Donate Us

Help us keep this free site alive with a small contribution from you. Select an amount below.

Wednesday, July 18, 2012

Kaspersky Labs analyzes a number of Trojan Horses and malware examples targeting Israel that are apparently written in Iran, in part one of a two part article.

The malware, nicknamed "Madi" (presumably a reference to the Shiite messianic figure of the Madhi), is not sophisticated. Instead, it relies on tried and true methods of social engineering, relying on naive computer users to allow scripts to run in PowerPoint presentations, ignoring the warnings that Windows gives about potentially dangerous actions.

It is well known in the computer security world that people are too likely to fall for such schemes.



Another method used is to send what appear to be JPG images, but in fact they are programs as well, using a known Microsoft bug where Unicode characters in languages that are written right-to-left can create file names that appear to have the extensions of mere images but in fact are executable programs that can do anything to the computer (in this case, a screen saver):



Once the malware is loaded then the attackers can remotely do anything they want on the infected machines.

Again, these are not sophisticated attacks in the least; hackers have been doing things like this for years. But it only takes one stupid victim to click on that cute photo of nature or puppies to compromise an entire company or government department.

This specific malware can take screenshots at regular intervals and also make audio recordings from the victim's computer, which can then be uploaded to the attackers' machines.

The Jerusalem Post reports that Iran is the target of the malware, even though key parts were written by Farsi speakers. I find that hard to believe given that Hebrew in the Powerpoint above, although the people who created the Trojan are not necessarily the same as those that created the Powerpoint macro that calls the Trojan.

(h/t Yoel, Ian)

--
Posted By Elder of Ziyon to Elder of Ziyon at 7/18/2012 01:30:00 PM

0 comments:

Post a Comment

EoZTV Podcast

Powered by Blogger.

follow me

search eoz

Recent posts from other blogs

subscribe via email

comments

Contact

translate

E-Book

source materials

reference sites

multimedia

source materials for Jewish learning

great places to give money

media watch

humor

.

Source materials

Sample Text

EoZ's Most Popular Posts Ever

follow me

Followers


pages

Random Posts

Pages - Menu

Elder of Ziyon - حـكـيـم صـهـيـون

Donate!

Tweets

Compliments

Monthly subscription:
Subscription options

One time donation:

Interesting Blogs

Categories

Best posts of 2016

Blog Archive

compliments

Algemeiner: "Fiercely intelligent and erudite"

Omri: "Elder is one of the best established and most respected members of the jblogosphere..."
Atheist Jew:"Elder of Ziyon probably had the greatest impression on me..."
Soccer Dad: "He undertakes the important task of making sure that his readers learn from history."
AbbaGav: "A truly exceptional blog..."
Judeopundit: "[A] venerable blog-pioneer and beloved patriarchal figure...his blog is indispensable."
Oleh Musings: "The most comprehensive Zionist blog I have seen."
Carl in Jerusalem: "...probably the most under-recognized blog in the JBlogsphere as far as I am concerned."
Aussie Dave: "King of the auto-translation."
The Israel Situation:The Elder manages to write so many great, investigative posts that I am often looking to him for important news on the PalArab (his term for Palestinian Arab) side of things."
Tikun Olam: "Either you are carelessly ignorant or a willful liar and distorter of the truth. Either way, it makes you one mean SOB."
Mondoweiss commenter: "For virulent pro-Zionism (and plain straightforward lies of course) there is nothing much to beat it."
Didi Remez: "Leading wingnut"