Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

August 17th, 2012, 09:30 GMT · By

Shamoon Malware Covers Its Tracks by Wiping Master Boot Record

SHARE:

Adjust text size:

Shamoon's driver is signed with a valid certificate
Enlarge picture
A curious piece of malware has been identified by security experts from Seculert, Kaspersky and Websense. While there are some questions that remain unanswered, they've all noticed that the malicious element known as Shamoon covers its tracks by overwriting files and by wiping the computer’s master boot record (MBR).

Kaspersky experts believe that the creators of this Trojan are actually inspired by the “Wiper” found on the computers infected with the infamous Flame.

Another curious thing about Shamoon (Trojan.Win32.EraseMBR.a) is the fact that its disk driver is signed with a certificate from EIdoS Corporation, a security solutions provider.

Researchers from Seculert have found that Shamoon actually relies on a two-stage attack. In the first stage, the attacker takes control of an internal device that’s connected to the Internet. From this machine the infection is spread out to other computers that aren’t necessarily online.

After the computers are infected, the cybercriminals steal all the information they need and then they initialize the data wiping process.

Once this is done, the Trojan reports back to its command and control server through the machine it initially infected.

Unlike other malware, Shamoon doesn’t attempt to hide its presence for as long as possible. Instead, after it completes its tasks, it overwrites the files and deletes the MBR to ensure that no traces remain.

The main targets of the malware may be organizations from the energy sector. Websense has confirmed that at least one of the organizations from this sector has been hit by this threat.

It’s uncertain at this time who may be behind the malware, but according to Kaspersky, its name may be related to the Shamoon College of Engineering in Israel, or it might represent the name of the author (Shamoon is equivalent to Simon).
FILED UNDER:
malware
Shamoon
MBR


2,055 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


MyAgent Trojan Targets Aerospace, Chemicals, Technology and Defense Industries

Trojan Hides Its Payload by Using NTFS’s Extended Attributes Feature

Bafruz Malware Replicates Antivirus Software in Order to Disable It, Microsoft Finds

Malicious "AntiHacker" Tool Installs DarkComet RAT to Spy on Syrian Activists

Kaspersky Turns to Outside Experts to Decrypt Gauss “Warhead”

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM