Feeds

Malware goes to the movies

Dangerous liaisons

The Essential Guide to IT Transformation

Online attackers have started to experiment with embedding malicious code or links to such code in different video formats.

On Tuesday, anti-virus firm McAfee warned Windows users that the company had discovered a worm, dubbed W32/Realor, actively infecting Real Media files. The infected video files do not contain an exploit for the RealOne or Real players, but a hyperlink that points to a malicious website. When infected files are opened, the victim is referred to the web ite, which attempts to compromise their computer using a previously patched flaw in Internet Explorer.

There are numerous disadvantages to using video files to carry malicious code, but using the technique may allow attackers to take advantage of users' expectations, said Craig Schmugar, senior threat researcher with McAfee's anti-virus emergency response team.

"A chunk of people generally regard video files as safe, where they might treat screensavers and Office documents with some caution," Schmugar said.

While W32/Realor had not spread far, the incident came the same day that Microsoft distributed a patch for five security vulnerabilities in Adobe's Flash Player - software that is frequently used to play video streamed from popular internet sites. A week earlier, users of the social networking site MySpace attempted to use links in video files to surreptitiously install adware on visitors' computers.

The attention is unsurprising. Vulnerability researchers, for one, have increasingly focused on media players. In 2006, 19 medium and high-severity flaws were found in Apple's QuickTime Player, two in RealOne and Real Player, another two in Microsoft's Windows Media Player, and three in Adobe's Flash Player, according to the National Vulnerability Database. SecurityFocus sought comment from all four companies. Apple and Microsoft did not respond to the request, while RealNetworks could not provide a spokesperson in time for this article.

To date, actual video files have rarely been used as a vector of attack - typically, video plays only an incidental role. Many mass-mailing email viruses, such as the Kama Sutra or Blackmal worm, attempt to lure victims by offering an attachment that masquerades as a video. In other incidents, a Windows virus shipped on Apple video iPods and the virus - again, Blackmal - sent out to subscribers of Google's Video mailing list.

Yet, the increasing popularity of video downloads and streaming internet video - as demonstrated by the $1.6bn valuation that Google placed on internet video startup YouTube - will likely mean that online attackers will increasingly find ways to utilise the digital media as a method of compromising PCs, security experts said.

"It is my belief that most malware targets the 'large audience'," said Val Smith, co-founder of OffensiveComputing.net. "So following that, I do think that YouTube is, and will be, a target...As soon as someone comes up with a good and simple video malware kit - if they haven't already - then I think we start to see this become a problem."

Video and other media files to which people frequently link could use unique methods to boost infection rates. Malicious code could use true viral marketing, for example, using the reputation systems of community-oriented video sites such as YouTube to attempt to make infected videos more popular. The MySpace worm Samy used such techniques to build a massive friends list for the MySpace user, "Samy."

Google has processes in place to make such attacks difficult, the company said in a statement emailed to SecurityFocus.

"We work constantly to prevent people from misusing our services to distribute malicious software," Google said in the statement. "When we become aware of an instance where this happens, we take immediate action to limit user exposure.

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.