoption of 3G   More...

Primary Navigation