Showing posts with label Jerome Segura. Show all posts
Showing posts with label Jerome Segura. Show all posts

Friday, 23 October 2015

Infected Ads With T-Online And eBay Germany


On the website of the German ISP T-Online and eBay Germany are infected ads appeared which attempted to infect visitors with malware. Also received several other German sites to do with the infected ads but eBay.de and T-Online.de are respectively 131 million and 79 million monthly visitors by far the biggest websites were affected.

Through the ads were visitors silently redirected to pages with the Angler- and Neutrino-exploit kits. This exploit kits do include using known vulnerabilities in Internet Explorer and Adobe Flash Player. These are known vulnerabilities. Users whose software was up-to-date therefore were not at risk.

What malware was installed on the attack late anti-malware company Malwarebytes not know. The ad network which spread the infected ads would meanwhile have intervened, but analyst Jerome Segura does not rule out that the attack campaign through other ad networks will continue.

Thursday, 22 October 2015

Phone Scammers Pretend To Be Apple Employees



For years, telephone imposters posing as Microsoft employees, but now there are also scammers who claim to work for Apple. It is in this case not to "cold calling", where people's homes are called by the scammers. It is precisely Apple users who call the scammers.

To achieve this, use the scammers malicious ads and pop-ups that let the user believe that his or her device with a "malicious adward attack" is infected, says anti-malware company Malwarebytes. Is then urged to call a phone number.When a user calls the scammer is trying to let him or her install software that allows the computer to be remotely controlled.

Apple offers a so-called "screen-sharing service" that can help a help desk remotely. This requires users to the website ara.apple.com go. An official part of the Apple website. Scammers now use this feature to deceive people. Once Apple users call because of a misleading pop-up or alert them to the website ara-apple.com forwarded.

Through this website you can download software that allows the scammers can take control over the computer. Then they show all sorts of so-called problems. The remedy must be paid for it. Something that happens through an unencrypted connection. According to analyst Jerome Segura run Apple users at greater risk of becoming a victim, because they have less experience with this type of warning pop-ups and 'errors'.

Thursday, 1 October 2015

Google AdWords For Blue Screen Of Death Scam



Criminals have used Google Adwords to lure users to pages that called a Blue Screen of Death show (BSOD). For resolving the problem should then phone calls. Eventually adjust the telephone scammers that they can fix it for an amount between 199 and 599 dollars, let anti-malware company Malwarebytes know.

To get people to the pages used to lure the BSOD be AdWords, the largest online advertising service from Google. When users via the Google search engine for the term "youtube" searching pull them alongside the search results to see two ads above the results. It seems here that the ads point to YouTube, but loaded into reality the BSOD page. After being informed, Google removed the ads. According to analyst Jerome Segura is consciousness but the best protection against these scams.

Tuesday, 15 September 2015

Infected Advertisements On EBay Weeks Remain Unnoticed


Cyber criminals are recent weeks managed to commonly-used ad networks like DoubleClick and AppNexus a large number of infected ads on popular websites such as eBay, Drudge Report and Answers.com get without that were noticed initially.

Which claims anti-malware company Malwarebytes. The attackers pretended to be legitimate advertisers and offered their ads through various real-time auctions to. Several ad networks allow advertisers bidding through auctions on the available ad space. To convincingly come across criminals used the companies that were registered with the US Chamber of Commerce, whose websites were sometimes recorded years ago.

According to analyst Jerome Segura was enough to fool most ad networks. The ads themselves were not provided with malware, but visitors were redirected to a page via an abbreviated URL that contained the Angler-exploitkit. This exploitkit uses vulnerabilities in Flash Player, among others. In the case the attack was successful Bedep the Trojan was installed on computers.

This Trojan can install additional malware on the computers, as malware, ad fraud and ransomware. The ads appeared on the UK eBay site, which receives 139 million monthly visitors and Drudgereport.com, which receives 61 million monthly visitors. All affected websites monthly gain of about 500 million. In total, the infected ads would have turned nearly three weeks undisturbed. Internet users whose software is up to date ran no risk in this attack.

Wednesday, 19 August 2015

Microsoft Phone Scam Now Also Available In French And German


Microsoft scammers are people for years by awkward to call them up and say that there are problems with their computer at home, but lately also Web sites and pop-ups used. Which let users believe that their computers with a "virus" is infected or has some other problem.

Next, there must be a specific telephone number to be called in order to resolve the problem. This is the number of scammers posing as Microsoft employee or specialist. Then they try to make the victims pay for the removal of the "virus" or the purchase of a virus. The amounts can run into the hundreds of dollars. Thus German victims at a recent campaign for an amount of 389 euro per person scammed. The ads and pop-ups are distributed through malicious advertisements and are bundled with "potentially unwanted programs".

Multilingual

Previously, the text of the pop-ups and websites was always in English and addressed the scam only English. Now scammers target other countries. There are versions in German, found French, Spanish and Japanese. The crooks who answer the phone speak the language. According to anti-virus firm Malwarebytes organisations behind the scam have probably turned several call centers in these countries and they are given instructions on how they can light up people by phone.

"Non-English-speaking countries were previously safe, but scammers have now realised that millions of potential victims are within their reach, particularly in Europe. Since the scam mainly makes social engineering use, they had to find a way to bridge the language barrier and there they have now succeeded, "said analyst Jerome Segura.

Saturday, 15 August 2015

Infected Ads Hide Behind SSL



The criminals who first infected ads on the websites of Yahoo demonstrated have now found a new ad network and use SSL to complicate the detection of malicious traffic. That leaves anti-virus company Malwarebytes know. The ad network in question is AdSpirit.de whose ads drudgereport.com and wunderground.com shown.

These websites get together more than 110 million visitors per month. The infected ads contain a redirect via SSL to an Azure-site, making it difficult to detect the malicious traffic at the network layer, reports analyst Jerome Segura. The ads users a website with the Angler-exploitkit charge. This exploitkit uses known vulnerabilities include Adobe Flash Player that users are not patched. What malware is installed on a successful attack Segura do not know.

Monday, 13 July 2015

Ads Malware Via Flash Player Flaw


Vulnerability in Adobe Flash Player last Wednesday by Adobe was patched is now attacked by infected ads. It is the first flaw in Flash Player that were found in the stolen data of the Italian Hacking Team.

According to anti-virus firm Malwarebytes there since the discovery of this vulnerability an increase in attacks on Internet users through so-called drive-by downloads. In this case, Internet users become infected through unpatched software, which only visiting a malicious or hacked website or see getting an infected ad is sufficient. One reason for the increase in the number of attacks is that many users their Flash Player version have not yet patched, said analyst Jerome Segura.

Ads

Meanwhile, the leak will also be attacked by infected ads. The way this is done is remarkable, says Segura. This primarily concerns a Flash ad that loads another Flash file containing the exploit for the Flash Player leak. The use of contaminated advertentes is much more common, but in most cases advertisements pointing to another website that the user attempts to attack.

The infected ad came from the DirectRev ad network and offered directly from the ad network server. In case the attack is successful, the Kovter malware is installed. Kovter can use computers to commit fraud ad (click fraud) or install ransomware.The malware was recently still in the news because the vulnerable versions of Flash Player on infected computers patches, to keep other malware on the computer outdoors.

Sunday, 22 March 2015

Just Patched Flash Player Flaw In sight Cybercriminals



A critical vulnerability in Flash Player that last week was patched used to attack Windows users. Through the vulnerability an attacker can place malware on your computer, for example if the user visits a malicious or hacked website or see a banner gets infected.

Report that security company FireEye and anti-virus company Malwarebytes . The exploits of the leak abuse is added to the Nuclear Exploitkit. This makes it easy for cybercriminals to attack unpatched Flash Users via the vulnerability. In the case, the attack is successful, a Trojan horse is installed there.

Although the update is available for a week does not mean that everyone who has installed, says analyst Jerome Segura."We know that in some cases, consumers, but usually companies, can not immediately install patches. In many cases, there must first be internally tested so that the patch does not disturb any business processes." The analyst advises organizations in this case to shield these systems from other systems on the network.

Wednesday, 18 February 2015

Vulnerability: "Website Chef Jamie Oliver Spreading Malware"


Attackers have managed to hack the website of the British chef Jamie Oliver and provide malicious code that attempts to infect visitors with malware. Researchers at anti-virus company Malwarebytes found on the website that visitors JavaScript invisible sends to a exploitkit on another hacked website. This makes exploitkit abuse leaks in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. "Unlike most web exploits that we have seen recently, this is not the result of contaminated ads, but a well-hidden injection at the site itself,"says analyst Jerome Segura. He notes that the problem lies in the compromised JavaScript on the website.

It may be possible to go a legitimate script adapted or an entirely malicious script. The webmaster will also receive the advice to look for other signs of infection, then just remove the script in question or modify. "Usually the stolen credentials or a vulnerable plug-in allowing an attacker gets access to a server," said Segura. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Hash:
f93f39f39dc5162f9e310648022d6f40