Showing posts with label Bitcoin. Show all posts
Showing posts with label Bitcoin. Show all posts

Wednesday, 14 March 2018

Dofoil Malware (Smoke Loader): Infected MediaGet Update After Recent Cryptominer Outbreak



An infected update for the torrent client MediaGet is responsible for the large cryptominer outbreak that Microsoft warned last week. The software giant quickly discovered 400,000 cases of Dofoil malware on computers, which eventually downloaded the cryptominer.

Following screenshot is Dofoil Malware Timeline:


The cryptominer uses the computational power of the infected computers to mine cryptocurrencies. In particular computers in Russia, Turkey and Ukraine were affected by the malware. Dofoil, also known as Smoke Loader, normally spreads via infected e-mail attachments and exploit kits. Striking in the outbreak last week was that most infected files came from a process called mediaget.exe. MediaGet is a program to download torrents. In this case, the malware was not downloaded via infected torrents, but from the program itself.


Further research showed that it was a carefully planned attack, according to Microsoft . The attackers distributed an infected user update from February 12 to February 19 this year via the MediaGet update servers. This update installed a backed up version of the torrent client. From March 1 to March 6, this backdoor was then used to install malware among users. Microsoft says it has shared information with the MediaGet developers, but they have not yet reported the incident on their website.

Wednesday, 25 October 2017

Assault Modifies Dns Coinhive Using Reused Password


An attacker succeeded in adjusting the coinhive dns yesterday, making websites using the cryptominer a JavaScript file of the attacker's being. Coinhive is a cryptominer that uses the computer's computing power to cryptocurrency Monero through the browser. To do this, the computer performs a cryptographic calculation.

Owners of websites that want to use Coinhive must point to a coinhive JavaScript file on their website. This file is then uploaded by the visitor's browser, after which the computing power of their computer is used to perform the cryptographic calculation. The attacker was able to access the Coinhive Cloudflare account. Cloudflare is Coinhive's dns provider.

Then, the attacker changed the DNS settings, which forwarded requests for coinhive.com to another server. This server turned a custom version of the JavaScript file. This caused the attacker to benefit from the calculations made by website visitors, rather than the websites running Coinhive.

According to Coinhive , the Cloudflare account has been hacked through an unsafe password probably stolen at Kickstarter's hack in 2014. "Since then, we learned hard lessons about security and used two-factor authentication and unique passwords for all services, but have failed to update our years-old Cloudflare account," said Coinhive. We are now looking at ways to offset affected websites.

Wednesday, 5 July 2017

Attackers Behind Petya-Ransomware Emptying Bitcoin Wallet


The attackers behind Petya-ransomware have 9,000 euros paid by victims transferred to another bitcoin wallet. That leaves Aleks Gostev on Twitter know, chief security expert at anti-virus firm Kaspersky Lab. The ransomware which last Tuesday infected several organizations showed users see a screen where they were instructed to make about $ 300 to the specified bitcoin wallet.

Unlike many other ransomware became for all victims the same bitcoin wallet used. Last night decided the attackers 9,000 victims who had paid to worry about another wallet. In addition, there appeared on Pastebin message that bitcoin 100 (225 000 euro) were asked for the decryption key to decrypt all infected systems by Petya.

However, it is unclear whether the persons who placed the Pastebin message also behind the Petya-ransomware. According to researcher Matt Suiche attackers try to confuse the public by the story Petya actually a wiper which data could again turn into a story about ransomware, let him opposite Vice Magazine know.

Fourth Largest South Korean Bitcoin Stock Exchange Bithumb Hacked



Attackers have hacked the fourth largest South Korean bitcoin stock exchange Bithumb and data and money of users stolen. Bithumb is one of the largest exchanges where digital currency bitcoin and ethereum traded. The attackers were able to access the personal information of nearly 32,000 Bithumb users, including names, mobile phone numbers and email addresses, so let know Brave New Coin.

According to the exhibition is about three percent of the customers. Let customers know that converted stolen millions of euros to digital currency, but Bithumb suggests that the attackers had no direct access to client funds. According to the fair, the attackers managed to penetrate through the computer of an employee. The attackers would then use the stolen personal information to calling customers and to steal additional information which transactions could be carried out.

Bithumb discovered the data breach on June 29 and alerted the authorities on 30 June. More than 100 Bithumb users have been reported to the South Korean police. The exchange said the victims of the data breach will pay a fee of the equivalent of 76 euros. Users who have suffered Further damages will be compensated for as soon as the amount is confirmed, so notify South Korean media.

Saturday, 14 November 2015

2000 Sites Affected By Linux Ransomware



The ransomware that encrypts Linux web servers has already affected some 2,000 Web sites, but it is still unknown how systems get infected in the first place. Last week, reported the Russian anti-virus company Doctor Web that Linux ransomware had discovered.

The malware encrypted files and demanded one bitcoin, equivalent to 300 euros. The text file with instructions proved to be indexed by Google, so the number of affected sites could be mapped. Initially it went to a hundred websites, as shown by the Google search results. The Finnish anti-virus company F-Secure estimated, used on the basis of the bitcoin wallet that the ransomware that approximately 36 people of the requested ransom also had paid.

Now reports Doctor Web which now has around 2000 sites affected by the ransomware. This relates to WordPress websites and web shops running on Magento. The attackers know exactly how to enter, according to the virus fighter is not yet known.What is known is that it is still all about the first version of the Linux ransomware, which contains an error. This allows victims to free decrypt their data via a Bitdefender tool. Doctor Web warns that the chances are that the creators of the ransomware end up with a new version including all the problems are solved.

Tuesday, 10 November 2015

Researchers Crack Linux Ransomware By Design Flaw


Researcher managed to crack the Linux.Encoder-ransomware for Linux so that victims without paying their files to recover. The ransomware was last week announced by the anti-virus company Doctor Web. At the time, it was unknown how the ransomware spreading.

It was known that it was mostly web servers that were infected. Now the Romanian anti-virus company said Bitdefender attackers use a vulnerability in the popular content management system magento to access servers. Then they install the ransomware, which looks a lot like Windows ransomware. Like Windows-based ransomware encrypts Linux.Encoder files with AES. The symmetric key is then encrypted with an asymmetric encryption algorithm (RSA).

When designing the ransomare the creators have made ​​a big mistake, allowing researchers Bitdefender can identify the AES key without that first with the RSA private key must be decrypted. The ransomware does not use any keys and initialisation vectors for encryption, but leads these two pieces of information on a specific feature in combination with the time of the encryption. This information is easily retrieved and, according to the researchers, a major design flaw. They now have a tool(zip) has been developed which automatically encrypted files can decrypt.

Sunday, 1 November 2015

Third Suspect Arrested For Assault On TalkTalk


The British police for the third time this week arrested a suspect for the attack on the British ISP TalkTalk, with data from less than 1.2 million customers were stolen. That the Metropolitan Police today announced.

The third suspect was arrested yesterday afternoon. It is a 20-year-old man. Earlier this week, two boys were 15 and 16 arrested. The provider has since announced that there is indeed in the attack data is captured, but less than was initially assumed. It is less than 1.2 million e-mail addresses, names and phone numbers of customers. In addition, tens of thousands of birth dates, account numbers and partly made ​​unrecognizable credit and debit card data captured. How the attackers managed to pull the trigger is still unknown.

Friday, 30 October 2015

Ransomware Provides Criminals Possibly $325 Million



The newest variant of CryptoWall-ransomware the creators possibly $ 325 million delivered, say Fortinet, Intel Security, Palo Alto Networks and Symantec (pdf). Concrete evidence that the criminals that amount actually earned their ransomware lacking.

CryptoWall is a form of ransomware that appeared almost a year ago for the first time. Like other ransomware encrypts files on the computer and pay victims for decryption. For their study looked at the security to version 3 of CryptoWall. This version is spread mainly via e-mail, according to analysis of 70,000. 67% use email as an infection vector, while 31% spread through vulnerabilities in popular software such as Adobe Flash Player and Internet Explorer.

The infection vector of the remaining percentage is not disclosed. In the case of the e-mails are mostly zipped attachments sent with it .scr files. Scr is the file for Windows screensavers, but acts the same as a normal .exe file. To leave nothing suspecting victims were adjusted as the icons of the files. In addition, in Windows by default not show the file extension, allowing users not to realize that it was an executable file.

Damage

According to the security CryptoWall version 3 would have caused an estimated damage of $ 325 million, but this is not clearly substantiated in the report. For example, it pointed to the bitcoin-wallets where victims had to make money at it, but the construction of the $ 325 million is not explained. The gang used according to the kinds of security-bitcoin wallets to funnel money and so to cover their tracks, which hampered the investigation.

Further inside, the report pointed to a campaign that made ​​15.000 victims, but it is unclear whether all of these victims have been paid, as researchers use the words "would account" and "associated".

Update

The security companies know that the damage is based on a large bitcoin wallet which reportedly all payments of the victims eventually ended up. With an average ransom amount of $ 500 which would involve some 650,000 victims CryptoWall version 3 paid the ransom. Earlier research at Dell SecureWorks showed another variant of CryptoWall that only 0.27% of the paid victims. If this percentage would apply to version 3 would mean that hundreds of millions of people have been infected worldwide, which seems unlikely. We have companies therefore requested further explanation.

Tuesday, 27 October 2015

15-Year-Old Boy Arrested For Assault On TalkTalk


British police arrested a 15-year-old from Northern Ireland for the attack on the British ISP TalkTalk, reports the Metropolitan Police. It is still unclear whether the attack there customer data is captured.The provider sets in a statement that the investigation is still ongoing.

"But unfortunately there is a chance that some of the following information may be accessed," said TalkTalk. This relates to names, addresses, birth dates, email addresses, phone numbers, TalkTalk account details and credit and debit card information and / or bank details. The possible stolen card information, however, would not be able to be used for financial transactions. The provider is also pleased with the swift action of the police.

Tuesday, 18 August 2015

Ransomware-Maker: The Victims Have Paid More Attention


A new ransomware variant that has been in development since early this year has a real roadmap for victims to explain the situation they find themselves in, where users also clear that the infection is their own fault. The ransomware was discovered by the Dutch security researcher Yonathan Klijnsma , who works at the Delft Fox-IT.

CryptoApp, as is called ransomware encrypts files with 162 different file extensions, like .docx, .avi and .xslx. Remarkably, according Klijnsma that files from QuickBooks accounting software is encrypted. Once active on a computer, the ransomware is looking not only at local disks for files to encrypt, but also relied network drives. As with other ransomware variants must then be paid an amount to decrypt the files.


It is in this case to an amount of 1 bitcoin, what with the current exchange rate 231 euros. On the website of the ransomware is user-maker explained their situation. As the author states that victims have been infected because they have not been paying attention. Also, the computer of the user according to the ransomware maker poorly protected and the files can be recovered only by paying. Thereby paying victims are advised to turn off their virus scanner.

The tool for decrypting the files can namely be considered as malware and removed by the virus. In that case, users will lose all their files, according to the warning. According Klijnsma the ransomware is not widespread and probably still in development. The website of the ransomware-maker, which was hosted on the Tor network, early August is gone. It may be that the author, the project has stopped or a new location sought to continue its operation, with the old website was a test setup, the researcher says.

Tuesday, 11 August 2015

Ransomware Focuses On Russia And Ukraine


Makers of ransomware is not only aimed at English speakers, also should beware of Internet users in Russia and the Ukraine. Microsoft saw earlier this year named a ransomware variant appear Troldesh mainly in June was very active. The malware spreads through exploit kits, which infect Internet via, for example vulnerabilities in Adobe Flash Player.

Once active Troldesh encrypts files on the computer and then asks for a fee to decrypt them. Unlike other ransomware which victims must make the payment in bitcoin, the maker of Troldesh communicate via email with his victims. On the infected computer is left a text file with instructions. These instructions enable the victim via e-mail contact with the author should include.

In June, a researcher contacted the maker, then successfully on the ransom amount to barter . Eighty percent of infections Troldesh took place in Russia, followed by Ukraine with 9%. Microsoft advises victims to not pay the requested ransom for decryption, as there is no guarantee that the victims referred to regain access to their files.

Sunday, 2 August 2015

Cisco Warns Of Emails With "Windows 10 Upgrade"


Cyber criminals have seized the launch of Windows 10 to distribute emails that attempt to infect surfers with ransomware. Before warns network giant Cisco . Windows 7 and Windows 8.1 users can upgrade to the new Windows version.

And cyber criminals now play in. The emails have the subject line "10 Free Windows Update" and seem to come from update@microsoft.com. The message that the recipient can upgrade to Windows 10. For this, the attached "installer" should be opened. In reality, the e-mail attachment "Win10installer.zip" a variant of the CTB Locker, a known form of ransomware that encrypts files on the computer for ransom.

Then users get 96 hours to pay the ransom in bitcoin, otherwise they lose their files. According to Cisco, the ransomware is now widely distributed. The networking giant also advises users to backup their files and keep these offline, so they can not be attacked by cyber criminals.

Hashes:

SHA256: ec33460954b211f3e65e0d8439b0401c33e104b44f09cae8d7127a2586e33df4 (zip)
aa763c87773c51b75a1e31b16b81dd0de4ff3b742cec79e63e924541ce6327dd (executable)

Wednesday, 29 July 2015

British Government Warns Of Ransomware


The British government has Internet users warned of ransomware, cyber criminals now use the name of the Ministry of Interior and the Ministry of Justice to infect computers with malware. The emails claim to come from a ministry and contain a link or attachment that contains information about an upcoming lawsuit.

In reality it is the Torrent Locker ransomware that encrypts files on the computer and then asks for a sum in Bitcoin to decrypt them. The UK Government says that it does not send unsolicited emails and never in e-mails asking for personal information and passwords. Additionally point links in e-mails from the Interior Ministry always to government sites that begin with https and on one. gov.uk are domain.

Saturday, 25 July 2015

FBI Warns Businesses For Extortion Through DDoS Attacks



The FBI has warned businesses through extortion DDoS attacks on their websites, as these attacks take place more often. The past few months have also several security companies to this form of extortion warned .

The attacks are carried out by a group that DD4BC (DDoS for Bitcoin) names and since last July is active. The FBI warning that Public Intelligence published ( PDF ), the group is not mentioned, but the method does is mentioned is identical. There is first a DDoS attack on the website of the company which usually takes place about an hour and has a size of 20 to 40 Gbps.You then send an e-mail with the demands of the attackers. That require an amount to be paid in bitcoin.

If the victim does not meet the requirements there will be a powerful DDoS attack within 24 hours, which lasts an hour and again has a size of 40 to 50 Gbps. This attack is succeeded by a warning. According to the FBI know most attacked companies to turn down the DDoS attacks by enabling the anti-DDoS services from third parties instead of paying the ransom. Where the attackers had first mainly on gambling sites provide, since April this year, other sectors targeted and larger amounts are required.

Friday, 10 April 2015

Ransomware Infected Dozens Of Computers Caregiver


A US healthcare end of last year the victim of ransomware, which files were encrypted on nearly 30 computers. Jeff Salter, Director of the Caring Senior Service, thought to be well prepared and had most of the files backed up and which could restore that.

From one machine lacked a backup. On the computer was the marketing material for 55 locations are franchised. Salter decided ransom of $ 500 then pay to recover those files. "It had cost us $ 50,000 to make everything again", he compared know the Associated Press. "It would have been a serious blow if we had lost the material." This week it was announced that an American police station that was hit by ransomware also the ransom had been paid.

Wednesday, 8 April 2015

American Police Pay Again For Ransom Ransomware


Again there is an American police by ransomware became infected and was forced to pay the ransom of hundreds of dollars. This time it was a police station in the town of Tewksbury in Massachusetts. In December the police system showed a warning that all files were encrypted and $ 500 to be paid to recover the files.

Because of the infection, the police had problems to request the arrest and incident records, as well as any other information that is only now through the Tewksbury Town Crier known. In total, the system was four to five days from the air. Via the computer was first infected knew the ransomware also encrypt all kinds of connected network folders and shared drives. The police did have a backup of the files, but that turned out to be corrupt.

The most recent backup that did work was 18 months old and insufficient to restore all lost data. Eventually decided to pay the police station and were all encrypted files are decrypted. "Nobody wants to negotiate with terrorists. No one wants to pay terrorists," said Police Chief Timothy Sheehan. "We have done everything possible." The agency Tewksbury is known thefourth police station after a ransomware-infection to pay rang.

Wednesday, 1 April 2015

American Ex-Officers Indicted For Theft Bitcoins


Two former US agents are charged with the theft of bitcoins that were used during the investigation into the online drug marketplace Silk Road and seized. It is an agent of the Drug Enforcement Administration (DEA) and an agent of the Secret Service.

The two officers were part of the Baltimore Silk Road Task Force, which investigated the illegal activities of the Silk Road.Through the Silk Road were all kinds of drugs marketed. The administrator of the marketplace in late 2013 arrested and sentenced early this year. The DEA agent operated as an undercover agent and made ​​contact with the administrator of the drug market. However, the agent would without permission different online identities have used that were involved in criminal activities, including the steal of bitcoins from the US government and the defendants that he had to investigate.

He asked as part of the research for bitcoins and got it from the government. However, he did not indicate that he had received the digital currency and made the money to his own private-account. He would also information about the government investigation of the Silk Road have passed on to the administrator of the marketplace. Furthermore, the agent while he was still working for the DEA worked at a bitcoin scholarship.

There he forced the company to freeze the account of a customer and to make money from this customer to his own account. According to the FBI, the man would further unauthorized summons from the Department of Justice sent to an online payment service, which was set to release his private-account again.

Secret Service of the agent would be more than $ 800,000 in bitcoins, where he was given control over the course of the investigation to the Silk Road, to his own account at the now bankrupt Japanese bitcoin scholarship Mt. Gox have made. He then transfer the money to his personal investment account in the United States. A few days later he was for an amount $ 2.1 million in accounts of Mt. Gox studded show place. The DEA agent was arrested on March 27, while the agent of the Secret Service itself indicated yesterday.

Wednesday, 25 March 2015

Fake Email Wehkamp Spreads Ransomware


Mail order company Wehkamp warns Internet users for an email that already goes around a few days and seems to come from the company, but in reality that is spreading ransomware encrypts files for ransom.According to the email, the recipient would have placed an order with Wehkamp.

It is the computer game Fifa 15 for the PlayStation 3. The message notes for more information on the order to the included zip annex which has an order number. The zip annex again contains an .exe file with an icon from Adobe that the malware appears to be. It is a variant of CTB Locker, which stands for Curve Tor Bitcoin. This ransomware resurfaced last year for the first time. Once users the .exe file to open the computer becomes infected and all kinds of files encrypted. Then users get some days to pay the ransom for decrypting the files.

The infected e-mails using the name of Wehkamp went last week all around, according to a warning from security researcher Mark Loman Twitter. Since then notify all kinds of Twitter users that they have the message received . Increasingly it appears to the so-called order of the computer. "There is indeed a phishing email around that does not come from us. You can best remove him immediately and not open!", says Wehkamp via Twitter.

Saturday, 28 February 2015

Privacy OS Tails adds to bitcoinportemonnee


This week there's a new version of it appeared on privacy-oriented operating system Tails, including a bitcoinportemonnee as addition. Tails stands for The Amnesic Incognito Live System and is designed to leave minimal traces on the Internet. With the advent of Tails 1.3 several vulnerabilities have been resolved, but also added several new features.

The first feature that in the eye is the presence of sprint Electrum , a user for the digital wallet currency bitcoin. Another new feature is keyringer , a program that can be managed in encrypted fashion secrets and exchanged. For this, the software uses GnuPG and Git. Tails is a complete operating system that can be used from a DVD or USB stick. Despite all the attention to the privacy Tails developers recently showed that a daily basis but 10,000 of the privacy OS use.

Monday, 23 February 2015

American Police Pay $ 600 To Ransomware


An American police has cybercriminals paid $ 600 after a police computer became infected with ransomware. "Not everything was encrypted at the police station, it was only for that specific computer and files," said Calvin Harden, an IT provider who works with the city.

Harden notes that the cybercriminals have not stolen the information, but only acted encryptions. According to the Chicago Tribune ran the computer infected by someone at the police opened an infected email attachment. All files were then encrypted and there appeared a message that an amount was to be paid in bitcoins to recover the files. The police eventually made ​​$ 606.

"Because the backups were also infected the decision was made ​​to pay the hacker and the files to recover," Harden furthermore states. It is not the first time that an American police station in the news because of ransomware. In 2013 it was a police station in the state of Massachusetts who proceeded to pay, followed by police stations in Dickson County and Durham who were the victims of ransomware.