Microsoft Discovers Trojan That Erases Evidence Of Its Existence

  /     /     /  
Publicated : 22/11/2024   Category : security


Microsoft Discovers Trojan That Erases Evidence Of Its Existence


This downloader is also the payload



Researchers at Microsoft have spotted a Trojan downloader that does something very savvy yet rare: It deletes its own components so researchers and forensics investigators cant analyze or identify it.
The so-called
Win32/Nemim.gen!A
Trojan is also unusual in that unlike most Trojan downloaders that are put in place to deliver the real payload, this Trojan is also the payload, according to Jonathan San Jose, a member of Microsofts Malware Protection Center.
But the researchers lucked out and found some pieces of the malware. Most URLs that this trojan attempts to connect to for downloading are currently unavailable, but we got lucky and were able to find some of its components to investigate further, San Jose wrote in a blog post.
Nemim.gens ability to delete its components can wreak havoc for forensics investigators and malware hunters. This prevents the files from being isolated and analysed. Thus, during analysis of the downloader, we may not easily find any downloaded component files on the system; even when using file recovery tools, we may see somewhat suspicious deleted file names but we may be unable to recover the correct content of the file, San Jose said.
Malware increasingly is becoming mores sophisticated, and the more advanced attackers are employing techniques to fly under the radar.
[Zero-day and rapidly morphing malware is proliferating across the Web. Is your enterprise ready to stop it? See
Malware: The Next Generation
.]
Jaime Blasco, labs manager at Alien Vault Labs, says hes seeing more malware with built-in anti-forensics features as well as the ability to deter investigators.
In the case of Nemin, it is a clever idea since the analysts wont be able to determine the origin of the infection, and the infrastructure used to infect the systems will remain undiscovered for a longer period, he says. In addition, most of the security companies rely on automatic environments that execute and emulate malicious programs. We have seen how more and more malware families are beginning to add capabilities to detect these environments and deter emulation. We have also seen some malware samples that only get activated if they detect human clicking activity on the system.
Microsoft found two components of the Trojan that it downloads and runs, including a file infector and a password-stealer. The file infector -- which Microsoft identified as Virus:Win32/Nemim.gen!A -- tries to infect executable files in removable drives. The password-stealer -- PWS:Win32/Nemim.A -- targets user credentials in email accounts, Windows Messenger/Live Messenger, Gmail Notifier, Google Desktop, and Google Talk.
The Trojan sometimes appears as part of a display graphics driver in order to camouflage itself, typically as a file called igfxext.exe, according to Microsoft.
If youre infected with TrojanDownloader:Win32/Nemim.gen!A, we recommend you change all account passwords after youve cleaned your system, as its likely youve also encountered PWS:Win32/Nemim.A, the password-stealer, San Jose said.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ Nigerian scammers now turning into mediocre malware pushers. ◂
Discovered: 23/12/2024
Category: security

▸ Beware EMV may not fully protect against skilled thieves. ◂
Discovered: 23/12/2024
Category: security

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Microsoft Discovers Trojan That Erases Evidence Of Its Existence