Virus creation for dummies (and some tips to stay safe)

virus

A computer virus could wreak havoc on your devices, network and even your entire business. But where do they come from, how easy are they to make, and how can you protect yourself from them? Find out in this blog, written by Ann, one of our Cyber Security Consultants.

Mr Potato Head

We all remember Mr Potato Head, right?  Our lovable, plastic spud that we could add features to, such as inverting his mouth to make him look sad, giving him frowning eyebrows or putting his nose on upside down. 

Okay, so I may be aiming this at the older generation, but a current day equivalent would be an Avatar, perhaps styled on our own appearance for a social media account or a character in a game, where we can design a player with very specific physical and personality attributes.  In our game, there would be at least one person that had the worst of all characteristics?  It would be easy to do, right? Anyone could do it.  

So, what if I told you that equivalent software was available ‘out there’ for the creation of viruses?  You do not need to be a programming legend to create a virus any more than you need to be one to create a character in a game.  On the contrary – all you need is a motive, a complete lack of any moral compass, and a computer… 

What is a computer virus? 

Viruses are files containing code that attack the host’s system using a variety of methods… those which the creator has selected.  They can attach themselves to programs and transmit themselves to other programs by making use of specific triggers.  Viruses need these events as they cannot self-start.  A trigger will come from an event created by the user, such as clicking a link on an email, visiting a website via a malicious advertisement, software, flashcards, pop-ups or other methods.  Once triggered, the virus can attack a system’s built-in programs, antivirus software, data files and system start-up settings but to name a few.   

How do you make a virus?

Let’s look at this screenshot of a real virus making tool, in which you can see some characteristics that would be annoying to the victim, but may not cause too much disruption to their day, such as disabling Notepad or Hiding the Windows Clock.   

virus

The ‘Crazy Mouse’ feature begins to introduce attributes that would make it difficult for them to continue with their work. Likewise, the ‘Swap Mouse Button’ would create significant irritation and may result in the mouse being replaced, only to find that the same behaviour happens with the new mouse.   

But look at some of the other features here – some of them are far more dangerous.  For example, imagine if the Windows anti-virus and firewall was disabled, the remote desktop feature enabled, windows updates disabled (so windows cannot self-update and switch these features back on)… That would mean that all the tools the user might use to investigate what’s happening, have been disabled.   

If you think that’s bad… it gets worse… 

Just switch it off and back on again… it will be okay 

After activating the above virus, as all the drives have been disabled, the screen will go blank.  What would you do? 

Maybe you would switch it off and on again? Most of us would do the same, and sometimes that works. But if you have a virus that has been created by someone that really wants to ruin your day, then switching the device off and on again may all be part of their evil plan.    

It’s scarily easy for an attacker to change your Windows username and password – just two clicks and then you can’t even log in.  But they can, and they may also have remote registry enabled – and the correct username and password. 

The attacker can also enable features like converting to a worm, which gives the virus the capability to infect other computers by duplicating itself. 

In all probability, the only other person to have an account on your device would be a senior member of staff or a member of IT, they may attempt to login… with their Admin credentials.  Hmmmmm  

What kind of person would make a virus? And why?

It’s fair to say that money is a key motivator behind the majority cyber attacks.  Attackers generally fall into 1 of 5 categories: 

Cyber criminals

These are individuals or groups of people who are intent on stealing sensitive company information or personal data and generating profits. 

Hactivists 

Motivated by a desire to promote a political agenda, religious belief, or social ideology.  They often work together and see themselves as fighting an injustice.  

State-sponsored attackers

These have particular objectives aligned with either the political, commercial or military interests of their country.  They have vast resources, employ skilled hackers and are more likely to perform a sustained attack. 

Insider threats

A threat to the organisation that comes from a member of staff, former member of staff, or third-party organisation including contractors and other temporary workers, and can be categorised as follows: 

  • Malicious – an intention to access and deliberately cause harm. 
  • Accidental – may accidentally delete an important file or share confidential data. 
  • Negligent – when an employee tries to avoid the policies put in place to protect endpoints and valuable data e.g. sharing files to a personal share file so they can work at home. 

Script kiddies

These are people who use scripts or programs, such as the virus-maker above, to attack computer systems and deface websites, for the sheer fun of it.  

How do I protect myself and my business?

We have seen that creating and launching a virus is as easy as creating a character in a game. We have also seen that potential attackers come in various shapes and sizes.  So, we must be proactive in ensuring that our devices and systems are as well protected as possible.

What should I do to prevent a virus from wreaking havoc on my business?

  • Ensure you have up-to-date anti-virus software on all machines – and that it is both enabled, and conducting regular scans
  • Disable AutoRun and AutoPlay on your Windows PCs. Why? Because this feature automatically executes files, which removes your first line of defence if you accidentally download some dodgy software, or connect an unknown, potentially malicious device. For example, if you were to plug in a USB stick without disabling AutoRun, your computer would automatically open it without giving you a chance to scan it with your anti-virus, which means you may not be able to prevent malware from infecting your computer
  • Ensure your team receives regular awareness training. After all, viruses don’t just magically appear on machines. They need a human to do something – for example, clicking a link or downloading a file
  • Introduce – and enforce – policies that help your team do the right thing (eg – ban USB sticks)
  • Ensure software security patches are applied as soon as possible

How can Securious help?

We know our stuff when it comes to protecting your devices, network and business from the bad guys. We can help you with your policies and processes, deliver world-leading staff awareness training and phishing simulations, conduct vulnerability and risk assessments, and a whole host of other things besides.

Get in touch using the contact form below if you’d like to get your business in good shape.