Showing posts with label Criminals. Show all posts
Showing posts with label Criminals. Show all posts

Tuesday, 20 January 2015

According To Researchers Avoid Chrome And Skype


Security researchers who work with sensitive information can better avoid Google Chrome and Skype, as recommended two researchers. According to Dani Creus and Vicente Diaz Kaspersky Lab happens that investigators are approached by criminal gangs and intelligence.

It also happens that researchers be bugged or that their devices while traveling is compromised. Operational security (OPSEC) is therefore essential, say Creus and Diaz. The main rule here is to remain silent. "If you do not have to say do not do anything. If you need to communicate with someone do it safely so you're not the contents of your message in danger and if possible also leave no metadata."

In the case of communication should be used such as email, instant messaging and phone the researchers several tips. So can only chat services that are trusted Off-the-Record (OTR) offering and Skype should never be used for discussing sensitive issues. Also, wherever possible, disposable phones are used. Furthermore, researchers are advised to use TrueCrypt to encrypt data.

To the Internet, according Creus and Diaz wise to use an 'air gap', which is created by an anonymous obtained 3G / 4G modem connection. Also have no cookies in the browser must be accepted and the execution of JavaScript can be prevented. Furthermore, users can not log on to an account and use Google Chrome is not recommended.

"OPSEC must be quickly part of the daily routine of security researchers," note the two researchers. "Given the kind of operation that is detected, and the parties concerned, the lack of knowledge and discipline in this area can have devastating consequences for researchers who do their work," concludes the pair. Earlier also gave a researcher called The Grugq sorts of tips for improving operational safety.

Sunday, 11 January 2015

Factories Target Online Banking Malware


Trojans designed to steal money from online bank accounts are also used at industrial plants and factories, so has had a security researcher know. Kyle Wilhoit anti-virus firm Trend Micro discovered thirteen different types of malware that occurred as software in SCADA (supervisory control and data acquisition) environments used. It involves, for example, Siemens WinCC, GE Cimplicity, Advantech and other human machine interface (HMI) products.

Although attacks on industrial environments often with attacks by countries are linked, it would be here involve ordinary cybercriminals. "It's an interesting trend, traditional banking Trojans and no targeted attacks," Wilhoit as late versus Dark Reading know. According to the researcher criminals focus their sights on SCADA / ICS systems because they are unsafe.

Many HMI machines run on Windows and would not use a virus scanner or are not equipped with the latest signatures. Most malware Wilhoit encountered no problems would be detected by an up-to-date virus scanner. While targeted attacks are still at risk managers should also take into account normal "crimeware", as the consequences can be just as bad. HMI systems are very susceptible to interference. Infection by a banking Trojan can also just as easily get the system down.

Wilhoit saw in October for the first peak in the attacks, but does not know what the occasion is. The criminals behind the malware use spear phishing mails and drive-by downloads to infect computers. Fake websites are used on that instance, resemble those of Siemens and supposedly download a WinCC update, while it is actually malware. Wilhoit 32 recently discovered malware instances that occurred as WinCC software. Next week, the researcher during a conference SCADA give more details about his research.

Tuesday, 23 December 2014

The Tor Network Is Under Attack



Tor users in the coming days may have problems with the use of its services. As representatives warn Tor, detected an attempt to take control of specialized servers, referred to as directory Authorities that support this network. They did not disclose what the hacker group or organization is behind this attack. "We have taken steps to ensure the safety of users of our services. Tor already uses redundancy mechanisms that will keep their anonymity, even if the planned attack will be executed. Tor is safe "provides" arma "on the blog associated with the project . "Arma" is a nickname associated with the project leader Roger Dingledine.

The Tor network packets are exchanged directly between the source and the receiver, and pass through several randomly selected relay servers, which mask the path of the flow of information and thus allow the anonymity of the users of the network. "Even if the attacker take control of the majority of servers, they will not be able to force the Tor client software to resign from the other relays communication and as a result will still be safe and anonymous "provides" arma ".

If you use Tor - you may want to note down and temporarily avoid these affected mirrors in a below pic

Affected Mirrors

Currently, Tor uses 9 servers to manage traffic in the network. They are located in the USA and Europe. At the moment (Monday 22/12/2014) there was no information about the planned attack on Tor. Representatives of the project promise that all information on the current situation will be immediately posted on the blog design . -providing anonymity on the Internet.

Tor network is used by users who want to avoid censorship and track their content published by the secret services, especially in non-democratic countries. Representatives say the Tor project, the network is also used by millions of people who want to ensure the security of the communication itself when connecting to the Internet in public areas. Unfortunately, it is also used by criminals, such as drug trafficking network Silk Road. It was closed down in October 2013 years by the US police, but there is another version - Silk Road 2.0. Despite these controversies, Tor network is one of the symbols of freedom and privacy of Internet communication and any attempt to attack this system probably will lead to big stir among users global network.

Sunday, 13 April 2014

U.S. sues nine people for spreading Zeus Trojan



The U.S. Justice Department has nine alleged members of a criminal organization accused of distributing and using the Zeus Trojan.
According to the prosecutor, they are responsible for infecting thousands of corporate computers with malware. Most of the suspects are from Ukraine.
Two of the suspects, Yuriy Konovalenko (31) and Yevhen Kulibaba (36) were arrested. The Ukrainians were arrested in the UK and have recently been extradited to the United States. Three other Ukrainians and Russian are also indicted but remain at large. The rest of the indicted individuals are not identified and included in the indictment. As "John Doe".

Indictment

All defendants are accused of conspiring to computer fraud and identity theft, conspiracy to commit extortion, several cases of bank fraud and identity theft qualified.
The suspects are accused of using Zeus or ZBot order bank account numbers, passwords, personal identification numbers, RSA SecureID token codes and similar information needed to log in to steal. On online bank accounts In the indictment was read to the accused banks were wise they were employees of the victims and were authorized to make transfers from the bank accounts of the victims.
Among the victims of the scam Zeus were the Bank of America, First National Bank of Omaha, Nebraska and the Franciscan Sisters of Chicago and Key Bank.

Method

The suspects reportedly used U.S. citizens as straw men. The straw men took the money and then returns to a foreign bank account of the criminals.
Kulibaba ran allegedly laundering network in the UK, while Konovalenko would have settled and was responsible for forwarding the information to Kulibaba. Straw men and the bank details The other members of the organization were responsible for the development of the malware and the financial and technical management.
"The Zeus Trojan is one of the most damaging financial malware ever used," said Assistant Attorney General David O'Neil. "As the charges demonstrate, we are determined to make the Internet safer and protect. Personal data and bank accounts of American consumers".

Research

The British police, the Dutch High Tech Crime Team and the Ukrainian Secret Service have the U.S. Department of Justice assisted with the investigation.
In 2007 Zeus botnet infected millions of computers worldwide. In 2010, a study by security firm RSA that almost all the "Fortune 500" companies have some form of a Zeus infection showed. From 2011 Zeus is sold as a commercial product.

Wednesday, 2 April 2014

Ransomware Crypto Defense allows decryption key behind computer victim

Ransomware Crypto Defense contains a crucial mistake: it allows the decryption key back to the computer of the victim.


Symantec analyzed Crypto Defense. The ransomware is part of the extended family of malware programs that encrypt files of victims until a ransom is paid. Crypto Defense uses Microsoft and Windows API to generate Encryption and decryption keys.

Key
Defense Crypto encrypts files using a 2048-bit RSA key. The secret key needed to de-crypt the files will be sent back to the server, the attacker until the ransom is paid again. Apparently the developers did not know that the secret key on the computer of the victim is in a directory containing application data. This key can decrypt the victim his data without the intervention of the cyber criminals. Itself, Unfortunately, the average user will not have enough knowledge to make this actually perform.

Success
Symantec estimates that have received, which shows the effectiveness of the scam. Cyber criminals within one month, more than $ 34,000 in bitcoins.
Symantec has blocked 11,000 Defense Crypto infection attempts in more than 100 countries. The majority of infection attempts were in the U.S., followed by Britain, Canada, Australia, Japan, India, Italy and the Netherlands.

MD5: f57d188c4667fab46208396af20badd2 (Virus Total Permalink)
         60f302b88160c27263c61c7e91dcb94e (Virus Total Permalink)

Monday, 31 March 2014

Barracuda launches Threat Glass

Barracuda Networks, the provider associated with the cloud storage solutions and ICT security, introduces Threat Glass, an online tool for searching, analysis and exchange of information on websites with malware. With Threat Glass users can see reviews of the infected websites with screenshots of the stages of infection and analyze network issues.

Daily popular websites cyber criminals exploited to. Malware to visitors loose Threat Glass of Barracuda Networks offers both casual users and the research community the opportunity to bring this persistent problem, identify and understand better. Threat Glass was developed as a front-end to a large-scale automated system that uses lightweight visualization for the independent detection of vulnerabilities and abuse thereof (exploits). The platform analyzes millions of websites every week. The websites that are submitted for inspection from various data feeds, including the top 25,000 websites by Alexa, social feeds and suspicious sites that are detected by the worldwide network of customers Barracuda, which spans more than one hundred fifty thousand organizations. Besides screenshots of the infection Threat Glass offers different views of network traffic, including DNS, HTTP and Net flow, in both graphic and text format. The system has about ten thousand live web-based malware attacks mapped to date and adds daily information on new events added.Detection engines from Barracuda Labs have numerous malware infections found in reputable websites. In recent months Barracuda Labs has published analyzes of popular websites like Cracked.com, Php.net and Hasbro.com.Information on this and thousands of other infected websites is now available through Threat Glass

Tuesday, 25 March 2014

XP malware allows criminals ATM emptying via SMS

ATM malware infects a Windows XP installation makes it possible for criminals by sending a single SMS message to retrieve the dispenser. Empty It involves the Ploutus malware last October for the first time in Mexico was discovered, but is now active in more countries.

Two weeks after the discovery of a new variant Ploutus was found . This version was translated not only in English but also had a modular architecture. Anti-virus company Symantec has this version further analyzed and discovered that criminals now the ATM to clean out. via sending text messages.

Attack
To attack the ATM criminals first need to have physical access to it. Then the ATM machine booted from a boot CD. This boot CD contains the Ploutus malware that infects the operating system of the ATM during startup. In addition, the virus may be present, the malware also switches off.

After installation, it is possible to activate Ploutus via a special key combination can be spent on command. Money Criminals straw men gave the command to retrieve the money had to share this key. If the straw men knew what could be done with the key they can light up their client, says Symantec.
Ploutus ATM attack overview


Smartphone
To solve this problem, the criminals can also link a smartphone to the ATM. The already installed malware ensures that the criminal can communicate. Using the smartphone with the ATM This avoids key shared. Lake with the straw man The criminal can now send an SMS to the ATM which then spends the money that is being recorded. Straw man by himself The attacks would have been observed. Different places in the world.

Symantec notes that as encrypted hard drives, which installed the malware may occur. Modern ATMs have better security, Older ATMs, however, would run on XP and are therefore more vulnerable. Ploutus example works only on Windows XP. Banks also get the advice to Windows 7 or 8 upgrade. In addition, the BIOS must be locked so that it can not be booted. From other media.

MD5:
488acf3e6ba215edef77fd900e6eb33b
b9f5bd514485fb06da39beff051b9fdc

Virus Total Link:
https://www.virustotal.com/en/file/0106757fac9d10a8e2a22dce5337f404bfa1c44d3cc0c53af3c7539888bc4025/analysis/

https://www.virustotal.com/en/file/34acc4c0b61b5ce0b37c3589f97d1f23e6d84011a241e6f85683ee517ce786f1/analysis/