Showing posts with label E-Mail Traffic. Show all posts
Showing posts with label E-Mail Traffic. Show all posts

Thursday, 9 July 2015

Criminals Hacked Apple And Microsoft Still Active



A group of cyber criminals in 2013 Microsoft , Apple , Facebook and Twitter hacked is still active and has provided the large companies, which both malware for Windows and Mac OS X is used. Before the attack on the US Internet companies at the time the attackers used a zero-day vulnerability in Java. At the time of the attack there was no update available for the leak.

After all the attention to the burglaries, the attackers vanished in 2013 for almost a year, but now they are back and they use a previously unknown vulnerability in Adobe Flash Player and use a certificate from the Taiwanese manufacturer Acer to sign with malware. That report anti-virus firms Symantec and Kaspersky Lab today. Both virus fighters have put a group of the analysis.

This is according to anti-virus companies to a group of cyber criminals who operates on a much higher level than other cyber criminals. So is wanted there for credit card information, but to very valuable information. The attacks were the past few years aimed at law firms, Bitcoin-related companies, investment companies, IT companies, health companies and brokers, as well as individual users. Most victims are located in Canada, Europe and the United States.

Attacks

To infect victims they have used the aforementioned zero-day vulnerability in Java and at least one vulnerability in Internet Explorer 10, says Symantec. Kaspersky Lab reports that the attackers have used an unknown vulnerability in Flash Player.The victims are attacked by the leak is unknown. At the first attacks in 2012 and 2013 were hacked websites which targets already visited by itself. How the attackers in the new series of attacks proceed in 2014 and 2015, however, a mystery. In case the attack is successful, the attackers use various tools, including a backdoor for Mac OS X and Windows.

The attackers have mostly provided on mail servers. Once access to the Microsoft Exchange or Lotus Domino servers obtained the e-mail traffic probably bugged, says Symantec. There may also be "fraudulent e-mails" are injected.Furthermore, Kaspersky Lab discovered the malware that was used this year by the group signed with a legitimate certificate from Acer. The certificate has been obtained is unknown. The certificate authority that issued the certificate has been asked to withdraw the certificate.

"Compared with other intelligence groups, this group is one of the most exciting we have analyzed and monitored," Kaspersky Lab says. The virus fighter warns that the criminals are still active. Symantec also warns companies of the group, which not only has excellent operational security, but also succeeded in expanding the activities and not be noticed. "The group is a threat that companies should take seriously," said the virus fighter. The data that the group steals the possible uses for their own financial gain, or by selling to the highest bidder.

Finnish Teenager Convicted Of Computer Crimes


A 17-year-old Finnish teenager was sentenced in Finland to a suspended sentence of two years for a large number of computer crimes. The boy needs help "combating cyber crime," notes the website Daily Dot according to reports in the Finnish media .

The Finn was convicted based on 50,700 counts of computer crime. It was to include data breaches, credit card fraud, money laundering, fraud and violating commercial secrets and other matters. He placed with stolen credit cards at various retailers orders. In one case, he happened to wine from Ireland. The Finland Times reports that the teenager also the e-mail traffic of 15,000 users of the Massachusetts Institute of Technology (MIT) intercepted and network traffic of the university sent to another server.

The teenager was also part of the Lizard Squad have been. The group was last year responsible for DDoS attacks on the networks of Xbox Live and the PlayStation Network. The Finnish teenager was also interviewed by the British television channel Sky News for the DDoS attacks. Were the attacks on the networks of Microsoft and Sony hacked thousands of home routers are used.

Monday, 22 June 2015

Anti-Virus Companies Were Targeted GCHQ And NSA


Several anti-virus companies in the past have been the target of US and British intelligence, focusing in particular went to the Russian virus fighter Kaspersky Lab, according to documents from whistleblower Edward Snowden in 2008.

The US NSA and the British GCHQ looked for ways to circumvent virus and other security software. The e-mail traffic was monitored in order to bring users of anti-virus software identified. The documents also show that British intelligence software Kaspersky wanted to reverse engineer and that the NSA was looking for vulnerabilities. US intelligence also shows traffic between the servers and Kaspersky users have viewed the software.

In 2008 discovered a research team from the NSA that the Kaspersky software users sensitive information sent back to the company's servers. This information could easily be captured to track users, says a report. The NSA would have intercepted e-mails, which were intended for security companies and which were warned of new viruses and vulnerabilities, reports the intercept today using different Snowden documents.

According to researcher Joxean Koret anti-virus software is an attractive target for attackers. The software often takes the highest rates in the system. An attack on a virus an attacker could cause these rights. Moreover, the security of many anti-virus software to be desired and even years on other client applications such as browsers and document readers behind, Koret said. "It means that Acrobat Reader, Microsoft Word or Google Chrome are much more difficult to attack than 90% of the virus." It was recently announced that Kaspersky Lab was the victim of a sophisticated attack carried out by a state, according to the virus fighter.

Tuesday, 21 April 2015

JavaScript Annex Spreads CryptoWall-Ransomware


In many email attacks are used executables and Office documents, but there are spammers that use JavaScript attachments. Before warns Trustwave. The security company recently discovered a spam campaign where emails were sent that contain supposedly a resume laity.

There was a zip file as an attachment sent with it a Javascript file, ending .js. Once the recipient opened the file the script tried to download an executable, which turned out to be a variant of the CryptoWall-ransomware. This ransomware encrypts all kinds of files on the computer and then asks hundreds of dollars for decrypting it.

On another spam campaign Trustwave discovered a phishing attack that also made ​​use of JavaScript. In this case, an HTML file was sent to JavaScript which recipients must enter their account details. "If an e-mail telling you to enable JavaScript that you should not really do," says analyst Brian Bebeau. "Despite the use of executable files and other exploits you can not ignore JavaScript attachments in your e-mail traffic. They can both your users and yourself cause problems."