Trojan built to disable cloud antivirus

By Liam Tung on Jan 20, 2011 9:25 AM
Filed under Security

Crafty Chinese malware writers.

Microsoft has discovered a Trojan that aims to sever the connection between a device and the cloud antivirus (AV) service that is meant to protect it.

The Bohu Trojan, which targets Windows machines, contains three main functions: evade detection, install a filter that blocks traffic between the device and service provider, and prevent the local installation from uploading data to the server.

The attack appears to aim to knock out the additional layer of security that many antivirus companies have added to bolster defences and reduce the processing burden of ever-expanding signature databases.

"Cloud-based virus detection generally works by client sending important threat data to the server for backend analysis, and subsequently acquiring further detection and removal instruction," Jingli Li and Zhitao Zhou of Microsoft Malware Protection Center wrote on the company's blog.

"The process can take seconds to minutes, and is designed to remove malware not handled by the traditional on-the-box signature approach."

Kaspersky, Microsoft and Sophos have developed signatures for the Bohu trojan, which the researchers noted relies on the user installing, installing a rigged video codec.

According to Microsoft's researchers, the network driver that Bohu installs probes for HTTP request keywords and the cloud-server names of major Chinese AV vendors, Kingsoft, Qihoo, and Rising, the company involved in a corruption fiasco, which resulted in a suspended death sentence for a senior Chinese bureaucrat.

 
Follow us on Facebook and Twitter
 

Copyright © iTnews.com.au . All rights reserved.

Promo

Trojan built to disable cloud antivirus
 
 
 
 
 
Top Stories
M2 offers $1.6bn for iiNet: bidding war starts
Counters TPG's attempt to create massive telco.
 
Who's leading public, private and hosted cloud?
How Microsoft, Amazon, Rackspace, VMWare, Cisco and others stack up.
 
Unisys to shed 1,800 jobs in $300m restructure
New CEO shows the door to 8 percent of workforce.
 
Sign up to receive CRN email bulletins
   FOLLOW US...
Polls
Do grey market imports hurt your business?

Latest Comments
CRN Magazine

Issue: 336 | March 2015

CRN Magazine looks in-depth at the emerging issues and developments for the channel, and provides insight, analysis and strategic information to help resellers better run their businesses.