118
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.6 2007 Storm Worm Virus (This virus, known by many names, was a Trojan that hit
computers running Windows. In this case, the distribution of malicious content again occurred
through an email entitled “230 dead as storm batters Europe”. Storm Worm was a trojan that
connected an infected computer to a botnet - a network of remotely controlled computers. And
although it was believed that this botnet consists of millions of computers, the exact number has
never been established.)
saying that they need to update their personal data by following the attached link.
After that, the user clicks the link, enters a fake website, and leaves his or her
personal data, including even passwords, credit card number, or bank account,
which results in these data being stolen. Modern antiviruses collect databases
of such threats and warn the user about hazards if the user attempts to follow a
phishing link.
2.1.4 Specifics of Using the Stuxnet Virus as a Type
of Cyberweapon
The history of creation and first use of the Stuxnet virus is detailed in Sect. 2.3. This
worm is distinguished by the fact that it used four 0-day (i.e., previously unknown)
vulnerabilities instead of one, which is also rare. To be precise, two of the vulnerabilities had been known, but only a little. Microsoft didn’t know about them and,
accordingly, didn’t release any patches. For the purpose of reliability, the virus also
used the fifth, well-known but extremely malicious vulnerability in the RPC service,
which had been earlier actively exploited by Conficker worm.
The virus was signed with a stolen digital signature, as Microsoft usually requires
all drivers in the system to be signed for the purpose of security. However, it didn’t
Précédent

- 139/839

Suivant