Great that Sophos quickly had a signature for the threat, but AV is basically an ineffective, reactive solution for zero-day threats like this. More proactive solutions like Application Whitelisting exist that are proactive and prevent any new code from running, which would have negated this threat and all others like it. Much better fit in closely controlled environments like those that run Siemens Process Control software,. The better solutions also stop in-memory attacks too.
This is a very sophisticated attack. This worm is looking to infect systems that run Siemens SCADA (software that run power plants, nuclear aircraft carriers). It uses a signed digital certificate stolen from Realtek. Disabling Autoplay will not stop this. You just need to browse to the folder with the files. I can't believe they run nuclear aircraft carriers on windows. Hope these people changed the default password.
@muk546 macs are overrated and they suck when it comes to games (portal lagged like a son of a cock on my bothers mac) and linux isent an operationg system its a mod
@ThePsychoticScyth396 Lol at your Linux comment. I don't understand how anyone could justify linux not being an operating system. Especially how much it has deviated from unix.
Worry more about Malware, vulnerability through Virus's/root kits are less common. Virus's tend to attack servers rather than individual users. My guess this was on the 32bit version of Win 7 since Root kits can't execute code on a 64bit OS.
Oh this is bad, very bad. I would have expected the malware to be executed with the same user rights as the user that launched it, instead it gets elevated rights. Ouch. There is a solution from MS but it is not pretty
labrat is the coolest logon ever!
SamyAdel9 6 days ago
Stuxnet is a false flag cyber attack launched by Iran to justify a kinetic attack on a third-party nation state. Seek the truth.
stuxnettruth 1 year ago
Has this been patched yet?
Stasoline 1 year ago
its the gonasyphaherpaleze of sneakernet!!!
allanonmage 1 year ago
@klemv20 ok well show me since you think it's so easy.
blacksteel25 1 year ago
Sophos's tool only protects against .lnk files, not against .pif files.
xbia1 1 year ago
Great that Sophos quickly had a signature for the threat, but AV is basically an ineffective, reactive solution for zero-day threats like this. More proactive solutions like Application Whitelisting exist that are proactive and prevent any new code from running, which would have negated this threat and all others like it. Much better fit in closely controlled environments like those that run Siemens Process Control software,. The better solutions also stop in-memory attacks too.
kenpaustin 1 year ago
Does Sophos Anti-Virus detect the particular malware or the exploit being used?
595o 1 year ago
This is a very sophisticated attack. This worm is looking to infect systems that run Siemens SCADA (software that run power plants, nuclear aircraft carriers). It uses a signed digital certificate stolen from Realtek. Disabling Autoplay will not stop this. You just need to browse to the folder with the files. I can't believe they run nuclear aircraft carriers on windows. Hope these people changed the default password.
sigintnsa 1 year ago
this is nonsense...
majstor037 1 year ago
Which rootkit is being used in this demonstration?
PUnitTheITGuy 1 year ago
haha windows is junk
muk546 1 year ago
@muk546 Good joke.
Borridd 1 year ago
@Borridd no joke its junk use linux or get a mac
muk546 1 year ago
@muk546 Linux isn't an operating system and Mac is marketing gone mad.
Borridd 1 year ago
@muk546 macs are overrated and they suck when it comes to games (portal lagged like a son of a cock on my bothers mac) and linux isent an operationg system its a mod
ThePsychoticScyth396 1 year ago
@ThePsychoticScyth396 Lol at your Linux comment. I don't understand how anyone could justify linux not being an operating system. Especially how much it has deviated from unix.
jake2135 1 year ago
i dont get it...
Sketchfactory 1 year ago
@Sketchfactory , yea mee to.. shity manual. ; /
panterml 1 year ago
vai a zappare
ducatidesmo77 1 year ago
non è mica un bug di seven, con xp e vista si poteva fare la stessa cosa...
lux1ph3r 1 year ago
Lol that's a pure SHIT XD
OperationLionCash 1 year ago
We run Sophos on all of our ~ 40,000 PCs. We love it; the terms of the agreement allow me to run it at home!
stevecrye 1 year ago
If I wasn't running Linux..I'd be using Sophos as my AV.
BacklTrack 1 year ago 2
Worry more about Malware, vulnerability through Virus's/root kits are less common. Virus's tend to attack servers rather than individual users. My guess this was on the 32bit version of Win 7 since Root kits can't execute code on a 64bit OS.
blacksteel25 1 year ago
@blacksteel25 Certain kinds of root-kits might be de facto impossible on 64-bit installation but certainly not all of them.
595o 1 year ago
Oh this is bad, very bad. I would have expected the malware to be executed with the same user rights as the user that launched it, instead it gets elevated rights. Ouch. There is a solution from MS but it is not pretty
silviucc 1 year ago
Interesting......
ebildude123 1 year ago
Interesting demonstration, but does the actual virus itself do any other damage to the computer other than hide the shortcuts from Autoplay?
Link77996 1 year ago
I hope other AV's Keep up and get the definition for the rootkit. Anyway NIce Video
FirefoxReview 1 year ago