ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Crisis Malware Threatens Virtual Machines

Paul by Paul
August 26, 2012 - Updated on June 4, 2022
in Malware
Reading Time: 2 mins read
7caf22f1dd99fc97297b5259da407af21
Share on FacebookShare on Twitter

Lately, news is circulating on the web that a Windows version of the Crisis Malware is able to infect VMware virtual machines.

The malware has been detected on VMware virtual machines on compromised hosts and it is able to copy itself onto an image by using a VMware Player tool.

What is important is to clarify is that the malware doesn’t exploit any vulnerability in the virtualization engine, but uses the mechanism of storage of local files that could be manipulated by malicious applications.

In many cases, the malware designers implemented a feature that made them inactive when the host is a virtual machine to avoid being discovered and analyzed.

Takashi Katsuki of Symantec explained in his blog post:

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

“Many threats will terminate themselves when they find a virtual machine monitoring application, such as VMware, to avoid being analyzed, so this may be the next leap forward for malware authors. It also has the functionality to spread to Windows Mobile devices by dropping modules onto Windows Mobile devices connected to compromised Windows computers”

Crisis Malware is an agent used to spy on victims by intercepting communications, and it is able to open a backdoor on the infected host once the user executes a Java archive (JAR) file made to look like an Adobe Flash Installer.

The malware has been developed for several OSs, and last month a Mac version had been isolated.

The malware has a long history, one of the oldest versions was detected during the Arab Spring when it was spread to spy on journalists, and it has been also been adopted by groups of criminals with the intent to steal banking credentials.

Lysa Myers from Intego’s Mac Security Blog clarified that the malware could infect a virtual machine only after being executed on an infected host. Outside of a virtual machine, it’s not possible to infect an image of a virtual environment without compromising the PC first.

This characteristic makes the trojan harder to detect especially in the absence of security protections in the virtualized environment.

Assuming we have malware that is able to infect different environments such as Mac, Windows, virtual machines, and Windows Mobile, that represents an innovation for the way it spreads to the targets it attacks… we must not underestimate it!

Tags: Crisis MalwaremalwareVirtual MachineVM
Previous Post

McAfee Releases Bugged Update

Next Post

AVG 2013 product line launched

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024
Please login to join discussion

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.