Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

August 27th, 2010, 15:15 GMT · By Catalin Cimpanu

USB Devices Harbor 25% of All New Worms

SHARE:

Adjust text size:


25% of all new worms use USB devices to get around
Enlarge picture
A report coming out of Panda Labs shows an increased trend for new malware and worm attacks to use USB devices as distribution channels.

The report places the figure around 25%, so for every one in four USB device, an attack has been reported.

Even if email attacks are still predominant, USB threats are on the rise, mainly due to the new wave of USB enabled devices launched on the tech market in recent years.

But don't imagine that only simple pocket-size USB drives are responsible. Any kind of USB device is susceptible to these attacks.

Anything from a digital camera, cell phone, external hard drive, DVD player, MP3 player, memory card, or mobile device can be the host of an USB worm.

These attacks rely on the Windows routine of reading the “Autorun.inf” file to get instructions on how to manage the newly connected USB device.

New worms are created that when reaching an USB device for the first time, modify the “Autorun.inf” file with malicious code, forcing the host to which the USB device is connected into running commands without the user's permission and even knowledge.

This technique is highly effective mainly because the user can't even react, Windows reading the infected autorun file almost instantly the device is connected.

Nevertheless, system hacks exist, disabling some Windows procedures when handling USB devices, forcing the OS to skip “Autorun.inf” when mounting any USB device.

Proprietary USB security software still isn't something that common, but some products have hit the market.

In the past, USBs have been responsible for famous incidents where they have been used as a distribution channel for some dangerous worms.

Security data from Panda’s Second International SMB Security Barometer shows that from a pool of 10,470 companies spread across 20 countries, 27% of them report infections with the source of the attack being localized on an external USB device.

The likes of the Mariposa and Vodafone botnets, and the dangerous Conficker and Stuxnet worms successfully used USB devices to spread on millions of computers around the world.

TELL US WHAT YOU THINK:

2,240 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


McAfee Signs OEM Deals to Install Antivirus Technology on USB Devices

Malware Hits All-Time High During First Half of 2010

AutoRun Malware Dominates the Threat Landscape in 2010

Complex IM Worm Infects Yahoo! Messenger and Skype Users

3,000 Mobile Phones Shipped with Malware in Spain

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM