Low-threat worm caused 'most significant breach' of U.S. military net

The incident made public this week by a high-ranking Department of Defense official alarmed the Pentagon

The most significant breach of U.S. military computers ever was carried out in 2008 by W32.SillyFDC, a low-level-threat worm that got into the network via a thumb drive plugged into a military laptop.

Is the U.S. the nation most vulnerable to cyberattack?

At the time, a variant of the worm found its way into classified and unclassified military networks and took months to eradicate.

This despite the fact that generic W32.SillyFDC worms had been discovered the year before, and security companies had long since figured out how to deal with them. Removal was ranked "easy".

The incident made public this week by a high-ranking Department of Defense official alarmed the Pentagon. "This previously classified incident was the most significant breach of U.S. military computers ever, and it served as an important wake-up call," says William J. Lynn III, an udersecretary of defense, in an essay published in Foreign Affairs.

The hack, which was publicized at the time, led to a ban on use of thumb drives that the military has just started to lift in the past 10 months, says John Pironti, a security consultant with IP Architects.

Despite being a variant of a well-known and low-risk worm, the malware could have been more dangerous than it might seem at first glance, he says.In discussions with military clients since the incident, he gleaned that the variant -- known as W32.agent.btz -- lodged itself within the network where it was smart enough to wend its way into a classified network. This requires a level of knowledge about sensors and defenses within military networks.

"It propagated well before it was detected," Pironti says. "This was not something off-the-shelf. It was something fresh and very interesting."

Still, corporate IT security professionals had a leg up on the worm if they had commercial antivirus software. For example, Symantec posted an advisory on the worm Feb. 27, 2007, in which it says that its then-current antivirus software would identify and remove it.

W32.SillyFDC removal was ranked easy by Symantec, its damage level potential was ranked medium and its overall threat rating was very low.

The worm is capable of replicating itself to removable drives and mapped drives and can download files. It exploits the AutoRun feature in Windows that lets executables run automatically when a drive containing them is accessed.

The worm copies itself to the system disk of the affected computer where it creates files or modifies the registry so the executables run whenever Windows starts up, Symantec says. It infects removable drives that get plugged in later with copies of itself that then run on the next machine the thumb drive is plugged into.

Its capabilities include downloading files from particular URLs, lowering security settings, altering Safe Mode settings, bypassing Windows firewalls and disabling Task Manager, Registry Editor and other system software, Symantec says.

Cleaning an infected machine could be accomplished by disabling System Restore, updating antivirus definitions and running a full system scan, Symantec says.

Read more about wide area network in Network World's Wide Area Network section.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags military network breachsecuritylegalgovernmentindustry verticalsanti-malwarecybercrimeantivirus

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tim Greene

Network World
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?