ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

New runner in Horse Race

highVulnerabilityimportance 42
Full article401 words · extracted from securelist.com · click to collapse

01 Jun 2005

minute read

Some interesting developments in the Operation Horse Race story, which we wrote about in our news section a couple of days ago.

A security company named 2bSecure originally located the Trojan code. The police asked them not to share the Trojan sample with antivirus companies in order to avoid alerting the offenders. However, now that they have been arrested and evidence is being collected, 2bSecure intend to publish the code of the Trojan on their website.

The company also plans to publish a disinfection tool along with the code to help victims remove the Trojan from their computer. 2bSecure believes that making the Trojan code publicly available will serve a similar purpose, by helping victims to identify infected systems and to evaluate the damage.

The full disclosure concept is nothing new, and in the past, other so-called security companies have published Trojan and virus code in order to “help” users deal with them.

In this case, given that a disinfection tool will be available, I think publishing the source or the Trojan code is redundant and, in my opinion, irresponsible. In the past, whenever a piece of malware has been made available on the Internet, it basically opened the door to countless modifications, hacks, or patched variants. We’ve seen this happen in the past with other bots where the source has been widely distributed – Agobot and SdBot are the first that come to mind, with over 800 variants in each family!

Sure, there will be researchers who will benefit from access to the Trojan – they’ll be able to analyse its behaviour and develop protection against it. However, the damage which will be inflicted on the Internet community by the potential multitude of new variants will far outweigh any positive effects.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/new-runner-in-horse-race/30022/