Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Exactly. I would've thought the malware would ask a C&C server to generate a key pair and then only send the public key to the malware. But I guess perhaps that required too much processing power for the server. But then again this can also distributed: let a random victim generate an RSA keypair for another victim.


This allows computers cut off from the internet to be infected too. Juicy and the risk is minimal.


Bitcoin payment requires internet.


You don't need bitcoin payment to be infected.


If those network requests could be identified, the whole thing would be shut down by network operators.


Instances of the worm could notice they've landed on especially-low-activity systems with open ports, and then modify their own "descendants" to contact them on that host for key-generation. (And then relay the key material to the origin host, before wiping their local copy.)

If the worm then notices that their host "goes active" (e.g. starts a login session), they could "submerge", closing the relevant ports and so forth, until the activity goes away; and their descendant instances would, while this is happening, fall back to the ancestor[N+1]th host.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: