main

'Blue Pill' Prototype Creates 100% Undetectable Malware

Daniel Fleshbourne   on 29 June 2006 - 09:54 · 13 comments & 4641 views

Advertisement (Why?)
A security researcher with expertise in rootkits has built a working prototype of new technology that is capable of creating malware that remains "100 percent undetectable," even on Windows Vista x64 systems. oanna Rutkowska, a stealth malware researcher at Singapore-based IT security firm COSEINC, says the new Blue Pill concept uses AMD's SVM/Pacifica virtualization technology to create an ultra-thin hypervisor that takes complete control of the underlying operating system. Rutkowska plans to discuss the idea and demonstrate a working prototype for Windows Vista x64 at the SyScan Conference in Singapore on July 21 and at the Black Hat Briefings in Las Vegas on Aug. 3.

The Black Hat presentation will occur on the same day Microsoft is scheduled to show off some of the key security features and functionality being fitted into Vista. Rutkowska said the presentation will deal with a "generic method" of inserting arbitrary code into the Vista Beta 2 kernel (x64 edition) without relying on any implementation bug.

View: The full story
News source: eWeek

Post a comment · Send to friend Comments · There are 13 additional comments
#1 domgrimm on 29 Jun 2006 - 09:58
Oh great, I hope they come up with a way of preventing this before a proper piece of malware is made
#2 paperless on 29 Jun 2006 - 10:00
Yes, tell everyone how its done ....
(1 reply) #3 xpgeek on 29 Jun 2006 - 10:30
Wow, scary if its true.
#3.1 OrganicPanda on 29 Jun 2006 - 17:25
lol, get a life
(1 reply) #4 alsheron on 29 Jun 2006 - 11:55
This is not good... Vista isnt even out yet and already it's been comromised (without the use of a known bug).... Will Microsoft do anything about this? I don't think they have time.
#4.1 Ryster092 on 29 Jun 2006 - 19:59
This has got nothing to do with Vista directly. Vista has not been "compromised" as you put it. This malware works by using virtualisation on the AMD platform. This article is just saying that even Vista would be affected by this malware.
#5 ksalter on 29 Jun 2006 - 12:15
"Rutkowska stressed that the Blue Pill technology does not rely on any bug of the underlying operating system. "I have implemented a working prototype for Vista x64, but I see no reasons why it should not be possible to port it to other operating systems, like Linux or BSD which can be run on x64 platform," she added."

So let's not say this is a Microsoft problem or bug, eh? Think you kids can do that?
#6 Emphatic on 29 Jun 2006 - 13:25
If you have physical access to a machine and enough time you have no security on any machine - the best you can hope for is to make it more difficult and limit the damage.

That pretty much goes for any OS.
(3 replies) #7 Nose Nuggets on 29 Jun 2006 - 16:40
im buying a mac, screw this noise.
#7.1 ksalter on 29 Jun 2006 - 16:51
"Rutkowska stressed that the Blue Pill technology does not rely on any bug of the underlying operating system. "I have implemented a working prototype for Vista x64, but I see no reasons why it should not be possible to port it to other operating systems, like Linux or BSD which can be run on x64 platform," she added."
#7.2 JiveMasterT on 29 Jun 2006 - 19:46
I'd like to stress the fact that OSX is based on BSD... pwnd!

Windows runs on teh macz0rs as well you know...
#7.3 Leo Natan on 30 Jun 2006 - 03:17
Macs are INTELS! The malware works on AMD...

Both of you are "pwnd"!!

#8 MaceX on 29 Jun 2006 - 18:36
So, just disable virtualization.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)