Feeds

Baby got .BAT: Old-school malware terrifies Iran with del *.*

New nasty capable of causing about an hour of annoyance

Top 5 reasons to deploy VMware with Tegile

A surprisingly simple disk-wiping malware has set off alarm bells in Iran after surfacing in the Middle East nation.

The software nasty deletes everything on storage drives attached to infected Windows PCs on specific dates, according to the Iranian security emergency response team. The malware was detected in one or more targeted attacks although the identity of the intended victim is not known.

Its operation is similar to the data-destroying worm Shamoon that ransacked Gulf oil giants earlier this year, but the two pieces of software otherwise appear unrelated.

BatchWiper, as the snared malware's name suggests, uses a Windows batch file to remove files from infected machines, according to an analysis by security tools biz AlienVault.

A self-extracting RAR archive called GrooveMonitor.exe is used to drop the malware's files onto a system. However the same software nasty can easily be packaged in other ways and appear under different guises.

Jaime Blasco, labs manager at AlienVault, said that it is not clear how BatchWiper malware is spreading. "The dropper could be deployed using several vectors, ranging from spear phishing emails, infected USB drives, via some other malware already running on computers, or an internal actor uploading it to network shares," he said.

Blasco concludes that despite its simplicity, BatchWiper is capable of causing significant irritation if its file-wiping code is executed. Once that kicks in, it's time to break out the backups or your favourite undelete utility. ®

Remote control for virtualized desktops

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?