Myfip Worm Analysis

One of the unanswered questions is what the thieves do with all the files this tool sends back to the FTP server.  If they were to capture everything on my work PC, they’d get a middle manager’s desktop conglomeration:  Thousands of more-or-less useless files and a few dozen documents which would probably be valuable to someone.  There are also a bunch of database files (in several formats) which could be mined, but aren’t clearly useful as they stand.  I have trouble finding stuff in this mess; how would someone who doesn’t work here make sense of it?

Still Witty after all these weeks

There’s a mind behind Witty, folks.  Wonder what she learned from the experiment.

Witty seems to have been an orchestrated attack, albeit using an opportunistic method.  The paper argues convincingly that we’re using the wrong security model; if we don’t change, the bad guys are gonna take down a lot of computers.  Doesn’t matter if it’s a prank or something really malicious, it’s going to be costly regardless.

