Showing posts with label Cyber War. Show all posts
Showing posts with label Cyber War. Show all posts

Saturday, 10 October 2015

From Critical Vulnerabilities In Adobe Reader And Acrobat Seal


Adobe will coming Tuesday, October 13th security updates for critical vulnerabilities in Adobe Reader and Acrobat release, but users will get this time not advised to install the updates within 72 hours. This is clear from the notice which Adobe has released.

Security updates have in fact been given a "priority 2". This means that the corrected vulnerabilities, which have been labeled as critical, not be attacked active and there are no attacks are expected shortly. In this case, Adobe advises users and administrators to quickly install the security updates, with 30 days as exemplified. In the case of updates with "priority one" install the updates is presented within 72 hours.

Through Critical vulnerabilities could allow an attacker at worst malicious code on the system without users having this through. Opening a malicious PDF document is sufficient in this case. Were vulnerabilities in Adobe Reader often used in the past to infect computers with malware, the last time this according to statistics from Trend Micro and Microsoft (pdf) is still hardly the case.

Tuesday, 22 September 2015

US Builds Aircraft That Can Hack Wifi Networks


The US Air Force has a plane converted to the wireless networks of the enemy from the air can attack and can block enemy communications. During some tests would be the US Air Force have managed to manipulate a network attacked from the air.

That left Major General Wilson Burke during a recent conference know, reports Breaking Defense. As for the plane WiFi attacks, a Lockheed EC-130H Compass Call used. According to Wilson, the converted EC-130 networks can attack which in most cases can not be accessed via traditional ways, but further details are not given. Many military networks deliberately would not be connected to the Internet in order to prevent attacks.

Wilson emphasises that the use of the aircraft does not mean that the US will no longer try to attack through traditional networking opportunities. "But to use other domains, such as from the air, I think is really the future," said Major-General. It will also be possible to have a target in different ways and to attack at the same time from different domains.

Wednesday, 20 May 2015

Digital Attacks On Oil Traders Without Malware


Researchers from the Spanish anti-virus company Panda Security discovered a digital attack on oil traders with no malware was used and the traders also were not the ultimate target. The attack starts with an executable file that looks like a PDF document.

In reality, it is a self-extracting archive file with several files, including various scripts, batch files and .exe files. Yet these files themselves are not malicious. "These are all legitimate applications that anyone can use," the researchers said that the threat of "The Phantom Menace" ( pdf call). The applications are created to store user names and passwords in the e-mailcient and browser in a text file and send it via FTP.

On the FTP server of the attackers, the researchers discovered more than 80,000 text files. It turned out to be files from ten companies in the oil sector. However, these companies were not the ultimate target. These are namely oil buyers. And especially oil buyers seeking special oil from the Nigerian city of Bonny. This oil is very popular because of its composition.In Nigeria holds the Nigerian National Petroleum Corporation (NNPC) on each transaction oil supervision.

Anyone who wants to sell in Nigeria oil must also be registered with the NNPC. Fraudsters operating in this market approaching traders and brokers and, for example offer a large amount of oil from Bonny at a very attractive rate. The potential buyer requests for documents that the product also exists. For this, several documents can be issued by the NNPC.

To use to inform the buyers on the scammers legitimate documents they captured at the previously attacked oil traders. Then the buyer will see this document and pay a deposit, for example, 50,000 to 100,000 dollars, but gets its oil never see.Eventually Panda Security was able to trace the possible culprit behind the attacks. The problem is that none of the attacked oil traders will report it, for fear of damage to reputation and the fact that they themselves have become a victim. This allows the police can not start investigation and the alleged perpetrator is still at large.

Malware Knew Hard Drive As Copy Protection


In early May there was some fuss about a new malware specimen called Rombertik that analysis, the Master Boot Record (MBR) erased from the hard disk and partition with null bytes' wrote about so that all available data was lost. Initially it was thought that it was a measure to thwart security researchers, but according to Symantec, it is a copy.

Rombertik is a new variant of the Carbon FormGrabber, also known as Carbon Grabber. It is a malware kit that is offered on the black market and is intended for cyber criminals who are unable to write their own malware. To combat illegal use of the malware creators have added a copy protection, so that their creation has not been without a valid license to use. Each version of Rombertik's made for a specific user and licensed. The malware connects to a predefined Command & Control server.

An illegal user could change the address of the server, so the malware makes to another address and link it sends the stolen data to. To prevent this, after the change of address copy protection are active. In addition, the malware also shows a message to the software pirate that the squat attempt failed. Symantec concludes therefore that it is not a measure to thwart investigators, but to punish freeloaders who think they can use the malware free.

Monday, 18 May 2015

American College Gets Offline Network After Attack


An American university network was taken offline after it had advanced malware discovered that for years was active. On November 21 last year, the Penn State College of Engineering was warned by the FBI for an attack. There was a study conducted in silence, the attackers did not let them know they were discovered so, said in a university statement .

Also had a "deviant action" by an individual user can provide unwanted operations to aggravate the situation. During the investigation, it was discovered that two sophisticated attackers had gained access to the network. One of the attackers since September 2012 would have had access to the network. Because of the size it is now decided to disconnect the network from the Internet and check all systems.

Further measures will be taken to prevent future attacks. There will be tighter security rules for workers and students are implemented. In addition, the IT policy will be adjusted properly. In the attack, no personal information would be captured.However, the attackers were able to compromise multiple accounts and passwords. From all accounts, the password will be reset. According to the university, the operation will take several days.

Sunday, 17 May 2015

Victims Ransomware In Conversation With Extortionists


Globally, still a large number of people and organizations affected by ransomware, the infection can sometimes have serious consequences for their lives and business, says FireEye. The US security was given access to the conversations between the victims and the makers of the Tesla Crypt-ransomware.

Within three months, the creators managed to extort about 67,000 euros from 163 victims, which amounts to about 410 euros per victim. There was also a victim who paid 875 euros. It turned out 13% of the victims to make the requested amount.Tesla Crypt offers an online chat functionality, the victim may ask the makers about paying via bitcoin. Therefore also the effect of ransomware on the lives of the victims clearly.


The victims were scattered around the world, students in Iran and Spain to people in the United States, Germany, Argentina, Croatia and Mongolia. Some were afraid that they would be expelled from school or dismissal by their employer if they would follow the files were not returned. Fathers and mothers were torn apart by the loss of their family photos.

Several organizations were targeted, including an organization that conducts research into blood cancers. According FireEye many of the victims are not able to pay the amount requested and then gave up. Below is a portion of the chat conversations where the security given access.

Friday, 8 May 2015

Australia Warns Of CVs Ransomware

The Australian government has warned companies to resumes that are currently scattered through e-mail and try to infect computers with ransomware. The e-mail suggests someone and says that he has attached his job. It is a zip file that contains a JavaScript file again. Once this .js file is opened, the computer becomes CryptoWall-ransomware infected.

It is the same attack in the April 21 news came. The Stay Smart Online campaign by the Australian government suggests that the attack focuses on Australian companies and a new campaign is active since last week. CryptoWall encrypts files on the computer and then asks for a ransom here. The Australian government warns that many victims recover their files if they pay the ransom, but there is no guarantee, since users have to deal with criminals. "Prevention is therefore the best medicine for ransomware and other malware attacks," the campaign.

Saturday, 25 April 2015

ESET: Ransomware Victims Should Not Pay



Computer users who are victims of ransomware and therefore no longer have access to their data should the ransom demand the criminals do not pay. This enables Raphael Labaca Castro of Slovak anti-virus company ESET. In recent months, several experts spoke out about paying ransomware and it was revealed that dozens of Dutch companies had the ransom paid after they were infected.

British anti-virus firm Sophos found that prevention is better than cure, but in the case of an infection the best " okay "is to pay the ransom. Labaca Castro has a different opinion. "If you pay your support cyber criminals by providing them with more money." In addition, according to the security expert would be no guarantee that the encrypted files are decrypted.Nevertheless, recent incidents where the ransom be paid to victims recovering their files.

Yet calls Labaca Castro paid a dangerous option. "Remember, this is not a service. The cyber criminals. Even if you pay, they do not on a" whitelist "position, so you can be infected again. So it is not a real solution for the future." Prevention according to the expert is the main weapon against ransomware. He also advises to make regular backups.

Wednesday, 22 April 2015

NATO Organizes Major Cyber Exercise In Estonia


400 computer experts will this week in Estonia to participate in a major NATO cyber exercise, where an attack is simulated on a fictional country. A total of sixteen teams from countries for Locked Shields 2015 registered as the exercise is called.

Locked Shields is an annual simulation held since 2010 in the cyber defense center of NATO in Tallinn. The organizers announced that this year, in addition to SCADA systems including Windows 8, a test version of Windows 10, Android devices and IP cameras are part of the exercise, as well as an "element of active defense".

"Locked Shields prepares computer emergency response specialists for continuously evolving cyber security landscape. Unique about this is that we are realistic technologies, use networks and methods of attack," said Colonel Artur Suzik, director of the NATO Cooperative Cyber ​​Defense Center of Excellence. "In order to ensure that the exercise is flush with real developments will be there every year new technologies and added attack vectors."

Monday, 20 April 2015

Steam Launches Limited User Accounts From Abuse


The popular game distribution platform Steam has announced a new measure against abuse such as phishing and spam attacks on users, namely the obligation for Limited User Accounts to spend at least $ 5 before they can use certain features. These include the posting, use the chat function and participation in the Steam Fair.

According to Valve, developer of Steam, the measure must protect users from spam and phishing. Steam has 125 million users worldwide. Through the platform, users can buy all sorts of games and digital objects. Some research argue that sold 75% of all PC games through Steam. Steam Accounts with many games or digital goods are also a favorite target of cyber criminals, who often approach users through chat or other parts of the platform.

"Malicious users often use accounts that have spent no money, which reduces the risk of the actions they perform," said Valve. Viewing the purchase history would be one of the main ways to distinguish normal users of malicious users. Malicious users would in fact do not care about the life of their account.

That's why we decided to introduce the limit of $ 5 before accounts can use all the features. Steam Users are happy that something against the scams on the platform is being done, but there are also critical voices of people who only buy physical ex. PC games and spend nothing on Steam, as evidenced by the lively discussion on Reddit .

Saturday, 18 April 2015

WikiLeaks Puts Stolen Sony Documents Online


Whistleblower site WikiLeaks has created an online archive of documents and e-mails late last year at Sony Pictures Entertainment (SPE) were stolen. It involves more than 30,000 documents and more than 173,000 e-mails to and from more than 2,200 Sony email addresses.

According to WikiLeaks offers online archive a special glimpse into the workings of a large "mystery" multinational. "The work in which Sony is known for creating entertainment, but the Sony Archives show that behind the scenes this is an influential company with ties to the White House and has the ability to influence laws and policies," said the whistleblower site. WikiLeaks also suggests that Sony has ties to the US military-industrial complex.

Julian Assange, editor of WikiLeaks, says that the stolen documents and emails are newsworthy and belong in the public domain. "And WikiLeaks will ensure they stay there." So Sony appears to be a strong lobbyist on issues such as Internet policy, piracy, trade and copyright issues. According to WikiLeaks show the emails show that there is continuously lobbied not only with the Motion Picture Association of America (MPAA), but also directly with politicians.

Thursday, 16 April 2015

Police Infected Computers Ransomware


A police chief has admitted in the American Houlton that he was the cause that various police computers ransomware became infected and the police eventually had to pay the ransom of $ 588. Police Chief Joe McKenna leaves opposite Bangor Daily News that the infection was his fault because he opened an infected email attachment.

"The last time I get quotes for different kinds of stuff we will replace," said McKenna. "Between all those emails was an email from a woman that says that the offer had been added. I did not think about it and opened it." The appendix was found to be a blank document, which the police thought that the sender had made a mistake and put his computer.

The appendix was found to be ransomware. When McKenna his computer turned on the ransomware hit, and all kinds of encrypted files on multiple computers. "It locked all computers. All emails to photos, documents and reports," said the police chief. Eventually, the police decided to pay the ransom of $ 588, although the total damage inflicted the ransomware is estimated at $ 1,400.

Wednesday, 15 April 2015

Advisory Warns Of Danger Of Wifi In Aircraft



An advisory from the US government has warned in a new report about the danger of wifi in aircraft that it would be theoretically possible for an attacker to gain unauthorized access to the avionics. The researchers from the US Government Accountability Office (GOA) argue that modern aircraft are increasingly connected to the Internet, what risks entails.

Aircraft Information Systems consist of the avionics for the control and entertainment systems for passengers. Traditionally, the systems for flying and control isolated from the entertainment system. The researchers spoke with the US aviation authority FAA and experts, who reported that IP networks, an attacker can still have access to these systems.

There are some firewalls to protect the avionics against attacks from the entertainment, but four experts suggest that firewalls hacked and can be circumvented. If the entertainment instance the same router as the avionics parts and use the same network platform, a user can bypass the firewall or attacks and gain access to the avionics.

An official of the FAA says that additional security checks can strengthen the system. According to the researchers, however, needs to be taken at different points of action. They advocate the development of a cyber threat model, it must be ensured that the Office of Safety (AVS) of the FAA, which deals with the certification of Internet systems in aircraft, part of a recently established cyber Committee is and must guidelines of the NIST be implemented.

RTF Most Popular File Type In Targeted Attacks


Attackers who use through targeted attacks on organizations trying to break into the most RTF documents, claims the Japanese anti-virus company Trend Micro . E-mail attachments that were used in targeted attacks last year was 24% of the cases to an RTF document.

Also DOC documents with 22% a popular file type. According to Trend Micro to explain the popularity of both file types because many organizations working with Microsoft Word. PDF documents are contrary despite the dominance of Adobe Reader hardly used in targeted attacks. Only 2% of the attacks took place via a PDF attachment.

Although last year zero-day attacks took place where attackers used a vulnerability in PowerPoint for which no update was available, it appears that simply avoid most targeted attacks. In many cases use is being made from vulnerabilities that are years old. A known vulnerability CVE-2012-0158. This is a flaw in Word that three years ago was patched. In 10% of the targeted attacks an exploit for this vulnerability was used.

Criminals Steal Nearly $ 1 Million Through Android Malware


In Russia, five people arrested who used Android malware to steal nearly $ 1 million from Russian and Ukrainian banks. The malware was spread via SMS and posing as Adobe Flash Player. Once installed on smartphones and tablets could steal the criminals in different ways money. Initially the money was through SMS banking captured.


This is a way to make money with some specific text messages are sent to the bank. Later, the malware was modified and used to steal credit card information. Once users Google Play on their device had opened there by the malware loaded a separate window that asked for credit card details. The completed information was sent to the criminals.

Finally, the criminals used phishing sites for various Russian and Ukrainian banks. Once users on the infected machine had started their mobile banking app malware replaced the original window for a phishing site. Again completed data were sent to the criminals. Who were with the login information and access to perform the SMS kinds of transactions on the device, so says the Russian Group IB.

Monday, 13 April 2015

Southeast Asia: State Cyber Spies Operate Ten Years Undetected


For a decade, spying a group of hackers governments and companies in Southeast Asia and India. According to one report, China is said to have instructed the snooping.

In 2005, the group of hackers APT would have 30 started successfully spy on government and economic institutions in Southeast Asia and India. These have targeted political, economic and military information the attacker. In the course of journalists came into the focus of hackers. That's according to a report of IT security firm FireEye , which shines through the operation of APT 30. Responsible for Cyber ​​espionage is China, the researchers suggest.

The security researchers from FireEye have analyzed over 200 spy tools and software for planning the attacks, monitoring of targets and execution of the attacks. The tools were tailored according FireEye with clearly defined objectives. A derivative of espionage tools have successfully hidden on infected computers before anti-virus programs.

Attacked first computer behind an Air Gap

In the wake of the attacks it was the hacker group also managed to penetrate into independent, non-affiliated security reasons with the Internet company networks, as a descendant of espionage tools has spread through removable media. The infiltration of computers behind an Air Gap succeeded APT 30 FireEye According back in 2006 - the first such attacks were documented in 2008.

In order to sneak on target computers, put the hacker group on phishing e-mails with supposedly important documents in the appendix. Opened an employee a file, an espionage tool that searched the computer for relevant information and related documents sent secretly to the attackers installed.

The assumption on the part of FireEye that China is behind the espionage activities, based on the evaluation of the goals. Among other journalists were monitored, reported on the Chinese dissident movement. In addition, the graphical user interface of attack planning software was written in Chinese and also the spy tools reported Chinese terms on.

Tuesday, 31 March 2015

GitHub Know Repel Chinese DDoS Attack After 113 hours



The popular online platform for developers GitHub has a DDoS attack that began on March 26 after 113 hours to successfully beat off, as the website shows through Twitter know. When the DDoS attack combining attack vectors used. It was well known attack techniques and new technologies used by the browsers of unsuspecting people who had nothing to do with the attack, large amounts of data direction github.com send.

"Based on reports we have received, we think that the aim of this attack is to remove certain content," said Jesse Newland from github in a blog posting . According to the company Insight Labs Internet in China was manipulated to harass GitHub website with traffic. Files of the Chinese search engine Baidu were thereby replaced with JavaScript against the GitHub pages of the Chinese New York Times and Great Fire was directed. Great Fire is an organization that monitors censorship in China.The added code caused the browsers of Chinese Internet users every two seconds clippings from the GitHub pages.

Even researchers Netresec say that the "Great Firewall of China" was used to perform a powerful DDoS attack on GitHub."Therefore the Great Firewall can not only be seen as a technology to censor the Internet of Chinese citizens, but also as a platform for conducting DDoS attacks against targets worldwide, with the help of innocent civilians deployed visit Chinese websites." The current measures taken by GitHub would however maintain.

Monday, 30 March 2015

Tens Of Thousands Of Frequent Flyer Accounts Hacked British Airways


Attackers have managed to gain access to thousands of frequent flyer accounts of British Airways and steal all kinds of bonus because users had used their password for the service also for one or more other websites, according to the British airline.

In an email to customers affected British Airways announces that the "unauthorized activities" has discovered regarding the "Executive Club account" of the user. It is an automated attack that happened to other places stolen credentials was tried to login. The Guardian reports that for tens of thousands of users are affected. To protect users, it was decided to close all accounts and change the password. Before users can log in again they must first create a new password.

On Reddit and Twitter are all kinds of angry messages from customers who reported that their Avois points are all stolen, formerly known as Air miles. It is a reward program where consumers when shopping sorts can earn bonus points which can then be used for travel. According to British Airways, there would be no personal information captured and is working to resolve the situation.

Wednesday, 25 March 2015

Danish Chiropractors Target Of Ransomware Attack


Danish chiropractors are the target of a highly targeted ransomware attack that attempts to encrypt all kinds of files for ransom. The attack begins with a perfect Danish drawn email, reports the Danish security firm CSIS . The IT security does not exclude that the message was written by a Dane. The email tries through social engineering open the receiver to let the included Dropbox link.

This link points to the kinds of ransomware that encrypts files on the computer. After encrypting a message appears on the screen that the files are encrypted and the user has 24 hours time to get his files, he or she will lose otherwise permanently.The malware also prevents the use of various Windows programs, such as Task Manager, Regedit and MSconfig. The ransomware has a keylogger to save keystrokes.

"We have decided to classify the attack as a major risk, even though that focuses on a specific group. This is mainly because of the level of social engineering that precedes the attack and the destructive code is attempted on the computer to install, "says Peter Kruse of CSIS. He notes that this type of attack is likely to be successful in many Danish organizations and therefore a threat to both companies and the authorities.

Malware Can Steal Data From Offline Computer Via Heat


Israeli researchers can steal developed a method by which malware through heat data from computers that are not connected to the Internet. BitWhisper , as the researchers from Ben Gurion University call their attack, uses the built-in thermal sensors of computers and the heat power , processor, video card and other dispensing components.

To carry out the attack, the computer that is not connected to the Internet become newly infected with malware. This could for instance via a USB stick. In addition, should read this computer next to a computer that is connected to the Internet and also been infected. The malware on the offline computer can then communicate through the heat sensor with the heat sensor of the online computer, somewhat similar to Morse code.


By allowing the temperature of the system increases and lowering the malware can forward information to the receiving system. In their model, the researchers got the first heat rise by one degree, to which in turn let to normal temperature bags.To find infected computers around the malware can periodically "ping heat" issue, for example, to determine whether a government employee has placed an infected laptop near.

The two systems can subsequently infected via the "heat-ping", which the temperature is increased by one degree, to exchange a handshake and thus set up a connection. At this time can be exchanged using this attack method only 8 bits of data per hour, reports Wired . Thus, an attacker could send a password or a secret key, but no large amounts of data.

In addition, the attack only works when the systems up to 40 centimeters far apart. According to the researchers, there are many organizations where there are multiple computers on one desk next to each other. One that is connected to the Internet, and one that is connected to an internal network. Soon the researchers will publish a report on their research. On YouTube is now a demonstration video in which one infected computer via heat signals can operate the USB rocket launcher from another infected computer.