Trojan Horse Delivered In Automatic Update

Trojan Horse - One Mans "Worse Case Scenario"system privilege it is running at, it modifies the
Predictioncommunication protocols and services on the system
---------------------to prevent any type of external communication to its
This is a fictional article about a Trojan Horse Virus, orlocal peers and external (Internet) hosts. It does this in
you could say it is one mans prediction of a "worsesuch as way that the only immediate method to
case scenario". Because of the field I'm in, I maintain arecover from this is a system roll-back, system repair,
personal list of my top 10 "worse case scenarios".or restore from near-line media, such as tape or disk.
Every time I perform a security assessment I run intoAnd as far as system recovery is concerned, I can tell
something new or identify a situation that is ripe for ayou that many people even in corporate entities do not
potential vulnerability. I think we could all agree that noperform the most basic steps to be prepared for a
respectable or ethical company would intentionallyquick system disaster recovery. In some cases, some
deliver a malicious piece of code as part of a helpfulof the most important recovery services have been
update solution. However, the reality is that humandisabled because of lack of system resources or disk
beings are behind technology and human beings arespace (which is amazing given how inexpensive this is
unpredictable and fallible.Many major operating systemanymore).What Could Be The Impact Of This
vendors have automatic update services. Many"Trusted" Trojan Horse
hardware vendors and other software packages---------------------
have followed this trend, incorporating automatedJust about every time you install a new application or
update services into their products. In some cases, thepiece of software you increase the time it takes to
services for automatic updates run as the localboot your PC and in some cases decrease its
"system" account. This account has the ability toperformance. On thing that drives me crazy is printing
access and modify most of the operating system andsoftware. For the life of me I cannot understand how
application environment. When automatic updatesor why printer support software could total 400MB in
were relative new, many people would perform thesize, but they sometimes do. Not only that, they tend to
updates manually, however, as time has progressed,load all kinds of unnecessary real-time running applets.
many now trust these services and allow the updatesHP printers are notorious for this. Be very aware of
to proceed in a truly automated fashion.The Final Stepwhat it is you are loading and only load those
Before The Hammer Fallscomponents that you need. Even some off-the-shelf
---------------------software packages load adware and other not so
So let's expand upon our "worse case scenario". Ahelpful applets. Also, when you uninstall software, not all
new service pack is just about ready for release. Thethe software gets uninstalled in many cases. One thing
last step prior to public release is quality control /I suggest is to purchase a registry cleaner. This can
validation. The team of people performing this taskdramatically decrease boot times and in many cases
includes a significantly disgruntled employee (Or mayincrease the overall performance of your PC.People
he/she is going through a horrible life crisis and has notare already concerned about identity theft, or at least
much to lose). When people are in pain or distress it isthey should be. I recently spoke with a business
not uncommon for them to project this same feelingassociate that told me that even with everything he
onto others in any way they can. So, instead ofdoes to keep his identity secure he has been the
performing their job in the normal fashion, they decidevictim of identity theft not once, but twice. If your user
to incorporate a malicious payload into the forthcomingid's, online accounts, passwords, financials, or other
update.The First Step For The Trojan Horse: Evasionconfidential information winds up on the Internet for any
---------------------anonymous person to see, you can bet it will be used
This payload has some unique characteristic, three toin a way to cause you problems. Even if only 10% of
be precise. First, it is constructed in such as way to notthe global systems fell victim to this Trojan Horse, the
appear as something malicious. The anti-virus andcut off of communications could cost businesses
anti-spyware programs currently on the market won'tbillions of dollars and potentially impact their reputation
be able to detect it through anomalous detectionas "secure" institutions.Conclusion
techniques.The Second Step For The Trojan Horse:---------------------
Information CollectionIf we don't think that this "worse case scenario" can
---------------------happen, then we're kidding ourselves. Recently, one of
Secondly, it has been instructed to wait 12 hours tothe market leaders in the perimeter defense business
activate to start searching your computer an networkhad to recall a service pack because it contained a
for important files that may contain financial, healthcare,significant "bug" that could result in a security breach; a
and other confidential information such as userservice pack that can be delivered through and
accounts and passwords. It then sends this informationintelligent update service. Obviously there has to be a
to anonymous systems on the Internet. Because thiscertain level of trust between us, the consumer, and
"Trojan horse" has been incorporated into anthe vendors of hardware / software we rely on. I'm
automated update by someone with reasonable skills,not entirely sure what "fail-proof" solution can be put in
it is instructed to only perform the collection of data forplace to prevent something like this from happening.
12 hours. Given the number of global systems thatAlthough I'm sure there are quite a few checks and
allow automated updates, 12 hours should be morebalances in place already. The bottom line is, if you or I
than enough. The person behind this realizes thatcan image a scenario like this, there is always a
someone will quickly identify that something malicious ischance of it happening. In my case, I usually wait for
going on and start to roll-out a defense solution to haltseveral days to apply new service packs and
the process.The Final Step: Incapacitatehot-fixes. Hopefully someone else will find the problem,
---------------------correct it, and then I'll apply it.You may reprint or publish
Finally, the Trojan Horse will cease it's data collectionthis article free of charge as long as the bylines are
and deliver it's final blow. Because of the level ofincluded.