Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: dayglored

It’s late and I may be missing something obvious — How does this malware reside solely in memory with nothing written to the disk? How does it get into the memory on power-up if not from the disk?


26 posted on 06/15/2015 11:22:48 PM PDT by Bob (No, being a US Senator and the Secretary of State are not accomplishments; they're jobs.)
[ Post Reply | Private Reply | To 1 | View Replies ]


To: Bob
> How does this malware reside solely in memory with nothing written to the disk? How does it get into the memory on power-up if not from the disk?

The malware is in the form of a 64-bit kernel-level driver, which because it will be loaded into such a secure part of the operating system (the kernel), must be signed digitally and verified. That's what the stolen key/cert is about -- it "validates" to Windows that the malware-infected driver is okay to load.

So in that sense the malware has a persistent presence, in the loadable driver, on the machines where it loads on boot.

But the driver is loaded into special machines on boot -- gateways, routers, firewalls -- that specifically have the internet on one side and the corporate local network on the other side. This means the driver gets to see, filter, change, redirect, or block any network traffic it wants to. It also -- and this is important -- can dynamically supply the infected driver over the corporate network to any/all other machines inside.

And in that way, those machines do NOT have a persistent, disk-resident copy of the malware.

Or at least, that's the picture I get from this Kaspersky release:

https://securelist.com/blog/research/70641/the-duqu-2-0-persistence-module/
If you read that and get a different picture, by all means write back and correct my misapprehension. Thanks!
27 posted on 06/16/2015 12:57:01 AM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 26 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson