Skip to main content

ZeuS variant only infects super-fast PCs

posted onNovember 25, 2010
by hitbsecnews

Miscreants behind one variant of the ZeuS Trojan have outfoxed themselves in their attempts to outwit anti-virus analysts by releasing a variant of the malware that only infects high-performance PCs.

Security firms use automation and virtualisation technologies to cope with the growing volume of malware spewed out by cybercrooks every day. VXers are well aware of this and use virtual machine detection and anti-debugging code in their creations. The tactic is designed to frustrate security researchers and in so doing increase the time it takes to detect, develop and distribute anti-virus updates.

Users of the ZeuS crimeware toolkit are very much involved in this cat and mouse game between security researchers and cybercriminals. But one particular group using the crimeware toolkit released a variant whose anti-debugging efforts are so aggressive it effectively assumes any machine whose CPU is running at lower than 2GHz must be running a debugger. As a result the malware only runs its malicious routines on high-performance machines, remaining inert on lower horsepower boxes.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th