Advertisement
Promo

Security threats Toolkit

Virus writers use 'open source' methods

Tom Espiner ZDNet.co.uk

Published: 17 Jul 2006 12:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Malware writers are increasingly using open source methodologies when developing malicious code, according to antivirus vendor McAfee.

In its Global Threat Report for 2006, McAfee warned that more hackers are sharing source code and ideas freely. This includes distributing source code with documented explanations and annotations of how that code works, which helps programmers to adapt it.

McAfee said that this can be an extremely effective way of developing code, both legitimate and malicious.

"Like any powerful tool, open source can also be used for malicious purposes, particularly in security," McAfee said in its Global Threat Report for 2006.

"DoomJuice was a mass-mailer that distributed a copy of MyDoom. Maybe the author was proud of their skills being reused. It contained the documented source code of MyDoom, like a Lego kit with instructions," said McAfee UK security consultant Greg Day.

So-called script kiddies, who download easy-to-use malware from the Internet, have long been a reality. But McAfee's report claims that more virus writers, especially those involved in organised crime, are forming communities and typically share information over IRC networks.

However, these groups are much harder to join than open source software communities, as the malware writers are keen to avoid attention from the authorities.

McAfee said that malware now has a long-term development lifecycle, with code being developed, bugs being fixed, and betas then final versions being distributed amongst the malware community in a similar way to open source communities.

"You could say open source methodology allows them to build better quality attacks," Day told ZDNet UK. "Today's news is group development."

Hacker tools are also created and distributed freely on an open source model, according to McAfee. Versions of SDBot, a Trojan horse that opens a back door, included an add-in for the FU rootkit, a cloaking piece of software available on the Internet. McAfee claims it is possible to find documented copies of FU rootkit online "if you hunt around". It is also possible to find documented copies of Morphine, a tool used by hackers to circumvent antivirus protection.

Day said that few virus writers are devoting time to coding from scratch and resolving bugs. Hackers are also acting as paid consultants offering guidance once their source code has been opened — also known as "patronage" of their code.

"This is an effective methodology for ill-gotten gains," said Day. "If anything this shows that open source is an effective way of coding — a good idea being used for bad intent," Day added.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
76 out of 172 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters