Low-threat worm caused 'most significant breach' of U.S. military net

The incident made public this week by a high-ranking Department of Defense official alarmed the Pentagon

The most significant breach of U.S. military computers ever was carried out in 2008 by W32.SillyFDC, a low-level-threat worm that got into the network via a thumb drive plugged into a military laptop.

Is the U.S. the nation most vulnerable to cyberattack?

At the time, a variant of the worm found its way into classified and unclassified military networks and took months to eradicate.

This despite the fact that generic W32.SillyFDC worms had been discovered the year before, and security companies had long since figured out how to deal with them. Removal was ranked "easy".

The incident made public this week by a high-ranking Department of Defense official alarmed the Pentagon. "This previously classified incident was the most significant breach of U.S. military computers ever, and it served as an important wake-up call," says William J. Lynn III, an udersecretary of defense, in an essay published in Foreign Affairs.

The hack, which was publicized at the time, led to a ban on use of thumb drives that the military has just started to lift in the past 10 months, says John Pironti, a security consultant with IP Architects.

Despite being a variant of a well-known and low-risk worm, the malware could have been more dangerous than it might seem at first glance, he says.In discussions with military clients since the incident, he gleaned that the variant -- known as W32.agent.btz -- lodged itself within the network where it was smart enough to wend its way into a classified network. This requires a level of knowledge about sensors and defenses within military networks.

"It propagated well before it was detected," Pironti says. "This was not something off-the-shelf. It was something fresh and very interesting."

Still, corporate IT security professionals had a leg up on the worm if they had commercial antivirus software. For example, Symantec posted an advisory on the worm Feb. 27, 2007, in which it says that its then-current antivirus software would identify and remove it.

W32.SillyFDC removal was ranked easy by Symantec, its damage level potential was ranked medium and its overall threat rating was very low.

The worm is capable of replicating itself to removable drives and mapped drives and can download files. It exploits the AutoRun feature in Windows that lets executables run automatically when a drive containing them is accessed.

The worm copies itself to the system disk of the affected computer where it creates files or modifies the registry so the executables run whenever Windows starts up, Symantec says. It infects removable drives that get plugged in later with copies of itself that then run on the next machine the thumb drive is plugged into.

Its capabilities include downloading files from particular URLs, lowering security settings, altering Safe Mode settings, bypassing Windows firewalls and disabling Task Manager, Registry Editor and other system software, Symantec says.

Cleaning an infected machine could be accomplished by disabling System Restore, updating antivirus definitions and running a full system scan, Symantec says.

Read more about wide area network in Network World's Wide Area Network section.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags cybercrimelegalantivirusindustry verticalsanti-malwaremilitary network breach

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Tim Greene

Tim Greene

Network World
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?