Showing posts with label Computer Virus. Show all posts
Showing posts with label Computer Virus. Show all posts

Tuesday, 14 July 2015

Hacking Team Has BIOS Rootkit For Permanent Infection



The Italian Hacking Team has an UEFI BIOS rootkit to infect computers with spyware permanently from the company. This enables the Japanese anti-virus company Trend Micro on the basis of the data that was recently at the Italian company captured.

Hacking Team offers government agencies a "Remote Control System" (RCS) allows investigators to remotely access the computers, for example, suspects can get. To ensure that the software remains on computers even if the hard drive is formatted or replaced by a new one, Hacking Team has an UEFI BIOS rootkit developed.

The BIOS (Basic Input / Output System) and the Unified Extensible Firmware Interface (UEFI), the successor to the BIOS is a set of basic instructions for communication between the operating system and hardware. It is essential for the operation of the computer, and also the first major software that is loaded. In the case of Hacking Team involves a rootkit for UEFI BIOS, Insyde Software. The company makes BIOS software for laptops.

Physical Access

To install the rootkit do have to have physical access to the system can be obtained. According to analyst Philippe Lin Trend Micro can not be ruled out that it is also possible to remotely install the rootkit. The Italian company also developed a tool to help users of the rootkit and provides support in the event the BIOS image is not compatible. According to Lin, the rootkit can be modified so that it also works with other BIOS software, such as the well-known software vendor AMI.

To protect themselves against the attacks, users of Lin's advice to enable UEFI Secure Flash BIOS, update the BIOS if updates are available and set a password to access the BIOS or UEFI. However, it is in many computers as possible to reset the password, but in this case, a user can see that something is wrong because he forgot no longer have to specify whether his original password no longer works.

Wednesday, 24 June 2015

Maker Black Shades Malware Gets Almost 5 Years In Prison


In the United States a 24-year-old Swedish man was sentenced to a prison term of nearly five years for developing the Black Shades malware, as reported to the US Department of Justice. Through Black Shades were users of the malware full control over the computers of their victims, including the webcam.It was also possible to view pictures via the malware, saving keystrokes and steal passwords.

The malware was offered at a cost of between $ 40 and $ 100 and could easily be adapted for various purposes. Globally, more than 500,000 computers in more than 100 countries with malware infected. According to the Department of Justice Black Shades would have been sold to thousands of criminals and this generated between September 2010 and April 2014 a total of more than $ 350,000. Last year there was a major international operation against users Black Shades place where the Dutch police attended.

According to the indictment of the American OM the Swede led his organization, which led to the development of Black Shades, like a real business, which he took and sacked employees, salaries and customized the software at the request of its customers. He also had several managers employ to keep the organization running, such as a marketing director, a website developer, a customer manager and a real team of customer service representatives.

The Swede was arrested in late 2013 and Moldova last April extradited to the United States. In addition to his prison sentence of 57 months, he must also give an amount of $ 200,000 and the computer that was used for the development of the malware.

Saturday, 20 June 2015

Network Waste Processor Fukushima Infected With Malware



The Japanese state company that manages radioactive waste resulting from the nuclear reactor of Fukushima was hit by malware, as it has Japanese Ministry of Environment announced. The Japan Environmental Storage & Safety Corp (JESCO) manages the locations where the radioactive material, which is the consequence of the nuclear disaster in 2011, is stored.

According to the Ministry on the network discovered unauthorized communication to the outside. Further investigation revealed that a computer virus had infected the intranet, reports the Japan Times . Because the infection was decided to take down the network. JESCO is busy setting up of facilities for the storage of radioactive soil and other debris. To this end, consultations with landowners.

However, computers JESCO would contain no information on the landowners, the ministry said. Recently it was announced that Japan Pension Service was infected with malware and attackers as access to pension data of 1.25 million Japanese had been given.

Thursday, 19 March 2015

Qakbot Botnet: "Infects Systems US Police"


Police in the US city of Baltimore has been hit by a computer virus which systems worked slower than normal. IT staff of the police was doing a research on what the inertia of the police systems caused the last few months, when they discovered the virus.

It was a variant of the Qakbot. This malware can data for online banking login credentials for social networks, Hotmail, Gmail, Yahoo !, credit card information, FTP, POP and IMAP logins, certificates and even steal the browsing history. Also can install additional malware Qakbot. Last year there was still a Qakbot botnet discovered from 500,000 computers existed.

How many computers have been infected with the police of Baltimore by the malware is unknown, but according to officials it could involve hundreds of machines, reports the Baltimore Sun . Police believe that the lack of security updates and other security has ensured that the virus could spread. The police do not think that information has been compromised or stolen.Meanwhile, outside help is enabled and started an investigation into the infection.

Tuesday, 3 March 2015

Anti-virus company: Europol Operation Failed Against Botnet


The operation against the Ramnit botnet that Europol several European investigative services and security last week performed partly failed, causing hundreds of thousands of computers controlled by cybercriminals, according to the Russian anti-virus company Doctor Web.

In the operation were seized hundreds of domains that the botnet used to communicate with infected computers, as well as different servers. The Ramnit malware did over a period of almost five years in total to infect 3.2 million computers. The last half year were approximately 500,000 computers have been infected with the malware.

Doctor Web suggests that there are several variations of Ramnit are active, including one which since September 2011 has been announced. This version can steal all kinds of passwords and FTP programs would have on hundreds of thousands of computers are active every day. "Despite the message in the media about a successful operation against the Ramnit botnet, our analysts have no decrease seen botnets that monitors the anti-virus laboratory," the anti-virus company.

According to researchers from the virus fighter would definitely twelve Ramnit botnets operate. Two of these botnets exist together from more than 500,000 infected computers. "The figures show that the parties behind the operation to destroy the botnet Ramnit evidently not been able to turn off all servers of this botnet," as the researchers conclude whatsoever.

Wednesday, 25 February 2015

Large Botnet Achieved By Europol In The Air


Europol has partnered with European investigation services a large botnet off the air that had infected 3.2 million computers worldwide. It involves Ramnit botnet that for years was active and on infected computers include passwords booty made ​​and other data.

Computers were infected by opening links in spam emails and visiting infected websites. Ramnit is also a so-called "file infector" who .exe, .dll- and .html files on hard drives and connected storage devices infected. Once a computer became infected malware added the infected code in these files, and as soon as they were started spreading the infection further. Also were found public FTP servers that were used for distributing Ramnit.

In addition to investigative agencies from the Netherlands, Italy, Germany and Britain Europol coordinated the operation with Microsoft, Symantec and Anubis Networks . During the operation of the botnet Command & Control servers were turned off, and the 300 domains that were used to control infected computers.

"This successful operation demonstrates the importance of cooperation between international investigative agencies and private industry in combating cybercrime. We will remain committed to disable botnets and disrupting the infrastructure used by criminals for cyber crime," said Wil van Gemert, Deputy Director of Europol. Microsoft and Symantec have now been delivered solutions to remove the malware from infected computers.