malware that inserts itself into another program
‘‘infects’’ other programs when run
Word, Excel, other office software support macros
viruses written in a scripting language
spread to office documents, not executables
vendor reaction: macros disabled by default now
useful-looking program that is malware:
maybe is (or not), but also does something evil
common form for targeted attacks
some mostly-legitimate programs also do malware-like things
location info collected by cell phone apps?
advertisments injected by useful browser extensions?
VDR=portion detected as unwanted; PPI=pay-per-install; MDM=mobile device management
opinion question:
if you’re making anti-malware software, what should it do for…?
A. remove it, no prompting
B. prompt to remove it, default to yes
C. prompt to remove it, default to no
D. don’t flag it
E. something else (discuss?)
this class: mostly talking about clearly anti-user software
but there are also problems of
intentionally ‘evil’ software masquarding as legit
ideally, prevent ‘‘bad’’ use somehow
adware — from ad revenue
ransomware — ransom user’s files/usability of system
steal/resell personal info
resell computation/network time
Source: FireEye M-Trends Report 2020
internet advertising is big business
… but you need to pay websites to add ads?
how about modifying browser to add/change ads
mostly bundled with legitimate software
From Thomas et al, ‘‘Ad Injection at Scale: Assessing Deceptive Advertisement Modifications’’
90% using code from VC-backed firm SuperFish:
encrypt files, hold for ‘‘ransom’’
decryption key stored only on attacker-controlled server
possibly decrypt files if victim pays
many millions in revenues
via Thomas et al, “Framing Dependencies Introduced by Underground Commoditization” (2015)
2011, Usenix Security
supplier of network-monitoring software
… used by many big customers, including US Gov’t
attacked by third-party to spy (?) on customers
targeted Iranian nuclear enrichment facilities
physically damaged centrifuges
designed to spread via USB sticks
publicly known 2010, deployed 2009
US + Israel gov’t developed
some email spam filters
blacklists for web browsers
malware authors tries to make it hard-to-detect
obfuscation: