{"id":5565,"date":"2012-08-21T12:47:17","date_gmt":"2012-08-21T19:47:17","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=5565"},"modified":"2016-02-12T10:30:11","modified_gmt":"2016-02-12T18:30:11","slug":"new-crisis-behavior-observed-now-infecting-virtual-machines","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/","title":{"rendered":"New Crisis Behavior Observed, Now Infecting Virtual Machines"},"content":{"rendered":"<p>The folks in Symantec&#8217;s research lab have found new behavior of a previously discovered <a href=\"https:\/\/www.intego.com\/mac-security-blog\/new-apple-mac-trojan-called-osxcrisis-discovered-by-intego-virus-team\/\">Crisis<\/a> package. To describe this newly discovered action in more technical terms, when the Windows component of the malware is run on a host machine which has VMWare installed, Crisis will mount VMware images it finds and then copy itself to those images. That way, all VMWare images will be infected with the malware without the user being aware.<\/p>\n<p>To break that down a bit more, let&#8217;s describe VMWare a bit further. VMWare creates an operating system within an operating system, kinda like Picture in Picture on a TV. It &#8220;mounts&#8221; a drive for each Virtual Machine image you create, which is a little partition for each image of the operating system. For those of you who run OS X, you see drives mounted on the system all the time in Finder, like when you run an install (DMG) file or insert a thumb drive. Those things that show up with an eject symbol next to them. This is a similar idea, in a very general sense. What this Crisis variant does is, when it&#8217;s run on a Windows system, it will mount all those virtual drive images that you created and then it will make a copy to that operating system within your operating system. It&#8217;s as if they were a physical drive like a thumb drive, and the malware will copy itself to the drive. So when an infected user tries to access those images again, the malware will be spying on them without them being aware.<\/p>\n<p>In order for this to happen, you have to be running the malware (initially) outside of a virtual machine. It&#8217;s not going to escape from one virtual machine directly into other images. So this does not invalidate the usefulness of virtual machines if you&#8217;re using VMWare in a security research environment. This just means that this malware can be that much harder to find and eradicate on infected machines, especially if you don&#8217;t make a habit of scanning your virtual machines like you would your physical machine.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The folks in Symantec&#8217;s research lab have found new behavior of a previously discovered Crisis package. To describe this newly discovered action in more technical terms, when the Windows component of the malware is run on a host machine which has VMWare installed, Crisis will mount VMware images it finds and then copy itself to [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8763,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[190],"tags":[86,703],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"The folks in Symantec&#039;s research lab have found new behavior of a previously discovered Crisis package. To describe this newly discovered action in more\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Crisis Behavior Observed, Now Infecting Virtual Machines - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"The folks in Symantec&#039;s research lab have found new behavior of a previously discovered Crisis package. To describe this newly discovered action in more\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2012-08-21T19:47:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-02-12T18:30:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lysa Myers\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg\",\"width\":\"400\",\"height\":\"260\",\"caption\":\"Malware Alert from Intego\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/\",\"name\":\"New Crisis Behavior Observed, Now Infecting Virtual Machines - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#primaryimage\"},\"datePublished\":\"2012-08-21T19:47:17+00:00\",\"dateModified\":\"2016-02-12T18:30:11+00:00\",\"description\":\"The folks in Symantec's research lab have found new behavior of a previously discovered Crisis package. To describe this newly discovered action in more\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Crisis Behavior Observed, Now Infecting Virtual Machines\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\"},\"headline\":\"New Crisis Behavior Observed, Now Infecting Virtual Machines\",\"datePublished\":\"2012-08-21T19:47:17+00:00\",\"dateModified\":\"2016-02-12T18:30:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#webpage\"},\"wordCount\":358,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg\",\"keywords\":[\"Malware\",\"OSX\/Crisis\"],\"articleSection\":[\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"caption\":\"Lysa Myers\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"The folks in Symantec's research lab have found new behavior of a previously discovered Crisis package. To describe this newly discovered action in more","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/","og_locale":"en_US","og_type":"article","og_title":"New Crisis Behavior Observed, Now Infecting Virtual Machines - The Mac Security Blog","og_description":"The folks in Symantec's research lab have found new behavior of a previously discovered Crisis package. To describe this newly discovered action in more","og_url":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/","og_site_name":"The Mac Security Blog","article_published_time":"2012-08-21T19:47:17+00:00","article_modified_time":"2016-02-12T18:30:11+00:00","og_image":[{"width":"400","height":"260","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lysa Myers","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","width":"400","height":"260","caption":"Malware Alert from Intego"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/","name":"New Crisis Behavior Observed, Now Infecting Virtual Machines - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#primaryimage"},"datePublished":"2012-08-21T19:47:17+00:00","dateModified":"2016-02-12T18:30:11+00:00","description":"The folks in Symantec's research lab have found new behavior of a previously discovered Crisis package. To describe this newly discovered action in more","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"New Crisis Behavior Observed, Now Infecting Virtual Machines"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a"},"headline":"New Crisis Behavior Observed, Now Infecting Virtual Machines","datePublished":"2012-08-21T19:47:17+00:00","dateModified":"2016-02-12T18:30:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#webpage"},"wordCount":358,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","keywords":["Malware","OSX\/Crisis"],"articleSection":["Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/new-crisis-behavior-observed-now-infecting-virtual-machines\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","caption":"Lysa Myers"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert-intego.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-1rL","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/5565"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=5565"}],"version-history":[{"count":7,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/5565\/revisions"}],"predecessor-version":[{"id":50218,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/5565\/revisions\/50218"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8763"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=5565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=5565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=5565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}