Malware variant recognizes Win8, uses Google Docs as a proxy to phone home


Recommended Posts

Windows 8 may block most malware out of the box, but there is still malware out there that thwarts Microsoft?s latest and greatest. A new Trojan variant, detected as Backdoor.Makadocs and spread via RTF and Microsoft Word document marked as Trojan.Dropper, has been discovered that not only adds a clause to target Windows 8 and Windows Server 2012, but also uses Google Docs as a proxy server to phone home to its Command & Control (C&C) server.

Symantec believes the threat has been updated by the malware author to include the Windows 8 and Windows Server 2012 references, but doesn?t do anything specific for them (yet). This is no surprise: the two operating systems were released less than a month ago but of course they are already popular, and cybercriminals are acting fast.

Yet the more interesting part is the Google Docs addition. Backdoor.Makadocs gathers information from the compromised computer (such as host name and OS type) and then receives and executes commands from a C&C server to do further damage.

In order to do so, the malware authors have decided to leverage Google Docs to ensure crystal clear communications. As Google Docs becomes more and more popular, and as businesses continue to accept it and allow the service through their firewalls, this method is a clever move.

malware-targets-2.png

The reason this works is because Google Docs includes a ?viewer? function that retrieves resources of another URL and displays it, allowing the user to view a variety of file types in the browser. In violation of Google?s policies, Backdoor.Makadocs uses this function to access its C&C server, likely in the hopes of preventing the link to the C&C from being discovered since Google Docs encrypts its connection over HTTPS.

Symantec says ?It is possible for Google to prevent this connection by using a firewall.? Since the document does not leverage vulnerabilities to function (it relies on social engineering tactics instead) it?s unlikely Google will be able to do much beyond participating in a game of cat and mouse with the malware authors.

Nevertheless, we have contacted Google and Microsoft about this issue. We will update this article if and when we hear back.

Update at 4:30PM EST: ?Using any Google product to conduct this kind of activity is a violation of our product policies,? a Google spokesperson said in a statement. ?We investigate and take action when we become aware of abuse.?

http://thenextweb.co...-to-phone-home/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Ford execs say they made a mistake when they replaced human engineers with AI by David Uzondu Ford recently announced that over the last three years, it's had to rehire about 350 "gray beard" engineers to mentor younger staff and reprogram diagnostic systems and AI tools that were failing to meet up to quality expectations. The company's VP of vehicle hardware engineering, Charles **** said that leaders overlooked the deep experience of veterans who survived many product cycles. **** admitted that simply replacing them with AI was a huge mistake, and that while AI is "a fantastic tool," it remains "only as good as the information you use to train it." The rehired engineers now run mandatory meetings to troubleshoot vehicles and reprogram automated engineering software and AI tools to prevent glitches before production. These technical specialists hunt for failure points before parts ever reach the plant floor, helping prevent the massive recalls and defects that previously cost the company billions as it aims to cut one billion dollars in expenses this year. In last year's JD Power Quality Survey, an annual study that measures the quality of a car during the first three months of ownership, Ford finished 10th among mainstream brands and scored below the industry average. But this year, JD Power ranked the automaker as the top mainstream brand, placing it above the likes of Toyota Motor Corp. and Honda Motor Co. Ford attributed this massive improvement directly to the expertise of these returned engineers. Ford's realization that AI cannot magically design and test quality vehicles without senior human oversight is just the tip of the iceberg. When Careerminds looked at companies that conducted AI-driven layoffs, researchers found out that 35.6% of those companies had to rehire more than half of the employees they previously fired. Another 32.7% had to rehire between 25% and 50% of them. In 2024, Sebastian Siemiatkowski, CEO of Klarna, proudly announced that its new chatbot was doing the work of 700 full-time customer service agents. As a result, the fintech company froze hiring and cut hundreds of positions. But by mid 2025, and into 2026, Klarna was scrambling to recruit human agents again because customer satisfaction had plummeted. It turns out, while AI is very good at answering basic questions like how to check an account balance, when faced with complex customer issues that require nuance, the thing usually resorts to the unhelpful, robotic corporate jargon we all know and love.
    • Free AI in IDEs is shifting to paid models Or you know, you could just learn to actually design and code apps, use frameworks to handle the repetitive parts and not use AI at all - and voila... free for life!
    • In a sane world US antitrust laws wouldn't even allow these companies to be in the position to be subjected to EU directives. As you say, better than oligarch nothing.
    • Apple reportedly has a second-generation iPhone Fold planned for 2027 Good grief, Apple hasn't even released a first folding phone and the Apple faithful is already obsessing over the sequel? Seriously people, go out and touch grass... because this level of obsession is borderline stalkery/neurotic.
    • I checked on the IPs associated with every login and they're all mine... And whenever I get a new prompt, there is no activity to show for it. 
  • Recent Achievements

    • Week One Done
      xvvxcvv earned a badge
      Week One Done
    • One Month Later
      xvvxcvv earned a badge
      One Month Later
    • Enthusiast
      Xonos went up a rank
      Enthusiast
    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      405
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      129
    4. 4
      neufuse
      69
    5. 5
      Xenon
      68
  • Tell a friend

    Love Neowin? Tell a friend!