Malware uses Google Docs as proxy to command and control server

Malware uses Google Docs as proxy to command and control server

تاریخ ایجاد

ID: IRCNE2012111681
Date: 2012-11-20

According to "computerworld", Security researchers from antivirus vendor Symantec have uncovered a piece of malware that uses Google Docs, which is now part of Google Drive, as a bridge when communicating with attackers in order to hide the malicious traffic.
The malware -- a new version from the Backdoor.Makadocs family -- uses the Google Drive "Viewer" feature as a proxy for receiving instructions from the real command and control server. The Google Drive Viewer was designed to allow displaying a variety of file types from remote URLs directly in Google Docs.
"In violation of Google's policies, Backdoor.Makadocs uses this function to access its C&C [command in control] server," said Symantec researcher Takashi Katsuki, Friday in a blog post.
It's possible that the malware author used this approach in order to make it harder for network-level security products to detect the malicious traffic, since it will appear as encrypted connections -- Google Drive uses HTTPS by default -- with a generally trusted service, Katsuki said.
Backdoor.Makadocs is distributed with the help of Rich Text Format (RTF) or Microsoft Word (DOC) documents, but does not exploit any vulnerability to install its malicious components, Katsuki said. "It attempts to pique the user's interest with the title and content of the document and trick them into clicking on it and executing it."
Like most backdoor programs, Backdoor.Makadocs can execute commands received from the attacker's C&C server and can steal information from the infected computers.
However, one particularly interesting aspect of the version analyzed by Symantec researchers is that it contains code to detect if the operating system installed on the target machine is Windows Server 2012 or Windows 8, which were released by Microsoft in September and October respectively. Symantec currently rates the distribution level of the malware as low.

برچسب‌ها