Showing posts with label Cyber Criminals. Show all posts
Showing posts with label Cyber Criminals. Show all posts

Sunday, 27 October 2019

Ivacy VPN Review




With the levels of sophistication that cybercrime has shown, it is important that we hit back with equal forces. VPNs are one of the most effective weapons in this war and amongst the pack, a few stand out. Ivacy is undoubtedly one of them. Launched a little over a decade ago, it has become one of the most honored names in the business winning the coveted Fastest VPN award by BestVPN.com for speed.  
Online Security and Privacy
Ivacy provides the best when it comes to cybersecurity and user privacy. It has a strict zero-logging policy which means that no record of your data traffic is kept. Even if a hacker were to make their way into the system, they are bound to find nothing. The service also comes with 256-bit encryption, the highest that exists. Ivacy also offers Public WiFi security to its users. 
Fast and Unrestricted Streaming
In the beginning, people believed that VPNs were all about accessing blocked websites and downloading torrents safely. Besides several other functions, Ivacy also offers the best solution for streaming and downloading. Ivacy helps users get rid of speed and bandwidth throttling for online viewership. It also allows Smart Purpose Selection to help you deal with all types of restrictions easily. 
There are a number of streaming services like Netflix which choose to limit the viewership of their content for a number of reasons. This hits travelers more than ever. With Ivacy, not only can you watch your favorite shows without limitations but also download them via torrent without having to worry about data leaks. 
Advanced Security Features
There is a lot that Ivacy offers which may others don’t. It provides Split Tunneling and an Internet Kill switch that kills the internet when The VPN stops. The service has multiple logins which means that one account can be used to protect up to 5 devices. Ivacy also has protection for less known protocols like IPv6. 
Other similar features include DDoS protection, secure downloading, a variety of encryption protocols and a lot more. It is a comprehensive protection pack that is a must-have for most. Ivacy applications are available for every major platform including Windows, Mac, Android, iOS even Xbox and PS4. No matter what gadget you have, Ivacy protects it from cybercriminals. 
Affordable Pricing 
Ivacy has one of the most affordable bundles among all the top tier services. The pricing starts at $9.95 per month but as the duration of the package increases, prices drop and savings grow. The most widely bought package with Ivacy costs just $1.99 per month and runs over a period of two years. There is also a single year bundle that costs $3.33 per month. These amounts are billed as one transaction is advance.  
Conclusion
VPNs are becoming a crucial part of cybersecurity infrastructure for households and smaller companies. The only thing to be careful about is selecting the right service for the job. Without careful evaluation, even with a VPN you will experience the same threat levels or even more. 


Monday, 12 March 2018

Recent Adobe Flash Player Vulnerability Leak Attacked Via Exploit Kits



A recently patched vulnerability in Adobe Flash Player is being actively attacked via exploit kits. This means that visiting a hacked website or seeing infected ads with a vulnerable Flash Player version is sufficient to infect with malware.

The vulnerability in question was resolved by Adobe on February 6 through an emergency patch . The vulnerability appeared to have been targeted against South Korean organizations since last November . Here Excel and Word files with embedded Flash objects were used. Now it appears that cyber criminals also have the exploit to use them via the web.

Flash Player was and still is the most popular target for exploit kits. Due to the absence of new exploits, and the fact that more and more browsers are phasing out the support of Flash Player, the effectiveness of exploit kits has declined sharply in the past period . According to researcher Kaffeine of the Malware do not need coffee blog , this is the first new Flash exploit that has been added to an exploit kit since July 2016 for a Flash leak. The new Flash exploit will be deployed via infected ads and will successfully install the Hermes ransomware. Users are therefore advised to upgrade to Flash Player version 28.0.0.161 or later, as the vulnerability has been corrected.

Sunday, 11 March 2018

Leaked Source Code Ammyy Admin Uses For Malware



Source code of the remote desktop software Ammyy Admin has been used for malware that has been used for both targeted and large-scale attacks, according to security firm Proofpoint. Ammyy Admin is a program that allows remote access to computers.

Some time ago the source code of Ammyy Admin version 3 appeared on the Internet and cyber criminals have used it to develop malware called "FlawedAmmyy". This malicious version has been used in attacks since the beginning of 2016, but only recently discovered, Proofpoint says. Among other things, the automotive industry would be the target of the attacks.

To spread the malware, the attackers use e-mails that contain Word or ZIP files as an attachment. The Word files have a malicious macro that, when enabled by the user, downloads the malware on the system. Once active on a system, FlawedAmmyy can be used to steal trade secrets, customer data and other information from companies, according to the researchers.

Avast: Attackers CCleaner Also Wanted To Install keylogger



The attackers who hacked software company Piriform last year and added a backdoor to the popular CCleaner tool were also likely to install a keylogger on infected systems, according to anti-virus company Avast , which is the owner of CCleaner.

Last September, Avast announced that attackers had hacked CCleaner developer Piriform and added malware to the official version. This infected version was downloaded by 2.27 million users. The malware was added to the Piriform development platform between 11 March and 4 July 2017. The software company was acquired by Avast two weeks later on 18 July.

The first phase of the malware was to gather information about CCleaner users, such as the name of the computer, installed software and active processes. The second phase consisted of downloading additional malware. However, this was done with a select number of machines. Eventually, 40 computers received this additional malware. These included systems from major tech companies such as Intel, Samsung, Sony, Asus, NEC and the South Korean telecom provider Chunghwa Telecom.

There is no evidence that a third step has been carried out, but Avast has now found information indicating that it may have been planned. During the investigation into the hacked Piriform infrastructure, early versions of the first and second phase of the malware were discovered, as well as a tool called ShadowPad. ShadowPad is used by cyber criminals to control computers remotely. The tool was installed on four Piriform computers on April 12, while the second phase of the malware was already installed on March 12.

The older version of the second phase malware connected to a command & control server. The servers were no longer active at the time Avast analyzed the computers, so it is unknown what was downloaded, but given the time window it was probably ShadowPad. The Avast researchers also discovered ShadowPad log files with keystrokes from a keylogger installed on the computers. The keylogger had been active since 12 April and had stored keystrokes of all kinds of programs. The encountered version of ShadowPad appeared to have been specially made. Avast thinks that the attackers who had adapted especially for Piriform.

In addition to the keylogger, the attackers also installed a password builder and tools to install other software. According to Avast, there are no indications that ShadowPad is installed on the computers of CCleaner users. The virus fighter does state that it was the third phase of the attack. It is not known whether the attackers wanted to install the keylogger on all 40 attacked computers in the second phase, or just a few or not at all, this is still in under investigation.

Monday, 23 October 2017

Security Company: Microsoft Should Patch DDE Feature In Word


Microsoft has to come up with a solution to the DDE feature in Word now that cybercriminals use it . The Dynamic Data Exchange (DDE) feature of Word allows you to inject data from one document into a second document. Instead of a document, malicious code may also be linked. DDE is a legacy Inter-Process Communication (IPC) mechanism dating from 1987.


It consists of a protocol designed to exchange messages between two applications. In the case of DDE, it is further enhanced by giving access to shared memory. Microsoft Office provides an extension to allow DDE to communicate within external processes. Thus, DDE in a Word document may not only allow Excel to be invoked, but also to execute commands on the system via cmd.exe.

Security company SensePost warned Microsoft, but the software giant said it would not take any measures for the time being because DDE is considered a feature. It may be considered as a "candidate bug" in a subsequent version of Office. One possible reason for this is that users in multiple windows should be allowed to run the code called by DDE.

Security company EndGame decided to look into DDE within Word and discovered a bug in the implementation. The MSDN documentation about DDE states that the application that calls DDE must already run. However, that does not appear to be the case. Therefore, a malicious Word document via DDE can call cmd.exe and perform additional commands. According to Bill Finlayson of EndGame, Microsoft could resolve this by asking the user to start the app itself instead of doing this automatically.

Additionally, Microsoft can customize the text in the dialogs and make more security-oriented before running the requested application. Finlayson, however, refers to all attacks via macros that show that the end-user eventually clicks each window, regardless of the wording used. "The correct solution is therefore to ask the user to launch the application before they can click through the dialog, and then re-run the request." Finlayson is therefore sorry that Microsoft does not want to solve the problem, as attackers increasingly use this feature.

Attack Via Office DDE Feature Also Works In Microsoft Outlook



The Microsoft Office DDE feature currently used to attack Internet users through Word documents also works in Microsoft Outlook, so researchers have shown. The attack can be performed by sending emails and calendar invitations set up in Rich Text Format (RTF).

The Dynamic Data Exchange (DDE) feature of Microsoft Office makes it possible to inject data from, for example, an Excel document into a Word document. This will add code to one document that points to the data in the other document. Instead of a document, malicious code may also be linked. Attackers now use this feature to infect internet users through Word documents with ransomware and other malware.

The attackers send emails that have attached a Word document. As soon as the recipient opens the document, he will see several dialog boxes asking for permission to run the code that is linked. However, it is not necessary to send Word documents, so researchers have shown . Researcher Kevin Beaumont found a way to use the DDE feature in Microsoft Outlook via e-mail. In this case, users get the same notification as with Word asking for permission to execute code.


In addition to a RTF-generated email, the attack can also be performed via a calendar invitation. According to anti-virus company Sophos , the attack is easy to stop, users need to click on no-click in the first window asking for code execution. If the user clicked yes in the first window, a second dialog will appear for permission. Only when yes is clicked is the code called through DDE executed. Another option that users can apply to protect themselves is to display emails in plain text.

Monday, 9 October 2017

Infected Pornhub Ads Spread Kovter Malware



On the popular porn site Pornhub, infected advertisements appeared to infect visitors with malware. According to market researchers, the porn site is ranked in the top 30 of most visited websites in the world. Pornhub claims itself to get 75 million unique visitors a day.

The infected ads were spread through Traffic Junky's ad network. The ads passed users to a website that believed that there was an important update for the browser or Adobe Flash Player. When users clicked on the page, a JavaScript file was downloaded that installed the final malware. It was about malware that caused the computer advertising fraud. After being informed, both Traffic Junky and Pornhub have removed the ads, according to security company Proofpoint.


"The combination of large scale malvertising campaigns on print-enabled websites with sophisticated social engineering that convinces users to infect themselves means that potential exposure to malware is quite high and millions of Internet users are reached," says the Proofpoint researcher with the alias Caffeine. "Once again, we see that attackers exploit the human factor as they adapt their tools and approaches to a landscape where traditional exploits are less effective." The investigator thus targets the fact that attacking vulnerabilities in browsers and Adobe Flash Player causes ever fewer infections to cyber criminals.


Indicators of Compromise (IOCs):


IOC
IOC Type
Description
www.advertizingms[.com|204.155.152.173
domain|IP
Suspicious Epom server 2017-10-01
*-6949.kxcdn.com
domains
Subdomain from a rogue KeyCDN customer 2017-10-01
phohww11888[.org|192.129.215.155
domain|IP
KovCoreG soceng host  2017-10-01
cipaewallsandfloors[.net|192.129.162.107
domain|IP
KovCoreG soceng host  2017-10-01
b8ad6ce352f502e6c9d2b47db7d2e72eb3c04747cef552b17bb2e5056d6778b9
sha256
            T016d6n7t96x2hc43r5f3u6gs61d.zip (zipped runme.js)  2017-10-01

4ebc6eb334656403853b51ac42fb932a8ee14c96d3db72bca3ab92fe39657db3
sha256
FlashPlayer.hta
 2017-10-01
a9efd709d60e5c3f0b2d51202d7621e35ba983e24aedc9fba54fb7b9aae14f35
sha256
Firefox-patch.js
 2017-10-01

0e4763d4f9687cb88f198af8cfce4bfb7148b5b7ca6dc02061b0baff253eea12
sha256
 Kovter 2017-10-01

f449dbfba228ad4b70c636b8c46e0bff1db9139d0ec92337883f89fbdaff225e
sha256
 Kovter 2017-10-01

Friday, 21 April 2017

Cybercriminals Use NSA Exploits To Attack Servers


Cyber criminals are currently actively using the NSA exploits last week by the hacker group Shadow Brokers were made public to provide servers backdoors and possibly spreading ransomware. Let know several security researchers.

Thus Double Pulsar tool found on the various servers. The NSA would use this tool after it has been through an exploit access to a server. In addition, security reports SenseCy that there is currently a "trend" going where the leaked NSA exploits used to infect Windows Servers with ransomware. The attackers were using either a vulnerability in Windows SMB Server make that Microsoft patched in March.

Further details are not given, however, about this ransomware attacks. Earlier researcher Kevin Beaumont predicted that the NSA exploits a ransomware worm would be used. "It's the next logical step yields for worms and criminals, because the money and is easy to do," says the researcher. Beaumont says that if known exploits are currently being used to servers a backdoor provide.

Tuesday, 19 April 2016

New York Police Launch Campaign Against Encryption



The police force of New York 's Manhattan along with the Attorney General and various organizations for crime victims a campaign against encryption starts. According to the initiators of the campaign "#UnlockJustice 'it is important to highlight the impact of encryption for public safety and crime victims.

"The debate over encryption is often determined by privacy and security, where there is no thought about the impact on victims," ​​said Attorney General Manhattan Cyrus Vance. "That narrow view ignores the impact of encryption for the investigation and prosecution of crimes." According to Vance all consumer must be able to be searched by investigators.

Apple and Google have, however, ensured that this is not currently the case, he said. "Congress should not allow companies to make devices that against his injunctions file. Companies should not be allowed to give criminals a place where they can go about their business. Victims of crime are entitled to greater protection than criminals."

According to Police Commissioner William Bratton undermines the existence of devices for which a court order is not the justice system applies. "This is a crisis in the making and goes beyond a single terror case. Providing shelter for pedophiles, rapists and murderers through their mobile phone affects unprecedented casualties. This exception of the judicial system is unsustainable and must be corrected immediately . "

In addition, hundreds of the initiators point for devices that can not be searched. Through the campaign, they hope to educate the public about this. The created for the campaign hashtag was quickly adopted by proponents of encryption. "People deserve better protection than criminals. Standard strong encryption protects citizens against robbers and thieves," said security expert The Grugq . Other Twitter users claim that it is a campaign of misinformation and encryption just helps in protecting data.

Microsoft Warns Of E-mails With Attachments JavaScript


Microsoft has issued a warning to spam messages that contain a JavaScript file attached and try to infect your computer with malware, including Locky-ransomware. The JavaScript attachments are back wrapped in a rar or zip file, says Alden Pornasdoro Microsoft.

In addition to use JavaScript files cyber criminals also Office documents with malicious macros to spread ransomware. According to Microsoft can be rapidly infected a computer via a JavaScript file. "It is interesting to note that an Office attachment with malicious macros usually two or more clicks required to open the document. One click for the document, and another click to activate the macro. On the other hand, the JavaScript annex just one or two clicks to run, "Pornasdoro notes.

He adds that it is very unusual for people to send JavaScript files attached. Who receives such a file must therefore not open. Pornasdoro also advises organizations to enable AppLocker so dubious software can not be performed. In addition, administrators are advised to disable macros in Office programs.

Finland's F-Secure has advice given how the Windows Script Host can be disabled so that JavaScript files are no longer open.

Friday, 12 February 2016

Ads On Skype Spreading Ransomware



Cyber Criminals have managed to show ads to Skype users who were trying to infect computers with ransomware, says anti-virus firm F-Secure. Although the ads appeared within Skype, does not mean that the browser is not open to advertising.


In the case of observed infected ads which showed the browser unnoticed load a page with the Angler-exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player to infect computers with malware. Users who had not patched their Flash Player could become so infected with the Tesla Crypt-ransomware. Like other ransomware encrypts Tesla Crypt sorts files for ransom. The ads on Skype came from the AppNexus-advertising platform, which in the past often for the spread of infectious advertisements used. Meanwhile, the offending ads are no longer displayed.

Thursday, 11 February 2016

Cyber Attack On US Tax System



One of the US IRS Tax system last month attacked by identity thieves who attempted to retrieve PINs that tax could be committed. The attacks were aimed at a web application that allows taxpayers, after entering their name, social security number, address and date of birth, their Electronic Filing (E-File) PIN to retrieve.

This PIN can then be used to apply for the tax refund. The identity thieves used the information to other parties was stolen to retrieve the PIN. In total, with 464,000 unique social security numbers tried to grab the code, which was successful at 101 000 social security numbers. According to the IRS , there was an automated attack. The Tax Administration claims that no taxpayers' data through IRS systems are won. In addition, the IRS will notify all individuals whose data were stolen by other parties.

British Tax Office Warns Of Return Over The Shared PC



UK Tax HMRC warns taxpayers to tax not do through shared computers such as in an Internet café. These criminals would save login details and then used to apply for fraudulent tax refunds.

HMRC would now have more than 17,000 fraudulent transactions intercepted by criminals 96 million pounds (124 million euros) were trying to reclaim. It is unclear how big the threat of the use of shared computers is exactly. Opposite the Mail Online allows a spokesperson for the British Tax namely also know that the HMRC is one of the most 'phished' brands in the world.

It often happens that criminals send phishing emails that attempt to lure them recipient to a fake version of the HMRC website to steal so then login details and other information. Because phishing attacks, there is a special page put online explaining how to recognize legitimate emails from the tax authorities.

American Bill Should Prohibit Encryption Backdoors


The US House of Representatives will today present a bill that prohibits US tech companies to add encryption backdoors to their products. In recent months warned some American politicians and investigative agencies, including the FBI, the use of encryption by criminals, which would hamper the investigation and prosecution.

The "ENCRYPT-law" of the Democratic delegate Ted Lieu and Republican Rep Black farenthold prohibits states companies may require to add an encryption backdoor to their products so that encrypted communications can be decrypted later.Recently had the US states of New York and California attempted to require encryption backdoors in smartphones.

According to Lieu technologically is unfeasible to handle individual states various encryption standards for consumer products."Apple is no different smartphones for California and New York and make the rest of the country," so let Lieu opposite Reuters know. Last year Lieu spoke even against the wishes of the FBI to weaken encryption.

"Democracy will always need to find a balance between security and freedom. We realize that it is a challenge for investigators to find that balance, we do not agree with the FBI's proposal to oblige companies to the safety of their products and weakening services by adding a "backdoor" which investigators encryption technology to circumvent, " says the deputy.

Monday, 30 November 2015

British Woman For 2.3 Million Euros Ripped Through Dating Scam


In Britain, a woman for 2.3 million euros ripped through a dating scam. The woman met on a dating site a man posing as a wealthy engineer. After the man's wife had built a relationship she was asked during a period of 10 months for various loans. Eventually she made about 1.6 million pounds, converted 2.3 million.

Two of the gang members were sentenced last week. According to the British police in the past year 100 victims of dating fraud analyzed taking internet scammers managed to steal a total of 5.7 million euros. In addition, people walk not only on dating sites risk. Recently, a British woman approached via Skype and eventually ripped off for 360 000 euros.

British police advises Internet users who are talking with potential partners over the internet to pierce pathetic stories, and not by just letting a photo fooled. Also, people can not send money to people abroad that they have not met or barely know. Continue to be drawn to the question of potential online partners in doubt. Many scammers give all sorts of compliments and ask many questions, but tell little about himself.

Sunday, 29 November 2015

NSA Stopped Mass Storage Phone Data


US intelligence NSA has stopped the massive storage of telephone data, so reporting news agency Reuters, CNN and the intercept. In June, President Barack Obama decided to implement various reform measures and to limit the powers of the NSA.

So the Secret Service should not collect unfocused phone records of US citizens. Instead, the NSA will now have to be more focused work, in which first a court order is required, after which telecom operators may be asked to keep phone records of certain people or groups of people for a maximum period of six months.

The measure is a victory for privacy advocates and saw Edward Snowden, who felt that the NSA had this much power to spy on citizens. However, the NSA has asked the court to be allowed to continue using the data stored to date to February 29, 2016 on a limited scale. The judge must still here a judgment on it.

Saturday, 28 November 2015

Criminals Copy Debit Cards Via Stereo Skimming


The past quarter have criminals in a European country copied via stereo skimming debit cards, reports the European ATM Security Team (EAST), an organization that maps fraud with payment terminals. EAST receives data from a large number of countries.

It is the first time that the organization receives notification to stereo-skimming successfully applied. In traditional skimming criminals copy the magnetic stripe of a debit card through a cross mouth placed on the ATM. In order to prevent skimming anti-skimming devices are used that emit a "jamming signal". In stereo skimming there are two headlines that read information from the magnetic strip and store it via audio technology. The first reading head strikes the jamming signal and map data, while the second read head only stores the jamming signal. Due to the one of the other subtracting remain on the map data.

Thanks to MP3 technology, this method would again make a comeback, according to InformationWeek. The technique in the past, has been used once before. In 2013 a simple stereo-skimming device was an Irish ATM discovered. In late September of this year reported security TMD Security that it had found new stereo-skimming technology in Ireland. The device would be based on existing stereo-skimming technology, but use sophisticated new technologies allowing the jamming signal be neutralized.

EAST late in the present report do not know to which country it is where the message came from, but Ireland is one of the countries that provide data to the organization. However, it still seems to be a novelty, since 17 countries reported the traditional skimming of debit cards. Also made ​​one country reported criminals who had downloaded via malware money from an ATM, and also became a 'black box attack reports', where criminals connect a personal device on the ATM and the machine so give commands to money through the issuance channel off to give.

Friday, 27 November 2015

FBI Warns Online Shoppers To Online Fraud


The FBI has the festive arrival of online shoppers for Internet fraud warning, as offers that are too good to be true. According to the police for criminals prepare themselves for the holidays and will try through creative scams to steal both money and private information.

Thus, Internet users are advised to not fall into offers that seem too good to be true. Also should be avoided websites that offer high discounts. Consumers should also pay attention to social media and installing smartphone apps, according to the FBI. Before an app downloaded from an unknown source users must first read reviews. In addition, some apps pose as game and are offered free, but in reality, trying to steal all kinds of personal information.

In addition to the FBI, the Computer Emergency Readiness Team of the US Government (US-CERT) Internet phishing, malware and other scams during the holidays warned. This will include recommended to purchase online to pay by credit card because it provides extra protection. Also, all online transactions should be printed before the arrive purchased products.

EFF Wants Stronger Encryption Against Terrorists And Criminals



If the government were to ask people to remove the good locks on their doors and windows and replacing them worse so that government employees can penetrate more easily in case someone is a terrorist, no one would accept this because bad locks make everyone vulnerable.

Yet this is exactly what governments and law enforcement agencies in the case of encryption will, according to the American civil rights movement EFF. Regularly advocate agencies like the FBI to add backdoors in encryption, ensuring encrypted communication can still be tapped. This is similar to prevent people from getting access to good locks and locksmiths can produce good locks.

In this last example, most people would understand that this is not a wise idea, says Cindy Cohn of the EFF. However, when it comes to Internet and technology, such as the operation of encoding, which for many people is less clear. Parties such as the FBI and politicians would also have known better, says Cohn. "The answer to insecure networks and digital technologies must be correct in order to make them safer."

But that is not what is happening, so she continues. Policymakers are therefore urged to take this into account. "Ensuring that everyone's door is unlocked, is not the answer to crime or terrorism. That is the development and support of better security," Cohn decision.

IT Vendor LANDesk Warns staff After Hack


The American IT vendor LANDesk has staff warned that their data may have been stolen in a burglary on the network, but LANDesk employees to know that the hack goes much further and there may also be source code was stolen. LANDesk develops software for computer management.

The company has issued a warning recently that suspicious activity is detected on the IT systems. In addition, the data may be stolen by employees, the company said. Details will not, however, give the IT provider, but it does know that the environments of customers using the LANDesk software no risk. Across IT journalist Brian Krebs tell several employees that the attackers may have been since June 2014 had access to the systems. This is clear from the logs.

The burglary was discovered only after an employee complained about a slow internet connection. The survey also showed that the attackers passwords IT manager and system had been compromised. Lists also were found with source code and build evers who had compiled the attackers. Through the source code, it could be easier for attackers to find vulnerabilities in the software and allows companies to attack. However, a spokesman would not confirm or deny that the break-source code has been captured.