I should have posted this yesterday after I had read the analysis on the securelist blog (linked at the bottom) but wasn't sure if it was news worthy or just a write up on the malware
. It's a previously unknown secuirty weakness and is now being investigated by multiple security researchers as well as Microsoft.
Story @ the Register
VirusBlokAda advisory
The write up by Kaspersky can be found below and is in three parts under the title of Myrtus and Guava.
Securlist Blog
Hackers have developed malware that spreads via USB sticks using a previously unknown security weakness involving Windows' handling of shortcut files.
Malware targeting the security weakness in the handling of 'lnk shortcut files has been spotted in the wild by Belarus-based security firm VirusBlokAda. The malware uses rootkit-style functionality to mask its presence on infected systems. These rootlet drivers come digitally signed by legitimate software developer Realtek Semiconductor, a further mark of the sophistication of the attack.
Story @ the Register
VirusBlokAda advisory
The write up by Kaspersky can be found below and is in three parts under the title of Myrtus and Guava.
Securlist Blog