Are you a Windows iTunes user?

If so, you should upgrade iTunes immediately or run the risk of being infected with the BitPaymer ransomware strain.

The group controlling the software has been spotted using a zero-day exploit in iTunes for Windows, which allows them to bypass antivirus detection schemes entirely.

The good news is that Apple responded quickly to the flaw's discovery and has already patched the zero-day out of existence in both iTunes for Windows and iCloud for Windows. The bug itself resided in the Bonjour updater component that ships with both products. The hackers discovered that by abusing the "unquoted service path" vulnerability, they could launch Bonjour then hijack the execution path, pointing it to the BitPaymer executable instead.

The bug allows hackers to install ransomware

While the bug did not grant the hackers admin rights on the target machine, it allowed them to install the ransomware locally without detection, which is certainly bad enough on its own. Unfortunately, there's a complication you should be aware of.  If you used iTunes or iCloud for Windows in the past and uninstalled the software, the Bonjour component almost certainly remained behind, rendering your system vulnerable to the attack even if you're not currently using either application.

Your system administrator will need to manually search for and delete the Bonjour component.  If you are using either, then simply updating to the latest version will also update Bonjour, rendering your system protected.

It's interesting that BitPaymer is being used in this way because typically, that particular strain of ransomware is used in "Big Game Hunting" attacks that target large organizations and seek to infect as many machines as possible, demanding a huge ransom.

Our perspective

This particular attack is designed to impact a single machine, so it could be a sign that BitPaymer's owners are shifting gears, but it's too soon to say that with any authority.

As Hill Street Blues' Sgt. Esterhaus always advised: "Hey, let's be careful out there!"

Meanwhile, check out this report

This free executive report may give you insights into how to build your business with safe IT environments: 10 Hidden IT Risks That Might Threaten Your Business and 1 Easy Way to Find Them

The author

Thanks for reading this short post. For more tips on thriving with small business technology, check out the other blog posts at DWPia Blogs. I am also available on LinkedIn, Facebook, and Twitter.

Cybersecurity Expert, Small Business Technology Consultant, Managed Services Provider, Managed IT SupportI am Denis Wilson, President and Principal Consultant for DWP Information Architects. I help professionals grow their business by building a foundation of rock-solid information solutions for smaller healthcare, insurance, financial, legal, and nonprofits firms in Ventura County and San Fernando Valley. And have created cost-effective IT solutions, for over 20 years, specializing in cybersecurity and regulatory compliance. I am also a published author and speaker, working extensively with a variety of organizations, as well as providing small business technology education programs through business and professional associations. This just in: I will be speaking regularly at California Lutheran University's Center for Nonprofit Leadership starting in September.

Contact me if you would like me to speak at your association.