Feeds

Video Trojan hoax scares up publicity for security firm

Another ambitious start-up banging another empty drum

  • alert
  • submit to reddit

Security for virtualized datacentres

Updated It sounded so very exciting on Friday: a relatively unknown computer security firm called Network Security Technologies (NETSEC) was rushing to meet with the FBI to discuss a devastating new Trojan they had discovered joined to an .avi video file.

The Trojan, they said, was capable of infecting personal computers and commandeering them to attack Web sites, resurrecting shades of the media frenzy surrounding February's DDoS attacks.

Clearly, NETSEC had struck gold.

Yet on Saturday, the FBI's National Infrastructure Protection Centre (NIPC) Web site remains strangely devoid of any mention of this impending calamity, as does the Carnegie Mellon University Computer Emergency Response Team (CERT) site.

Apparently, the wire services had got a few things wrong on Friday, no doubt with NETSEC's gentle encouragement.

We now know that the video Trojan, which NETSEC dubbed 'Serbian Badman' (ooohh, how scary that sounds), is actually known by the tragically prosaic name 'Downloader' (aka Backdoor.ldr; Downloader.Kit; Trojan.Win32.Loder.WPW; W95/Loader; and WWWPW).

It works by fetching, downloading and silently running another, and quite familiar, Trojan called 'Sub7', which consists of a remote server enabling a third party to control an infected computer.

We are terribly disappointed to report that the Sub7 server is not capable of launching DDoS attacks, unless it has been updated radically since the last time we, em, 'evaluated' it.

Meanwhile, Network Associates' McAfee site has condescended to run some information on NETSEC's sensational new discovery, but what they have to say sounds painfully familiar.

The Downloader Trojan "downloads another Trojan from the Internet and runs it silently. The downloaded Trojan is identified as 'BackDoor-G2'" [aka Sub7].

"NETSEC alerted the Internet community about BackDoor-G2 by calling it 'Serbian Badman Trojan (TSB Trojan)'. News stories suggest that the controlling Trojan which is downloaded is a new threat -- it is not. Although the Trojan known as "Downloader" is new, the file downloaded is a known Trojan."

In other words, NETSEC's discovery amounts to nothing more than a publicity stunt by an opportunistic security firm in quest of free advertising in the form of media attention.

The Register is shocked....shocked....to learn that media manipulation is going on. ®

Previous coverage

Movie clip Trojan to be used in DDoS-style attack

Business security measures using SSL

More from The Register

next story
Hey, Scots. Microsoft's Bing thinks you'll vote NO to independence
World's top Google-finding website calls it for the UK
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Apple CEO Tim Cook: TV is TERRIBLE and stuck in the 1970s
The iKing thinks telly is far too fiddly and ugly – basically, iTunes
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
OECD lashes out at tax avoiding globocorps' location-flipping antics
You hear that, Amazon, Google, Microsoft et al?
Show us your Five-Eyes SECRETS says Privacy International
Refusal to disclose GCHQ canteen menus and prices triggers Euro Human Rights Court action
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.