Trojan Piggybacks on Windows Updater

May 15, 2007

Researchers discover a Trojan that uses an integral part of Windows to download files onto infected systems.

At least one Trojan virus writer is now using an integral part of the Windows operating system - BITS (Background Intelligent Transfer Service) - to download files to already infected systems.

Windows Update uses BITS as an asynchronous download service to fetch patches, updates and other files - and, in this instance, malware.

Security researcher Frank Boldewin, along with Symantec's Elia Florio, discovered the technique the week of May 7 after analyzing a recent Trojan distributed via spam e-mail in Germany toward the end of March. According to Florio's May 10 posting on Symantec's site, Boldewin determined that the Trojan - which he detected as "Downloader" - was using BITS to bypass the firewall and download files without firewall inspection. As part of the operating system, BITS is trusted and gets passed through without having to go through the firewall.

According to Florio, more common methods used by malware to bypass firewalls include running a continuous thread that sends "Yes, accept" messages to the firewall window, which warns users about strange network connections; shutting down the firewall or killing its processes; injecting malicious code into Internet Explorer or other processes in the firewall's trusted applications list; and patching network drivers to disable firewall filtering.

This new technique doesn't constitute a significant new threat, as the Trojan doesn't evade anti-virus products and is only using BITS as a means of connection. Still, it's an interesting new development in that attackers are using a component of Windows itself, rather than having to write downloaders or updaters themselves, Oliver Friedrichs, director of Symantec Security Response, said in an interview.

"The main impact of this particular threat is the ability to evade outbound firewall filtering," Friedrichs said. "That's not a new concept, … - but - it's another novel way malicious code can use outbound connections."

Symantec, based in Cupertino, Calif., observed this technique being discussed as a means of downloading files on Russian hacker boards at the end of 2006. This is one of the first times it's been seen in the wild, Friedrichs said, and it's something the company expects to see more of in the future.

A Microsoft spokesperson said the company is aware of public reports that BITS is being used by the Trojan, whose official name is TrojanDownloader:Win32/Jowspry, to bypass policy-based firewalls in order to install additional malware.

However, Microsoft, based in Redmond, Wash., says the bypass relies on TrojanDownloader:Win32/Jowspry already being present on the system - in other words, BITS isn't an attack vector for the initial infection.

"The bypass most commonly occurs after a successful social engineering attempt lures the user into inadvertently running TrojanDownloader:Win32/Jowspry, which then utilizes BITS to download additional malware," the spokesperson said in an e-mail exchange.

Microsoft recommends that any users who believe their systems have been affected by TrojanDownloader:Win32/Jowspry visit Windows Live OneCare to scan their systems, determine if they are infected and clean up all currently known variants of the Trojan.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4 /5 (18 votes)


May 15, 2007 all stories

Comments: 0

4 /5 (18 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Trojan horse for ovarian cancer -- nanoparticles turn immune system soldiers against tumor cells
    created Jul 15, 2009 | popularity not rated yet | comments 0
  • Digital frame virus traced to China
    created Feb 19, 2008 | popularity not rated yet | comments 0
  • Researcher Reveals 2-Step Vista UAC Hack
    created May 17, 2007 | popularity not rated yet | comments 0
  • Mac's Boot Camp spawns security worries
    created May 17, 2006 | popularity not rated yet | comments 0
  • Asia, U.S. high on spam-relaying report
    created Apr 21, 2006 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Trying to adapt a fuel gage circuit
    created 12 hours ago
  • Pushing the piston.
    created 17 hours ago
  • Do Camcorders/ Video camera have Sensors in them?
    created 22 hours ago
  • Aspiring Engineering major looking for general answers
    created Nov 19, 2009
  • More from Physics Forums - General Engineering

Other News

Intel logo A

Intel wants a chip implant in your brain

Technology / Hi Tech

created 1hour ago | popularity 4.3 / 5 (3) | comments 3

(PhysOrg.com) -- Computer chip maker Intel wants to implant a brain-sensing chip directly into the brains of its customers to allow them to operate computers and other devices without moving a muscle.


The Symbian platform is used on almost 50% of mobiles worldwide

Spotify launches application for Nokia phones

Technology / Software

created 1hour ago | popularity not rated yet | comments 0

Swedish streaming software Spotify announced on Monday the launch of a music application for the Symbian platform, used by the world's biggest mobile phone maker Nokia and other smartphones.


Workers at the Statkraft Osmotic power plant prototype in Tofte

Harnessing the power of salt, Norway tries osmotic power

Technology / Energy

created 2 hours ago | popularity not rated yet | comments 2

After wind, sun, currents and tides, a company is preparing to make clean electricity by harnessing another natural phenomenon, the energy-unleashing encounter of freshwater and seawater.


Microsoft has held talks with Rupert Murdoch's News Corp over removing its news websites from Google, a report said

News Corp, Microsoft hold talks on Google: report

Technology / Internet

created 2 hours ago | popularity 5 / 5 (1) | comments 1

Microsoft has held talks with Rupert Murdoch's News Corp over a possible plan for the software giant to pay the media company to remove its news websites from Google, a report said Monday.


A woman uses her mobile phone near a share prices board in Tokyo

Mobile multimedia revenues tipped to dethrone text

Technology / Telecom

created 1hour ago | popularity not rated yet | comments 0

Multimedia services will surpass text messaging this year as the main source of mobile operators' non-voice revenue in the Asia-Pacific region, industry analyst IDC said Monday.