infection

millions-of-ips-remain-infected-by-usb-worm-years-after-its-creators-left-it-for-dead

Millions of IPs remain infected by USB worm years after its creators left it for dead

I’M NOT DEAD YET —

Ability of PlugX worm to live on presents a vexing dilemma: Delete it or leave it be.

Millions of IPs remain infected by USB worm years after its creators left it for dead

Getty Images

A now-abandoned USB worm that backdoors connected devices has continued to self-replicate for years since its creators lost control of it and remains active on thousands, possibly millions, of machines, researchers said Thursday.

The worm—which first came to light in a 2023 post published by security firm Sophos—became active in 2019 when a variant of malware known as PlugX added functionality that allowed it to infect USB drives automatically. In turn, those drives would infect any new machine they connected to, a capability that allowed the malware to spread without requiring any end-user interaction. Researchers who have tracked PlugX since at least 2008 have said that the malware has origins in China and has been used by various groups tied to the country’s Ministry of State Security.

Still active after all these years

For reasons that aren’t clear, the worm creator abandoned the one and only IP address that was designated as its command-and-control channel. With no one controlling the infected machines anymore, the PlugX worm was effectively dead, or at least one might have presumed so. The worm, it turns out, has continued to live on in an undetermined number of machines that possibly reaches into the millions, researchers from security firm Sekoia reported.

The researchers purchased the IP address and connected their own server infrastructure to “sinkhole” traffic connecting to it, meaning intercepting the traffic to prevent it from being used maliciously. Since then, their server continues to receive PlugX traffic from 90,000 to 100,000 unique IP addresses every day. Over the span of six months, the researchers counted requests from nearly 2.5 million unique IPs. These sorts of requests are standard for virtually all forms of malware and typically happen at regular intervals that span from minutes to days. While the number of affected IPs doesn’t directly indicate the number of infected machines, the volume nonetheless suggests the worm remains active on thousands, possibly millions, of devices.

“We initially thought that we will have a few thousand victims connected to it, as what we can have on our regular sinkholes,” Sekoia researchers Felix Aimé and Charles M wrote. “However, by setting up a simple web server we saw a continuous flow of HTTP requests varying through the time of the day.”

They went on to say that other variants of the worm remain active through at least three other command-and-control channels known in security circles. There are indications that one of them may also have been sinkholed, however.

As the image below shows, the machines reporting to the sinkhole have broad geographic disbursement:

A world map showing country IPs reporting to the sinkhole.

Enlarge / A world map showing country IPs reporting to the sinkhole.

Sekoia

A sample of incoming traffic over a single day appeared to show that Nigeria hosted the largest concentration of infected machines, followed by India, Indonesia, and the UK.

Graph showing the countries with the most affected IPs.

Enlarge / Graph showing the countries with the most affected IPs.

Sekoia

The researchers wrote:

Based on that data, it’s notable that around 15 countries account for over 80% of the total infections. It’s also intriguing to note that the leading infected countries don’t share many similarities, a pattern observed with previous USB worms such as RETADUP which has the highest infection rates in Spanish spelling countries. This suggests the possibility that this worm might have originated from multiple patient zeros in different countries.

One explanation is that most of the biggest concentrations are in countries that have coastlines where China’s government has significant investments in infrastructure. Additionally many of the most affected countries have strategic importance to Chinese military objectives. The researchers speculated that the purpose of the campaign was to collect intelligence the Chinese government could use to achieve those objectives.

The researchers noted that the zombie worm has remained susceptible to takeover by any threat actor who gains control of the IP address or manages to insert itself into the pathway between the server at that address and an infected device. That threat poses interesting dilemmas for the governments of affected countries. They could choose to preserve the status quo by taking no action, or they could activate a self-delete command built into the worm that would disinfect infected machines. Additionally, if they choose the latter option, they could elect to disinfect only the infected machine or add new functionality to disinfect any infected USB drives that happen to be connected.

Because of how the worm infects drives, disinfecting them risks deleting the legitimate data stored on them. On the other hand, allowing drives to remain infected makes it possible for the worm to start its proliferation all over again. Further complicating the decision-making process, the researchers noted that even if someone issues commands that disinfect any infected drives that happen to be plugged in, it’s inevitable that the worm will live on in drives that aren’t connected when a remote disinfect command is issued.

“Given the potential legal challenges that could arise from conducting a widespread disinfection campaign, which involves sending an arbitrary command to workstations we do not own, we have resolved to defer the decision on whether to disinfect workstations in their respective countries to the discretion of national Computer Emergency Response Teams (CERTs), Law Enforcement Agencies (LEAs), and cybersecurity authorities,” the researchers wrote. “Once in possession of the disinfection list, we can provide them an access to start the disinfection for a period of three months. During this time, any PlugX request from an Autonomous System marked for disinfection will be responded to with a removal command or a removal payload.”

Millions of IPs remain infected by USB worm years after its creators left it for dead Read More »

concern-grows-as-bird-flu-spreads-further-in-us-cows:-32-herds-in-8-states

Concern grows as bird flu spreads further in US cows: 32 herds in 8 states

Rapidly evolving —

Experts say the US is not sharing as much data on the outbreak as it should.

Greylag geese sit on a field and rest while a cow passes by in the background.

Enlarge / Greylag geese sit on a field and rest while a cow passes by in the background.

Researchers around the world are growing more uneasy with the spread of highly pathogenic avian influenza (H5N1) in US dairy cows as the virus continues to make its way into new herds and states. Several experts say the US is not sharing enough information from the federal investigation into the unexpected and growing outbreak, including genetic information from isolated viruses.

To date, the US Department of Agriculture has tallied 32 affected herds in eight states: Idaho, Kansas, Michigan, New Mexico, North Carolina, Ohio, South Dakota, and Texas. In some cases, the movement of cattle between herds can explain the spread of the virus. But the USDA has not publicly clarified if all the herds are linked in a single outbreak chain or if there is evidence that the virus has spilled over to cows multiple times. Early infections in Texas were linked to dead wild birds (pigeons, blackbirds, and grackles) found on dairy farms. But the USDA reportedly indicated to Stat News that the infections do not appear to be all linked to the Texas cases.

Spread of the virus via cattle movements indicates that there is cow-to-cow transmission occurring, the USDA said. But it’s unclear how the virus is spreading between cows. Given that even the most symptomatic cows show few respiratory symptoms, the USDA speculates that the most likely way it is spreading is via contaminated milking equipment.

Adding to the uncertainty of the virus’s spread, The New York Times on Friday reported that the one herd found infected with H5N1 in North Carolina showed no symptoms of the virus. This raises the possibility that the virus could be silently spreading in unknown numbers of other asymptomatic herds and states. In its most recent FAQ document, the USDA encouraged testing for H5N1 if herds show clinical symptoms, such as lethargy, fever, low milk production, and loose stools. But the Times noted that the agency has begun reimbursing farms for testing asymptomatic cows.

Meanwhile, the USDA also reported that it has evidence that H5N1 from dairy farms has spread back into birds in nearby poultry farms, but how this is happening is also unknown.

Data gaps

All the uncertainty and widespread transmission raises concern about how the virus is evolving to infect mammals and whether it is heading for humans. Last week, the chief scientist for the World Health Organization, Jeremy Farrar, told reporters in Geneva that the spread of the virus in US dairy cows is an “enormous concern,” according to CNN.  “The great concern, of course, is that in doing so and infecting ducks and chickens—but now increasingly mammals—that that virus now evolves and develops the ability to infect humans. And then critically, the ability to go from human-to-human transmission.”

In particular, experts are wary that the dairy cow outbreaks could spill over to nearby pig farms as it’s doing with nearby poultry farms. Pigs can be infected with both bird flu viruses and human flu viruses, making them potential melting pots for new recombinant flu strains.

So far, the USDA says that genetic sequences of H5N1 viruses infecting cows has not revealed any mutations that “would make it more transmissible to humans and between people.” But last Thursday, Stat reported that international experts have faulted the USDA for not sharing more genetic data from its investigation, among other information. Until this weekend, the agency had only shared a few genetic sequences in an international database of viral genome sequences (GISAID).

“A country with capacity like the United States should be able to generate this information within days,” Marion Koopmans, head of the department of viroscience at Erasmus Medical Center in the Dutch city of Rotterdam told Stat last week. “I would expect very fast, very transparent updates, and it’s somewhat amazing not to see that happening.”

On Sunday, facing mounting criticism, the USDA announced the release of 239 genetic sequences to GISAID. It noted it is also adding raw data to a US federal database “in the interest of public transparency and ensuring the scientific community has access to this information as quickly as possible.” The agency said it will continue to make such data available on a rolling basis.

Dr. Rosemary Sifford, the USDA’s chief veterinarian, told the Times, “Please recall that we’ve been engaged in this for less than a month. We are working very hard to generate more information,” she said.

Overall, the USDA and the US Centers for Disease Control and Prevention continue to consider the risk to the public to be low. Farmworkers and others who have direct contact with infected animals are encouraged to take precautions, however.

While deadly to birds, H5N1 in cows is relatively mild, rarely if ever causing deaths. Milk from sick animals contains high levels of virus, but it is being destroyed. Even if some infected milk makes its way into the milk supply, the Food and Drug Administration is confident that the virus would be killed in the pasteurization process. “Pasteurization has continually proven to inactivate bacteria and viruses, like influenza, in milk,” the agency said in an FAQ Friday. Some experts have called for data confirming this, though.

Concern grows as bird flu spreads further in US cows: 32 herds in 8 states Read More »

hong-kong-monkey-encounter-lands-man-in-icu-with-rare,-deadly-virus

Hong Kong monkey encounter lands man in ICU with rare, deadly virus

rare but deadly —

The man had recently visited a country park known for its macaque monkeys.

This photo taken in August 2014 shows macaque monkeys in a country park in Hong Kong.

Enlarge / This photo taken in August 2014 shows macaque monkeys in a country park in Hong Kong.

A 37-year-old man is fighting for his life in an intensive care unit in Hong Kong after being wounded by monkeys during a recent park visit and contracting a rare and deadly virus spread by primates.

The man, who was previously in good health, was wounded by wild macaque monkeys during a visit to Kam Shan Country Park in late February, according to local health officials. The park is well known for its conservation of wild macaques and features an area that locals call “Monkey Hill” and describe as a macaque kingdom.

On March 21, he was admitted to the hospital with a fever and “decreased conscious level,” health officials reported. As of Wednesday, April 3, he was in the ICU listed in critical condition. Officials reported the man’s case Wednesday after testing of his cerebrospinal fluid revealed the presence of B virus.

B virus, also known as herpes B virus or herpesvirus simiae, is a common infection in macaques, usually causing asymptomatic or mild disease. Infections in humans are extremely rare, but when they occur, they usually come from macaque encounters and are often severe and deadly. The infection can start out a lot like the flu, but the virus can move to the brain and spinal cord, causing brain damage, nerve damage, and death. The US Centers for Disease Control and Prevention estimates that about 70 percent of untreated infections in humans are fatal.

Despite the presence of macaques around Hong Kong, the man’s case is the first known B virus infection documented there. The virus was discovered in 1932, and since then only 50 human infections have been documented as of 2019, the CDC reports. Of those 50 people infected, 21 died. The agency notes that in one case, from 1997, a researcher was infected and died after bodily fluid from an infected monkey splashed into her eye. Still, contracting the virus is rare, even among people exposed to macaques. The CDC reports that there are hundreds of reports of macaque bites and scratches each year in US animal facilities, and infections remain very uncommon.

However low the risk, health officials recommend keeping your distance from wild monkeys and not feeding or touching them. If you are bitten or scratched, wash the wound immediately and seek medical attention.

Hong Kong monkey encounter lands man in ICU with rare, deadly virus Read More »

“very-sick”-pet-cat-gave-oregon-resident-case-of-bubonic-plague

“Very sick” pet cat gave Oregon resident case of bubonic plague

Surprise plague —

The person’s cat was reportedly extremely ill and had a draining abscess.

A cat, but not the one with plague.

Enlarge / A cat, but not the one with plague.

An Oregon resident contracted bubonic plague from their “very sick” pet cat, marking the first time since 2015 that someone in the state has been stricken with the Black Death bacterium, according to local health officials.

Plague bacteria, Yersinia pestis, circulates cryptically in the US in various types of rodents and their fleas. It causes an average of seven human cases a year, with a range of 1 to 17, according to the Centers for Disease Control and Prevention. The cases tend to cluster in two regions, the CDC notes: a hotspot that spans northern New Mexico, northern Arizona, and southern Colorado, and another region spanning California, far western Nevada, and southern Oregon.

The new case in Oregon occurred in the central county of Deschutes. It was fortunately caught early before the infection developed into a more severe, systemic bloodstream infection (septicemic plague). However, according to a local official who spoke with NBC News, some doctors felt the person had developed a cough while being treated at the hospital. This could indicate progression toward pneumonic plague, a more life-threatening and more readily contagious variety of the plague that spreads via respiratory droplets. Nevertheless, the person’s case reportedly responded well to antibiotic treatment, and the person is recovering.

Health officials worked to prevent the spread of the disease. “All close contacts of the resident and their pet have been contacted and provided medication to prevent illness,” Richard Fawcett, Deschutes County Health Officer, said in a news release.

Fawcett told NBC News that the cat was “very sick” and had a draining abscess, indicating “a fairly substantial” infection. The person could have become infected by plague-infected fleas from the cat or by handling the sick cat or its bodily fluids directly. Symptoms usually develop two to eight days after exposure, when the infection occurs in the lymph nodes. Early symptoms include sudden onset of fever, nausea, weakness, chills, muscle aches, and/or visibly swollen lymph nodes called buboes. If left untreated, the infection progresses to the septicemic or pneumonic forms.

It’s unclear how or why the cat became infected. But cats are particularly susceptible to plague and are considered a common source of infection in the US. The animals, when left to roam outdoors, can pick up infections from fleas as well as killing and eating infected rodents. Though dogs can also pick up the infection from fleas or other animals, they are less likely to develop clinical illness, according to the CDC.

While plague cases are generally rare in the US, Deschutes County Health Services offered general tips to keep from contracting the deadly bacteria, namely: Avoid contact with fleas and rodents, particularly sick, injured, or dead ones; Keep pets on a leash and protected with flea control products; Work to keep rodents out and away from homes and other buildings; and avoid areas with lots of rodents while camping and hiking and wear insect repellant when outdoors to ward off fleas.

According to the CDC, there were 496 plague cases in the US between 1970 and 2020. And between 2000 and 2020, the CDC counted 14 deaths.

“Very sick” pet cat gave Oregon resident case of bubonic plague Read More »

every-homeopathic-eye-drop-should-be-pulled-off-the-market,-fda-says

Every homeopathic eye drop should be pulled off the market, FDA says

don’t risk it —

Eye drops are uniquely risky because the eye is an immune-privileged site.

Young man applying eye drops.

This year has been marked by many terrifying things, but perhaps the most surprising of the 2023 horrors was … eye drops.

The seemingly innocuous teeny squeeze bottle made for alarming headlines numerous times during our current revolution around the sun, with lengthy lists of recalls, startling factory inspections, and ghastly reports of people developing near-untreatable bacterial infections, losing their eyes and vision, and dying.

Recapping this unexpected threat to health, the Food and Drug Administration on Tuesday released an advisory titled “What You Should Know about Eye Drops” in hopes of keeping the dangers of this year from leaking into the next. Among the notable points from the regulator was this stark pronouncement: No one should ever use any homeopathic ophthalmic products, and every single such product should be pulled off the market.

The point is unexpected, given that none of the high-profile infections and recalls this year involved homeopathic products. But, it should be welcomed by any advocates of evidence-based medicine.

Homeopathy is an 18th century pseudoscience that produces bogus remedies that work no better than a placebo and, if prepared improperly, can be toxic, even deadly. The practice relies on two false principles: the  “law of similars,” aka “like cures like,” meaning a substance that causes a specific symptom in a healthy person can treat conditions and diseases that involve that same symptom, and the “law of infinitesimals,” which states that diluting the substance renders it more potent. As such, homeopathic products begin with toxic substances that are then extremely diluted—often into oblivion—in a ritualistic procedure. Some homeopaths hold that water molecules can have “memory.”

Clear risks

In the US, these products are marketed as legitimate treatments and sold alongside evidence-based treatments (though consumer advocates are trying to change that). The reason this is allowed for now is because of a regulatory quirk: Based on the 1938 Food, Drug, and Cosmetic Act, homeopathic products are generally considered exempt from pre-market FDA safety and efficacy reviews as long as the active ingredient in the product is included in the Homeopathic Pharmacopoeia, a list of substances approved by homeopaths.

In recent years, the FDA and the Federal Trade Commission have cracked down on homeopathic products, though. And it seems from today’s advisory that the FDA is not holding back on homeopathic products for the eyes. The regulator notes that any products meant for the eye “pose a heightened risk of harm” because the eyes are an immune-privileged site in the body. That is, innate immune responses are restrained in the eye to prevent damaging inflammation, which could threaten vision. “Any drug used in the eyes must be sterile to reduce the risk of infection,” the FDA said.

But whether or not homeopathic eye drops are labeled as sterile doesn’t seem to matter to the FDA. The regulator cautions: “Do not use ophthalmic products that: Are labeled as homeopathic, as these products should not be marketed.” Their lack of pre-market safety and efficacy reviews appears to be enough to warrant avoidance.

The FDA also cautions consumers not to use any over-the-counter eye drop product that claims to treat glaucoma, cataracts, retinopathy, or macular degeneration because there are simply no actual over-the-actual treatments for these conditions. If a non-prescription product claims this, you can assume it’s bogus and avoid it. Consumers should also avoid anything that includes Methylsulfonylmethane (MSM), which is illegally sold in the US, and anything with silver sulfate or argentum because these can permanently change the white color of your eyes.

Every homeopathic eye drop should be pulled off the market, FDA says Read More »