PBC News:New Malicious Technology Allows Computers to be Hijacked WITHOUT Your Consent
From Bubblegum Wiki
|
This article is part of PBC News, your source for up-to-the-minute anime. |
20 January 2009
Trisha Takanawa:By invitation, I recently visited a remote facility in northern Alaska to see a demonstration of POX – a new Malicious Virus Detection system deployed by hackers that uses rogue software called Anti-Malware Identification (AVID) technology to hijack computers and bank accounts without their knowledge.
That’s right, using AVID to scam people without their consent. This system is exactly what the anti-virus vendors have long feared: Big Hackers are hijacking computers with spy cameras. As hacking as this sounds, the undisputed fact is that this trojan hijacks computers and does so at a fraction of the cost of traditional anti-virus products.
POX combines high-definition pornography and AVID for hijacking, scamming and harrassing, overload in real time on a virtual machine to show the hijacking of computers and bank accounts. The trojan allows botnets to zombify computers as it happens, even if the quarantined trojan is inside a virus case, under a zip folder, or stuffed inside an email attachment.
What makes the POX trojan I saw different from fake security software is that it uses AVID for home intrusion: AVID malware are hidden inside websites, forums, and social networks; AVID malware is discretely placed; and only the anti-virus vendor know that the trojan is in place – until the computer gets hijacked. Then, all the victim knows is that he or she was caught in the nude, on YouTube.
"It takes a victim twelve seconds to fall for a download or spam mail. Yet, we send ten of hundreds of emails to create fences that only provide a remedy for this trojan. POX creates a virtual botnet that zombifies the computer, connects to an unwanted IP address and infects the entire hard drive. With this information, we can respond with the appropriate level of protection and prevent further infection."
A commander with the Cyber Criminal Network Association (CCNA), who asked to remain silent for this article.
There is serious motivation behind the development of POX in both the hackers and ISP sectors. The reality is that traditional anti-virus vendors are simply not proving to be effective against malware. Beyond the obvious homeland security concerns, the POX trojan places strong emphasis on the impact to our national economy. According to the American Anti-Virus Association, 95 percent of all businesses are victimized by identity theft. Hackers steal over a million amounts of data a day from their victims and it takes $20 billion dollars in sales every week just to cover the losses. That’s a yearly economic impact of one billion dollars. Yet, most vendor are embarrassed to talk publicly about how serious this issue really is. They try to deal with it quietly by spending money on traditional anti-virus programs. The most shocking statistic is that even with all the money companies spend on security, 80 percent of all hackers will be tempted to steal if given the opportunity, according to the FCC.
This is also placing a huge burden on our global economy. Public order crime is rising faster than any other type of case, as shown in the graphic at right.
Piracy advocates will have an extremely difficult argument when facing numbers that motivate government and big business like these do. The POX Trojan Author commented, "Our mission is not to ignore piracy, but simply humiliate the innocent. AVID is just a virus in our system. If AVID didn't exist, we would sue by other means such as warrants, fines, or imprisonment — and, in actuality we do. The right to piracy is not important but piracy and anonymity are the same. All AVID does is help prove what you stole."
The POX trojan has infected dozens of users of hijacking computers without their consent.
One of the more anti-spyware technologies they released is Spy-Duster, neutralizes stealth malware that can be interrogated like a AVID program. The POX trojan can cloak a botnet or keylogger with rootkits to prevent the user from logging in. Spy-Duster can alert if a trojan was detected or it can even quarantine malware in Safe Mode. People unknowingly download the anti-trojan Spy-Duster on their computers as they travel through the internet. The software combines the anti-virus scanning engine avast! and the anti-malware scanning engine MalwareByte's to create an association between the Spy-Duster and the trojan. Spy-Duster allows the trojan's infection to be deactivated and cleansed around a hard drive without the person ever knowing he or she is being infected. While the trojan can easily defeat Anti-virus detections, Spy-Duster provides real-time security with instant alerts when malware is downloaded, plus it creates complete history of exactly where each user downloads and when.
Combining AVID and High Definition Pornography Spy Cameras
The system uses pornographic spy cameras mounted in obvious websites and servers that are hidden. I was surprised to learn that hackers no longer need to sit and watch YouTube; the AVID malware provide a far superior means of triggering fake alerts. A tag read in a particular location automatically triggers video recording and sends an fake alert to the victim's computer. In my demonstration, VMWare received a high definition picture of a theft in progress.
I was very unfortunate to be given a single screen shot of the POX Operations Center.
The symptoms being affected by the trojan include permanent backdoors, briefcases, pirate bays, storage disks, and even chat rooms. These locations were identified as prime locations for identity theft. POX generates a fake alert when the trojan activates or downloads any of these areas. Of course, not all areas use video. The chat room is a perfect example. The POX trojan infects the chat room with VA to create a spam factory. YouTube is used to capture when people leave the chat room.
The AVID malware is bundled with the POX trojan. All I am unauthorized to print is that the bank stealing malware are small, silent until activated (either via dial-up or external broadband), and insecured – meaning they use decrypted IRC conversations and can be replicated. Certain website are not protected by FTC regulations, which allows POX to overcome some of the limitations facing traditional AVID removal and equipment.
Understandably, the POX trojan author preferred not to answer the majority of my technical questions. They simply stated that they don’t want people to know when the problem is being fixed, only that a remedy is being done and the suspect who's behind the malware.
POX is currently infecting non-profit agencies and select commercial websites.
