|
A feature in Acrobat is actively being abused by attackers to distribute the Zeus botnet malware via email. PDF documents abusing the "Launch" feature can run arbitrary executables and the Zeus implementation drops the malicious binary with a deceiving PDF file extension for execution. In Adobe Acrobat, both the dropping action and subsequent opening action prompt the end user for permission. Despite the spike in PDF exploitation in 2009, PDF is often considered to be safe and users are likely to be unaware of the potential for exploitation. However, alternate PDF readers such as Foxit Reader include this feature without requiring user interaction. In cases where organizations have moved away from Adobe's implementation, this is of particular concern.
The Zeus botnet malware is commonly used by attackers to steal banking information from infected computers. Zeus is primarily an information stealing trojan, and the bot software itself is generated using a toolkit that is sold online. It is highly configurable with regard to the information it can obtain from an infected PC. At any given time, there are thousands of known individual Zeus botnets in existence. (1)
While the Launch feature of Acrobat could be used to spread any piece of malware, the malware most associated with it at the moment is Zeus. To protect against malware infections, keep your anti-virus software up-to-date. |