Security Experts Warn of Updated Trojan
So-called backdoor program SubSeven could infect your PC and use it as launching pad for later attacks.
Douglas F. Gray, IDG News Service
An updated version of the backdoor program SubSeven was released by its creator, a hacker known as "mobman," on Friday, according to the program's "official" Web page.
The SubSeven backdoor, which allows malicious hackers to access and control your PC without your knowledge, is "one of the highest threats to Windows PCs, especially those running in broadband environments," says Chris Rouland, director of the X-Force research team at computer security firm Internet Security Systems, or ISS.
The program, a kind of Trojan horse program, typically arrives in an e-mail disguised as one of a variety of benign file types. If you unwittingly launch the program, you may allow malicious hackers entry to your system. They could restart or shut down your PC, retrieve passwords, or upload, download, and delete files from the hard drive.
Still, it can be stopped if you exercise caution about opening attachments from unknown correspondents.
"Up-to-date antivirus software and intrusion detection software is the real solution here," Rouland says.
Update Adds Hazards
The new version, SubSeven 2.2, has a broader set of functions than its predecessor, making it more dangerous, according to the ISS team. For example, the program includes expanded notification capabilities that could let hackers more effectively collaborate distributed denial-of-service attacks, giving them a list of infected computers. The list makes it easier to orchestrate such an attack, which can shut down a Web site by flooding it with fake requests for information.
Another new feature supports what are known as socks4 and socks5 proxies, which help the attackers hide their identities. Using these proxies to cross international borders between countries whose governments don't cooperate with investigators could make it even more difficult to track down the hacker, Rouland says.
Already in the Wild
SubSeven 2.2 has already been spotted on the Internet, hidden in pornography files on a Usenet group, Rouland says. It isn't clear whether any users have yet been infected with the new version.
Another major development in version 2.2 is that most of the program's functionality resides in plug-in dynamic link libraries, making it fairly simple to upgrade. The hacker community plans to release a software developer kit that would enable hackers to create custom plug-ins. This could make it even harder to detect than previous versions and allow customization of the program, Rouland says.
Backdoors such as SubSeven and the better-known BackOrifice have a tendency to spread quickly because they are easy for hackers to launch, Rouland said. ISS found one strain of SubSeven 2.17 in thousands of computers, and Rouland estimates the total number of infected machines to be in the tens of thousands. In many cases, the malicious code lies dormant in the infected PC unless a hacker chooses to target that machine.
The Best of PC World
Microsoft Office Home and Student 2007
- Great year-end deals for small business!

-
Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors and save up to 200!
-
HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!
- *Other names and brands may be claimed as the property of others. ©2009 Intel Corporation. Intel, the Intel logo, vPro and Core trademarks of Intel Corporation in the United States and other countries. All rights reserved.
Dell Fast Track
-
Free Next Day Business Shipping on Dell's Most Popular Systems
Over 35% off Dell’s most popular systems. Delivered in 48 hours with free next business day shipping! Ends 12/22 at 3 PM CST
People who read this also read:
Best Prices on Antivirus Software
Norton Antivirus 2010 (Full Product, 1 User)Price: $17.90
Anti-virus 2010 (OEM Product, 1 User)Price: $20.99
AntiVirus 2010 (Full Product)Price: $24.95
Norton AntiVirus 2009 (Full Product)Price: $16.89
AntiVirus Plus 2010 - 3 Users (Full Product)Price: $11.95
Anti-Virus 2009 (Full Product)Price: $15.04
- 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
- A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage




