MiniDuke Malware Exploits Adobe Flaw, Uses Twitter
A newly-discovered form of malware can reportedly spread via malicious PDF documents. An infected system can then be controlled via Twitter.
Called 'MiniDuke' by security experts, it appears the malware is still very active.
Russian security company Kaspersky Lab, who recently discovered MiniDuke, said that recovered fragments of the malware had been created as recently as February 20, 2013. That has led Kaspersky researchers to suggest that MiniDuke is still being used to attack computer systems.
Hackers Capitalize on Adobe Flaw
The malware is reportedly being spread in the form of malicious PDF documents (likely distributed via emails). Kaspersky Lab researchers say that the software itself is quite tiny -- just 20 kilobytes in size.
Researchers add that the bug takes advantage of a vulnerability in Adobe Reader software (versions 9 through 11) which has since been patched. However, it's likely many Adobe users have not yet applied the fix and remain vulnerable to attack. (Source: pcworld.com)
By exploiting the Reader flaw, hackers are able to install a downloader on a victim's PC. This gives them a backdoor approach which allows them to remotely access a compromised PC.
Twitter Used to Expand Infection
Once a computer is infected, the attack code tells the PC to contact Twitter accounts controlled by MiniDuke operators. This allows the malware creators to use Twitter to relay instructions to the infected computer.
Instructions are sent in the form of GIF image files. Once these files make their way onto a compromised system, they extend control of the PC and allow the malware creators to install new and more sinister types of malicious software.
Security experts say that this is a remarkably advanced form of attack that is difficult to detect and remove.
"This model is flexible and enables the operators to constantly change how their backdoors retrieve further commands or malcode as needed," Kaspersky researchers noted in a recent report. (Source: informationweek.com)
Luckily, it does not appear as though MiniDuke has spread too far. At this point there have been just 59 reported infections in 23 countries, including the United States, Brazil, Israel, Japan, and much of Europe.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.