A new malware outbreak is being spread via USB keys. The US Computer Emergency Response Team (US-Cert) is warning users and administrators to be on the lookout following a rise in incidents. Attacks are taking two main forms.
The first infection tactic involves malware that simply copies itself to all storage devices which are connected to the infected PC. The tried-and-true attack method is usually delivered by way of social engineering, often posing as video or application files.
The second method uses the Windows Autorun feature. The malware copies itself from the infected machine onto a USB drive as a file named ‘autorun.inf’, allowing the file to automatically execute and perform a new infection when the drive is plugged into another system with Autorun enabled.
USB drive attacks use a method as old as the computer virus itself. Early viruses spread themselves by infecting floppy disks and local networks as floppies were passed around offices, a method known as sneaker net attacks.
Though the tactic eventually gave way to web page and e-mail borne attacks, security specialist Symantec suggests the increasing use of media players and USB thumb drives is making the “sneaker net” attack method popular once more.
To safeguard against attacks, US-Cert is says users and administrators should disable Autorun for connected devices. Symantec also suggests that administrators set policies which limit the ability of users to mount connected devices unless absolutely necessary.





Subscribers 0
Fans 0
Followers 0
Followers