News

Same Tech Used in Lenovo Superfish Software found in Twelve Other Apps

The SSL-busting technology recently discovered to be pre-installed on Lenovo laptops has been found as part of another 12 pieces of software, including Trojan malware. The HTTPS-bypassing code, developed by Israeli company Komodia, was a part of the now-infamous Superfish software found on-board Lenovo laptops.

Matt Richard, threat researcher for the Facebook security team, revealed the extent of the code’s reach in a post on Friday, writing, “What all these applications have in common is that they make people less secure through their use of an easily obtained root CA [certificate authority], they provide little information about the risks of the technology, and in some cases they are difficult to remove.”

He continued,  “Furthermore, it is likely that these intercepting SSL proxies won’t keep up with the HTTPS features in browsers (e.g., certificate pinning and forward secrecy), meaning they could potentially expose private data to network attackers. Some of these deficiencies can be detected by antivirus products as malware or adware, though from our research, detection successes are sporadic.”

Even the developer Komodia calls one of its SDKs an “SSL hijacker”, so it’s no surprise that the code has found its way into malicious software. The malware, Trojan.Nurjax, was first discovered back in December. According to Symantec, the malware “hijacks the Web browser on the compromised computer and may download additional threats.”

Lenovo has apologised for inflicting the HTTPS-breaking code upon is customers and has released a program to aid removal of the Superfish software.

Source: Ars Technica

Ashley Allen

Disqus Comments Loading...

Recent Posts

Fortnite Main Battle Royal Mode Was Thought up in the Back of an Uber

No matter who you are or where you are it's pretty sure thing that you've…

6 hours ago

Philips Evnia 42″ 3840×2160 OLED 138Hz 0.1ms A-Sync HDR Widescreen Gaming Monitor

Low input lag reduces time delay between devices to monitor SmartImage game mode optimised for…

7 hours ago

Alphacool Apex Stealth Metal fan 2000rpm Matte Black

High-quality, elegant as well as timeless design and technical innovation - these are the features…

7 hours ago

NZXT T120 RGB Performance 120mm CPU Cooler

Aluminum heat pipe cover discreetly hides copper piping 4 conductive copper heat pipes with Direct…

8 hours ago

ASUS ROG Ryujin III 240 ARGB Performance AIO CPU Liquid Cooler

The customizable ARGB fans snap together with a magnetic connector that links the fans and…

8 hours ago

Varmilo VEA88 CMYK Gaming Keyboard, MX-Red, White-LED

TKL mechanical keyboard with 88 keys in a UK ISO layout V-silk PBT keycaps with…

8 hours ago