Windows RPC exploit spawns bots and worms

An evil spell


Miscreants are taking advantage of slowness in patching systems with an emergency Windows security fix issued late last month to spread malware.

Exploit toolkits for the MS08-067 are dropping bots that turn compromised machines into drones in a DDoS attack network, among other attacks. The attack code, thought to originate in China, takes advantage of a flaw in Windows RPC code to weave its evil spell.

Microsoft patched the vulnerability with an out-of-sequence patch on 23 October. Trojans exploiting the flaw were spotted the day afterwards. Analysis of these strains suggested they may have been in circulation before Microsoft issued its patch.

Things have since kicked up a gear with reports of the KernelBot DDoS attack tool as well as other separate reports, via the SANS Institute's Internet Storm Centre, that worms based on the vulnerability are circulating in the wild. Symantec rates the Wecorl worm as a low-risk threat.

The latest worm attacks are distinct from the earlier Trojan attacks, and low level. By comparison the Blaster (aka LoveSan worm) - which exploited an earlier flaw in Microsoft's RPC technology five years ago - caused widespread infection and system instability. ®


Keep Reading

Tech Resources

Webcast Slide Deck | How backup modernization changes the ransomware game

If the thrill of backing up your data and wondering if you will ever see it again has worn off, start the new year by getting rid of the lingering pain of legacy backup. Bipul Sinha, CEO of the Cloud Data Management Company, Rubrik, and Miguel Zatarain, Director of Global Infrastructure Technology at PACCAR, Fortune 500 manufacturer of trucks and Rubrik customer, are talking to the Reg’s Tim Phillips about how to eliminate the costly, slow and spotty performance of legacy backup, and how to modernize your implementation in 2021 to make your business more resilient.

What WAF is right for you

Applications are architected in many ways, but all need protection from threats. Learn the most important things to consider when choosing a WAF.

Three reasons you need a hybrid multicloud

Businesses need their IT teams to operate applications and data in a hybrid environment spanning on-premises private and public clouds. But this poses many challenges, such as managing complex networking, re-architecting applications for the cloud, and managing multiple infrastructure silos. There is a pressing need for a single platform that addresses these challenges - a hybrid multicloud built for the digital innovation era. Just this Regcast to find out: Why hybrid multicloud is the ideal path to accelerate cloud migration.

Top 20 Private Cloud Questions Answered

Download this asset for straight answers to your top private cloud questions.

Biting the hand that feeds IT © 1998–2021