Archive for March, 2006

Bagle Worm now using Rootkits

Saturday, March 25th, 2006

A new rootkit has been found in the wild by and reported by F-Secure. This follows days from when Sana Security found the Rootkit.Hearse rootkit. This time the rootkit code has been bundled with the Bagle worm to make up a new Bagle variants.

This is a new departure for the Bagle worm which has been in existance for a while now. The Bagle worm is very powerful as it is but with the addition of rootkit techniques it makes it more powerful because of its stealth.

The Bagle variants Bagle.GE and Bagle.GF work together to setup a proxy on the infected PC so that the Bagle variant author can use the PC to send out Spam and other criminal related activity. The Bagle.GE variant holds the rootkit code and this in turn hides the files that the Bagle.GF variant uses.

F-Secure has reported that the rootkit code is limited and seems to be a test for worse to come.

Keep Safe

regards
Steo
www.antirootkit.com

Sana Security uncovers a scary Trojan.Hearse

Thursday, March 23rd, 2006

Microsoft demonstrates Virtual Machine Rootkit - Subvert

Sunday, March 12th, 2006

World of Warcraft hackers use Sony BMG rootkit to cheat

Friday, March 10th, 2006