Microsoft finds malware hidden in new computers in China
Microsoft has found malware on new computers its employees purchased in various cities in China as part of an investigation into the security of the supply chain. That finding led researchers to a botnet called Nitol and a court order giving the company permission to take technical measures to disrupt the botnet.
The effort, dubbed Operation b70, began in August 2011 when it decided to see if there was any merit to claims that counterfeit software and malware were being installed on computers by suppliers before they hit the retail shelves in China. So, the company had employees go into stores and buy 10 laptops and 10 desktop computers.
"We went into what they call 'PC Malls.' We wanted to get a sampling of what an average consumer in China would get," Richard Boscovich, assistant general counsel for Microsoft's Digital Crimes Unit, told CNET in an interview today. "We were surprised how quickly we were able to find something to back up the suspicion."
The researchers discovered that four of the 20 computers came pre-loaded with malware, including some that was capable of spreading through USB flash drives. One was infected with the Nitol virus, which installs a backdoor on computers so they can be used as part of a botnet to send spam or attack Web sites. Another computer had the Trafog backdoor that allows an attacker remote access via File Transfer Protocol (FTP). The third had Malat, which is an Internet Relay Chat (IRC) backdoor and the fourth was EggDrop, which Microsoft said is suspicious but not necessarily malicious, according to the report that is accessible on this Microsoft blog post.
The malware was not active, except for Nitol, which was actively running and had attempted to connect to a command-and-control server on a domain owned by a Chinese company, 3322.org, that has been linked to malicious activity since 2008, Boscovich said.
Microsoft this week was granted permission by federal court in eastern Virginia to use a sinkhole technique to trick infected computers into communicating with researcher-controlled servers instead of command-and-control servers on the nearly 70,000 subdomains hosting 565 types of malware, he said. Some of the malware was capable of doing lots of nasty things, including remotely turning on microphones and video cameras, recording key strokes, and stealing data in other ways, the company said.
Microsoft has requested a temporary restraining order (TRO) against the owner of the domain and "John Does" representing owners of the subdomains. There is a hearing is scheduled for September 26 in the case and Boscovich said the company is hoping to convince the owner of 3322.org to reveal the identities of whoever registered the affected subdomains.
In response to the granted TRO, the Public Internet Registry, as the registrant for all .org domains, began pointing the 3322.org domain, which hosts the Nitol botnet, to Microsoft's newly created domain name system, Microsoft said. This system enabled the company to block operation of the Nitol botnet and the 70,000 malicious subdomains hosted on the 3322.org domain, while allowing all other traffic for the legitimate subdomains to operate without disruption.
As far as the pre-loaded malware problem, Boscovich said policy makers need to realize there are problems and do something to make sure that the supply chain is secure.
"Apparently, what happens is the operating system is installed somewhere between the wholesaler and the retailer and it's possible that somewhere in there malware was introduced," he said.
Source
Tags:
- Microsoft Finds Malware Hidden In New Computers In 2022
- Microsoft Finds Malware Hidden In New Computers In 2021
- Microsoft Finds Malware Hidden In The Sand
- Microsoft Finds Malware Hidden In Christ
- Microsoft Finds Malware Hidden In The Hill s
- Microsoft Finds Malware Hidden Message For Roblox Password
- Microsoft Finds Malware Hidden Pictures
- Microsoft Malware Removal Tool
- Microsoft Malware Scanner
- Microsoft Malware Check
- Microsoft Finds 3 47 Tbps Ddos
- Microsoft Findstr
Blog Archive
-
▼
2022
(148)
-
▼
December
(87)
- Google To Pay Nearly $43M Over Collection Of Andro...
- Learn How To Read Supplement Labels With These Tips
- Apple's IOS 15 Update Is Here, But You Might Want ...
- Tesla Solar Roof: The Sleekest Solar Option Isn't ...
- Dell Precision 5470: Packing Peak Performance In A...
- Facebook To Meta: A New Name But The Same Old Prob...
- Does Your Baby Need Toys? What Developmental Exper...
- How To Play PS Plus Premium Games On Your PC
- Best MacBook Pro Alternatives For 2022
- This Is Verizon's First 5G Smartphone
- Lenovo's Latest Legion 7 Gaming Laptops Are Its Mo...
- Could We See The Pixel 6A Today? All The Rumors We...
- Asus ZenWiFi AX Review: This Wi-Fi 6 Mesh Router H...
- Facebook, WhatsApp And Instagram Coming Back Onlin...
- WWE 2K20 Is Being Eviscerated By Fans For Its Insa...
- Microsoft Finds Malware Hidden In New Computers In...
- Microsoft Reportedly Blocks Older PCs From Windows...
- The New Features Coming To Your Android Phone
- Acura's Return To Formula 1 Came With Wins For Hon...
- Deleting Your Twitter? Here's How To Archive Your ...
- YouTube Names The Top 10 Most-viewed Videos Upload...
- Why This CryptoPunk NFT Sold For $532 Million. Sor...
- New IOS Malware Tricks Its Way Onto IPhones In Chi...
- This Segway Ninebot Max Might Just Be The Best Ele...
- Facebook Parent Meta To Settle Cambridge Analytica...
- 13-inch MacBook Pro With Apple M1 Chip Hits 20 Hou...
- Google Maps And Search Will Clearly Label Faciliti...
- Facebook, YouTube To Restrict Some Russian State-C...
- ESPN, Tom Brady To Launch NFT Collection
- Netflix: The 44 Absolute Best Movies To Watch
- How The Apple Watch Saved My Life -- And Could Res...
- Alphabet's Wing Unveils XXL And XXS Drones For Mor...
- High Gas Prices Are Revving Up This Online Anti-Ca...
- E-mailed Malware Disguised As Group Coupon Offers ...
- Are You Drinking Harmful Bacteria? Here's How To C...
- NHTSA To EV Drivers: No Selectable Low-Speed Sound...
- Garmin Venu Sq Review: A Solid Fitness Tracker Wit...
- Samsung Is Launching Yet Another Cheap 5G Phone In...
- Truth Social App To Remain In Android Limbo Over C...
- DJI Made A $119 Phone Camera Stabilizer That Folds...
- Compare FHA Mortgage Rates
- LG's Rumored Rollable Phone Shows Up In A YouTube ...
- Anker Nebula Cosmos Laser 4K Projector Review: Get...
- Collagen Vs. Collagen Peptides: Which One Is Better?
- Fitbit Recalls Ionic Smartwatches Over Burn Hazard
- 2017 Kia Niro Review: 2017 Kia Niro Is A Solid Hyb...
- Affordable Yi Action Cam Lands On Amazon For The H...
- The DJI Avata Is The Most Fun I've Had Flying A Dr...
- Record-holding Batman Costume Stocked With 23 Work...
- Think You Might Have Monkeypox? Here's What To Do
- Extra Sneaky Hammertoss Malware Acts Just Like You...
- Windows 11 Finally Has A Quick Way To Switch Your ...
- Facebook Parent Meta Reports First-Ever Revenue Drop
- Pixar's 'Turning Red' Teams Up With Firefox To Cel...
- 5 Hidden IOS 16 Features We Didn't Expect To Find
- Return Of Meme Stocks: Why Bed Bath & Beyond And G...
- IPad Deal Alert: Save Up To $70 On Select Configur...
- Google's Promise To Simplify Tech Puts Its Devices...
- NASA To Launch Scientific Study Of UFOs
- 2023 Toyota Highlander Adds Turbo Power, New Displ...
- 5 Streaming Services You Can Cancel In August, FOM...
- You Should Be Using These IPad Features
- Lenovo IdeaPad Gaming 3 Laptops Are Upscale Option...
- Garmin Fenix 7 And Epix Up The Ante With Endurance...
- GM Will Make EV Motor Components In New York With ...
- Essentials To Pack In Your Diaper Bag
- Ford's F-150 Lightning Gets More Horsepower And Mo...
- Doctors Call On Spotify To Stop COVID Misinformati...
- DeLorean Alpha5 Gullwing EV Is A Not-So-Retro Revival
- Mini-LED TV: What It Is And How It Improves Samsun...
- The Easiest Method To Remove A Tick Is One That Do...
- IPad Air 2022 Review: M1 Is A Very, Very Nice Addi...
- Best Car Interior Cleaner For 2022
- Dell XPS 13 OLED (9310) Review: Beautiful Design T...
- Expand Your Workspace With The 27-inch HP FreeSync...
- Make Better Coffee At Home With The Sboly Burr Gri...
- GoPro Reveals What The GPS In The Hero5 Black Came...
- Netflix Releases 3 New Mobile Games, Including Cut...
- LastPass Says No Passwords Stolen In Data Breach
- Google Maps Is Adding A 3D 'Immersive View' That's...
- Apple Watch SE Vs. Series 6 Vs. Series 3: How To C...
- Twitter Rumored To Make TweetDeck A Subscription S...
- IPhone 14 Is Coming Soon: Report Points To A Sept....
- Snapchat's Newest AR Effects Work With Apple's IPh...
- Star Wars Celebrates Jon Favreau With Black Series...
- Save Up To $250 Off Robot Vacuums From Eufy -- Tod...
- Pokemon Scarlet And Violet Trailer Shows Off New P...
-
▼
December
(87)
Total Pageviews
Search This Blog
Popular Posts
-
Kerastase oleo relax treatment for hair, kerastase oleo relax serum, kerastase oleo relax masque, kerastase oleo relax hair products, kerast...
-
Perodua viva elite, perodua viva elite premium, perodua viva elite 2010 for sale in sri lanka, perodua viva elite front bar how to remove, p...
-
Kerastase chronologiste perle, kerastase chronologiste, kerastase chronologiste mask, kerastase chronologiste treatment, kerastase chronolog...