Microsoft discovers Chinese malware pre-installed on new PCs
LATEST NEWS
SUBSCRIBE
Computerworld is New Zealand's only specialised information systems fortnightly. Subscribe now for $100 (23 issues) and save more than 37% off the cover price!
SIGN UP
Microsoft has published evidence of an extraordinary conspiracy in which potent botnet malware was apparently installed and hidden on PCs during their manufacture in China
By John E Dunn | London | Monday, 17 September, 2012 | 3 Comments
Microsoft has published evidence of an extraordinary conspiracy in which potent botnet malware was apparently installed and hidden on PCs during their manufacture in China.
In 'Operation B70' started in August 2011, Microsoft documents how its Digital Crimes Unit (DCU) bought 20 brand new laptops and desktop PCs from various cities in China, finding that four were infected with pre-installed backdoor malware, including one with a known rootkit called 'Nitol'.
Tracing Nitol's activity back to an extensive network of global command and control (C&C) servers, the team discovered that the malware that has infected PCs to build a larger bot, most probably used to launch DDoS attacks.
Once in situ, Nitol would spread beyond the PCs on which it had been pre-installed by copying itself to USB and other removable drives.
Disturbingly, other malware hosted on the main domain used as C&C by Nitol was capable of performing just about every nasty in the malware criminal's armoury, including keylogging, controlling webcams, and changing search settings.
This hints at the disturbing possibility that the pre-installed malware tactic is almost certainly much more significant than previously realised.
That PCs are being pre-installed with malware during or soon after manufacture confirmed a long-held suspicion that had prompted Microsoft to investigate supply chain security, the firm said.
"What's especially disturbing is that the counterfeit software embedded with malware could have entered the chain at any point as a computer travels among companies that transport and resell the computer," Microsoft said in a blog introducing its investigations.
Anyone installing malware during manufacture - that is before any form of security is added - would have an important head start over security systems that might be installed on the PC at a later point. The only way around this would be for the customer to reinstall the operating system after purchase using a known secure image.
As PC malware scandals go this is about as bad as it gets; Operation B70 offers an unpleasant glimpse of the state of PC security and asks questions of the security of the supply chain.
Microsoft was earlier this week granted permission by a US court to take control of the C&C servers being used to direct the Nitol botnet.
Microsoft's DCU has acquired a reputation for unwinding botnets. An earlier bot disruption assault called Operation B71, it disrupted servers being used to distribute the Zeus banking Trojan. In 2011, it played a critical role in knocking down the Rustock botnet.
Third parties can already gain access to the company's global honeypot for monitoring botnets through an API.
Comments
Microsoft is at fault
It's easy to blame others, whether it's a genuine claim or just another Microsoft fabrication, but the reality is that Microsoft's products are so incredibly insecure that they allow these issue to occur. They like to point the finger in every direction but their own, yet for decades we have seen how their products are the root cause of the problem.
Posted by JohnG at 12:20:22 on September 17, 2012
Posted by JohnG at 12:20:22 on September 17, 2012
Microsoft is at fault
Are you serious? You are simply an ignorant bigot.
Posted by Anonymous at 19:50:56 on September 19, 2012
Posted by Anonymous at 19:50:56 on September 19, 2012
Microsoft is at fault
No computer is completely secure if you have physical access to it pre-sale and post-sale if unencrypted. It really does not matter what the pre-installed OS is, only how popular it is because the bot-net world is a "game" of numbers.
Makes you wonder how many smart phones coming from China has malware pre-installed on it...
Posted by Anonymous at 20:58:57 on September 17, 2012
Makes you wonder how many smart phones coming from China has malware pre-installed on it...
Posted by Anonymous at 20:58:57 on September 17, 2012
MOST POPULAR
Social Media @Computerworld NZ

Computerworld NZ has now reached LinkedIn! Join to expand your networks and meet others interested in information systems.





