Malware Automates Storing of Data Haul on File-Hosting Site SendSpace
Added 7th Feb 2012Trend Micro researchers have discovered a piece of malicious software that automatically uploads its stolen data cache to the SendSpace file-sharing service for retrieval.
Malware authors have used file-hosting and sharing servers for that purpose before, but this is the first time malware has been noticed to do that automatically, wrote Roland Dela Paz, a threat response engineer with Trend Micro.
SendSpace accepts files and then generates a link that can be shared with other people to download the content in the files. The malware has been configured to send files, copy the download link and send it to a command-and-control server along with the password needed to access the archive, Dela Paz wrote.
It appears SendSpace's terms of service would prohibit use of the site that way. SendSpace said in response to an email that it was "notified of this several days ago by Trend Micro themselves, and we're working to find a solution for this."
File-storage services offer several advantages for cybercriminals, said Rik Ferguson, director of security research and communication for Trend Micro in Europe.
Although the cybercriminals often use networks of proxy computers to mask how they are communicating with a compromised computer, using a storage service adds another layer, Ferguson said. "It breaks in some ways the chain of evidence," he said.
Also, authorities would be less likely to take down a legitimate file-hosting service than a new server set up by scammers, Ferguson said.
The services are especially useful for so-called Advance Persistent Threat attacks, where cyberspies seek to infiltrate an organization for a long period of time, Ferguson said. There is also a better chance that organizations that are hacked will not regard outbound connections to a file-hosting service as suspicious, making it less likely the connection will be shut down, he said.
"Basically it's criminals taking advantage of public infrastructure to appear less suspicious," Ferguson said.
latest news
-
UK Government Publishes Open Data Institute Plans
The new Open Data Institute will initially support start-ups that use open data to drive economic growth
-
Shareholders sue Facebook, Zuckerberg, Morgan Stanley
Class action lawsuit, launched Wednesday, alleges info was hidden by Facebook, Morgan Stanley prior to IPO
-
Windows 8 Puts End to Endless Reboots
OS kicks out to recovery tools after second boot failure
-
Apple is 'Most Valuable' Global Brand Despite Jobs' Death
Apple boosted its brand value by 19% in the past year to $182,951 billion, or 37 percent of its market capitalisation.






