Symantec discovers new malware targeted at SQL databases


by CBR Staff Writer| 23 November 2012

The new 'Narilam' malware has affected several Symantec's Iranian business clients.

Computer security firm Symantec has discovered a new malware that targeted Iranian businesses to steal financial and sales data.

Designed to destroy business data in Microsoft SQL databases, the new 'Narilam' malware has affected several Symantec's Iranian business clients, the anti-virus firm said.

Symantec's Shunichi Imano said in a blog post that the malware does not have any operation to steal data from the infected system and is programmed specifically to harm the data stored within the targeted database.

"Given the types of objects that the threat searches for, the targeted databases seem to be related to ordering, accounting, or customer management systems belonging to corporations," Imano said.

On an affected system, the malware searches for Microsoft SQL databases, following it hunts for specific words in the SQL database and will replace them in the database with random values or erases certain fields.

The names that can be accessed by malware include 'hesabjari,' which means current account, 'pasandaz' which means savings and 'asnad' meaning financial bond.

"Unless appropriate backups are in place, the affected database will be difficult to restore," Imano said.

"The affected organization will likely suffer significant disruption and even financial loss while restoring the database.

"As the malware is aimed at sabotaging the affected database and does not make a copy of the original database first, those affected by this threat will have a long road to recovery ahead of them."

Post a comment

Comments may be moderated for spam, obscenities or defamation.

Join our network

756 people like this.
0 people follow this.

Security Intelligence

Buy the latest industry research online today!
See more

Suppliers Directory

Privcy Policy

We have updated our privacy policy. In the latest update it explains what cookies are and how we use them on our site. To learn more about cookies and their benefits, please view our privacy policy. Please be aware that parts of this site will not function correctly if you disable cookies. By continuing to use this site, you consent to our use of cookies in accordance with our privacy policy unless you have disabled them.