Security standoff over PC-PDA malware code

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Topics

Antivirus

NEWS

Mobile antivirus researchers and antivirus companies are at loggerheads over access to code for a PC-to-mobile Trojan.

The Mobile Antivirus Researchers Association (MARA) said last week that it had received proof-of-concept code last week for Crossover, which MARA claims is malware that can jump from a Windows desktop machine to a Windows Mobile Pocket PC handheld.

Antivirus vendors and researchers usually collaborate by sharing code with competitors. This reciprocal arrangement seems to have broken down on this occasion, with several major antivirus vendors including Sophos and McAfee complaining that they don't yet have access to the code.

MARA claims that some antivirus vendors had attempted to "bully" the code out of them, while the antivirus companies say they aren't prepared to comply with the conditions that MARA wants to impose on them before they get access to the code for Crossover.

"A small number [of antivirus vendors] have refused to sign any agreement, and have made comments to the effect that, 'we're the experts, not you, so hand it over right now.' Some of them have even tried to bully individual members into bypassing the proper protocol," MARA said in a statement on its Web site.

"That is unfortunate, since it would be illegal to distribute malware without a signed agreement. There has to be a chain of custody in place," said MARA.

Antivirus vendor Sophos confirmed it had been in contact with MARA, but denied using strong-arm tactics to try to gain the code.

"That isn't Sophos. I cannot imagine anyone here being so rude. I know the guy who dealt with this at Sophos, and he's very polite," said Graham Cluley, senior technology consultant at Sophos.

McAfee said it had also been contact with the group, but had not "bullied" any MARA members.

"McAfee hasn't put any pressure on them," said Greg Day, security analyst at McAfee. "It would surprise me to see anyone bullying them, because sharing code is all about trust and mutual consent," he added.

Sophos and McAfee are unhappy because they have been told that before they can get the code they must first join MARA, which would force them to share code with all MARA members.

"We can't help but feel this is a hold-to-ransom rather than a goodwill gesture," said Day.

"Basically we have to join their club." said Cluley. "If they asked us we would have to provide all of our virus samples within 24 hours. None of the major antivirus companies are members of their group — no-one wants to join. We wrote to them, they said we could only have the code if we joined up, so we said 'no, thank you very much'."

But a MARA spokesman denied that all antivirus vendors had been reluctant to sign up.

"Several major antivirus companies and security corporations are already signing up with us," Cyrus Peikari, a MARA representative, told ZDNet UK.

Peikari denied that his organisation refused to share code with non-MARA members, but said that antivirus vendors would have to sign a "mutual trading and ethics agreement".

"MARA provides samples of malware to antivirus vendors and other parties that have a legitimate research need. There is absolutely no requirement to become a MARA member. We are happy to provide samples even if you choose not to join MARA. In this case, we simply ask you to sign a mutual trading and ethics agreement," said Peikari.

"Trading malware is a sensitive business; for ethical and legal reasons there should be a written chain of custody. And if an antivirus vendor prefers not to use the MARA agreement, then they are welcome to suggest one that is to their liking," Peikari added.

Cluley said that Sophos was particularly unhappy about one particular stipulation of MARA's.

"If we joined, we couldn't share any identifying information about MARA members, so if we found someone in the group publishing virus source code, or co-authoring articles with known virus writers, we couldn't divulge that information," said Cluley.

Cluley also claimed that some members of MARA had links with people thought to be virus writers.

"We don't want to touch that with a bargepole. What kind of message would that send to our customers?" said Cluley.

McAfee also said that "some of the papers from MARA had apparently been co-authored by a member of the 29A virus group," and said that it would take time to build up the trust necessary to share virus samples.

"It's important to share samples with 100 percent faith, and that faith has yet to be proven in MARA. Groups share on a personal level, and that requires a build-up of trust over time," said Day.

Peikari denied that MARA members had co-authored MARA papers with virus writers or published virus source code.

"We have read articles where antivirus executives say that MARA has published virus source code. We believe that this may be libel. It is certainly not true: a couple of MARA members contributed to an article on the Dust virus [the first Pocket PC Trojan] last year that also had a separate, Part III written by a virus writer, in which he lists some proof of concept code. However, contrary to some reports, this was never published by MARA," said Peikari.

Informit.com, which is part of Pearson Education, published an article in 2004 called Reverse-Engineering the First Pocket PC Trojan. Its authors included both Peikari and Ratter, who is understood to be a member of 29A. But according to Peikari, he and Ratter produced separate parts of the article and never worked together.

With the code of the Crossover virus not being made available to antivirus vendors, some concerns have been raised that customers are at risk because antivirus vendors have not developed an effective signature. McAfee denied that this was a security risk.

"This is not a critical issue for our customers, as this virus hasn't been seen in the wild," said Day. "McAfee has a broad range of security products, many of which have behavioural controls which would be able stop an attack."

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

6 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

8 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

8 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

10 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

12 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

13 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

14 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

14 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

15 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

16 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

22 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?