SANS was all over this right after Christmas. I’m glad to see it getting a bit more press and must admit that Deborah Gage’s write-up lacks the confusion we typically see in the media reporting of incidents. (Although I guess the media confusion applies to all subject matter.) If an infection subverts your anti-virus, you’re pretty much guaranteed to be screwed. In this case, you’ve been infected by some attackers that were willing to take more risks than normal in launching the attack; physical access is my greatest fear.
In short, several brands of digital picture frames were purchased in big name stores bearing an unexpected gift (read trojan horse). Simply connecting one of these fine products to your Windows computer would pretty much guarantee you a rootkit. We’ve heard this song before with hard drives and USB drives. This time, according to the article, we’re relatively lucky that the infection is only a keylogger that attempts to steal user names and passwords for select online games…for now.
Between downloaders, self-patching and self-healing malware, I won’t be surprised to see additional functionality from these infections in the coming months. And even if we don’t, we’re still looking at a source of attack that further damages the trust relationship we as consumers have with manufacturers. Lead in children’s toys? Poison in dog food? As much as they think they can, governments can’t effectively regulate everything and attack vectors like this are vulnerable. We have further proof of the need for awareness and caution.
I’m inclined to think this is a well-organized group behind this attack. The attack method is shrewd. You avoid the unreliability of social engineering and spam and eliminate the variables and risk of alluring someone to the infection. The attack is limited in that it will only initially infect consumers who purchase the tainted wares. The supply chain is fraught with opportunity to induce such an infection, from manufacturing to shipping/distribution to the reseller. But let’s imagine for a minute that the picture frame is wireless and displaying pictures of lattes and muffins at a Starbucks full of users enjoying the free wireless access. It starts to get a little scarier, doesn’t it?
So what better way to cap a new beginning than a prediction? In the not too distant future there is going to be another spate of attacks where the source of infection is a product tainted before it reaches the end-user and it will be a more malicious and effective attack than this one. Government will look to enforce some kind of regulation on any type of electronic device that interacts with another device and all the while we’ll be poisoning our animals and watching our kids chew on that shiny and colorful piece of lead.