Malware uses Windows security feature to block security software

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
Summary: Trend Micro finds malware using Windows Software Restriction Policies to block security software from running.

Trend Micro researchers have written about a twist in the BKDR_VAWTRAK banking malware in Japan. It is using Windows Software Restriction Policies (SRP) to restrict the privileges of security software, including Trend's.
SRP is a feature that was introduced in Windows XP and Windows Server 2003 and is generally administered through Group Policy. It is designed to allow administrators to blacklist and whitelist specific executable programs, or to restrict them to unprivileged (standard user) execution.
This is not the first time SRP has been used by malware, but Trend Micro says that the prominence of VAWTRAK attacks makes it more significant.

SRP can also be invoked with the Local Policy Editor in any version of Windows:

srp-sample-620x443.jpg

And since policies translate to registry keys on the systems being managed, it is also possible to create the registry keys directly, which is what Trend Micro reports the malware does. In the example above, the registry keys are placed in HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers.
When the user attempts to run the executable, they are prevented by Windows from doing so:

srp-blockage-572x139.jpg

The malware must itself be executing in a privileged context in order to create these registry keys, and it must execute in spite of the presence of the security software it is attempting to block. Potentially, updates to the security software could find the malware, but not if the malware has been blocked in this way.

Ironically, the Microsoft TechNet article introducing SRP on new years day 2002 describes how it can be used to "fight viruses." The other purposes described in the article are:

  • Regulate which ActiveX controls can be downloaded
  • Run only digitally signed scripts
  • Enforce that only approved software is installed on system computers
  • Lockdown a machine
Trend Micro lists 53 products and companies for which the malware looks on the infected system. If it finds any, it creates an SRP for that program.

Source
And
http://blog.trendmicro.com/trendlab...rity-feature-abused-blocks-security-software/
 
Last edited:

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
Oh oh..o_O The BKDR_VAWTRAK malware's use of "Windows own Software Restriction Policies",:eek: in Japan (the birth place of Judo) of all places, represents a Warrior's opponent who has been vanquished by his own power:mad: turned against him!:confused:
;)
 

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
vadertypography2.jpg


"...is a Japanese martial art that first became widely known in the early 20th century under the headmastership of Takeda Sokaku. Takeda had extensive training in several martial arts (including Kashima Shinden Jikishinkage-ryū and sumo) and referred to the style he taught as "Daitō-ryū" (literally, "Great Eastern School"). Although the school's traditions claim to extend back centuries in Japanese history there are no known extant records regarding the ryū before Takeda. Whether Takeda is regarded as either the restorer or the founder of the art, the known history of Daitō-ryū begins with him.Takeda's best-known student was Morihei Ueshiba, the founder of aikido."
https://en.wikipedia.org/wiki/Aikijutsu

Darth Umbra, your students learn something every day:)
...we are allowed to continue drawing breath.:cool:
 
Last edited:

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
vadertypography2.jpg


"...is a Japanese martial art that first became widely known in the early 20th century under the headmastership of Takeda Sokaku. Takeda had extensive training in several martial arts (including Kashima Shinden Jikishinkage-ryū and sumo) and referred to the style he taught as "Daitō-ryū" (literally, "Great Eastern School"). Although the school's traditions claim to extend back centuries in Japanese history there are no known extant records regarding the ryū before Takeda. Whether Takeda is regarded as either the restorer or the founder of the art, the known history of Daitō-ryū begins with him.[1]Takeda's best-known student was Morihei Ueshiba, the founder of aikido."
https://en.wikipedia.org/wiki/Aikijutsu

Darth Umbra, your students learn something every day:)
...that we are allowed to continue drawing breath.:cool:
Epic!!:):)
 

Mateotis

Level 10
Verified
Well-known
Mar 28, 2014
497
Oh, the irony! It's very fascinating to see the creativity of malware authors. Although at least you are notified exactly why you cannot run your AV and can go ahead and look it up or fix it yourself. :)
 
  • Like
Reactions: Cats-4_Owners-2

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top