Showing posts with label Kaspersky Lab. Show all posts
Showing posts with label Kaspersky Lab. Show all posts

Wednesday, 5 July 2017

Test: Ten Tested Virus Scanners For MacOS



German test lab AV-Test has a new test virus put online, this time for anti-virus software for MacOS looked. The amount of new malware for MacOS is not commensurate with those for Windows. However, last year there was an increase in visible , of 819 new units in 2015 to 3033 in 2016.

Most infections MacOS is still doing for social engineering, in which users are tricked into installing malware, although some cases are known where attackers managed to add malware to legitimate programs. That there is little malware for MacOS in circulation is evident from the number of copies that malware-AV-Test used for the test. The lab works on Windows with tens of thousands of malware specimens. 184 specimens were used for the test with Mac malware.

Four products (Bitdefender, Intego, Symantec and Kaspersky Lab) were able to detect all malware instances. MacKeeper ends with a score of 85.9 percent down. Besides the detection was also the tax system looked when copying files. Then put Canimaan Software and MacKeeper down the best performance, followed by Kaspersky Lab and Symantec with one second difference. Intego slows the most systems. Finally, we looked at the false positives. In this case considers a virus if infected legitimate, clean files. During this test item was no virus in error.

Attackers Behind Petya-Ransomware Emptying Bitcoin Wallet


The attackers behind Petya-ransomware have 9,000 euros paid by victims transferred to another bitcoin wallet. That leaves Aleks Gostev on Twitter know, chief security expert at anti-virus firm Kaspersky Lab. The ransomware which last Tuesday infected several organizations showed users see a screen where they were instructed to make about $ 300 to the specified bitcoin wallet.

Unlike many other ransomware became for all victims the same bitcoin wallet used. Last night decided the attackers 9,000 victims who had paid to worry about another wallet. In addition, there appeared on Pastebin message that bitcoin 100 (225 000 euro) were asked for the decryption key to decrypt all infected systems by Petya.

However, it is unclear whether the persons who placed the Pastebin message also behind the Petya-ransomware. According to researcher Matt Suiche attackers try to confuse the public by the story Petya actually a wiper which data could again turn into a story about ransomware, let him opposite Vice Magazine know.

Monday, 2 November 2015

Flash Player And Internet Explorer Favorite Cyber Criminal



Internet users who do not update their software run mainly risk of becoming infected with malware if they use Adobe Flash Player and Microsoft Internet Explorer, according to figures from the Russian anti-virus firm Kaspersky Lab. This involves infections via so-called "drive-by downloads."

These cyber criminals use of exploit kits, which automatically infect Internet through unpatched vulnerabilities with malware.Most kits include attacks to exploit vulnerabilities in IE, Flash Player and Silverlight. It is in all of these cases vulnerabilities this year by Adobe and Microsoft were patched. We look at the attacked software, it is mainly Flash Player and Internet Explorer. Attacks on Java even took off. In recent exploit kits there are no exploits for Java included.

Kaspersky Lab also looked at attacks from "web resources" and where those resources are located. 

Tuesday, 13 October 2015

Kaspersky: .NET Weaponry Cyber Criminal



Microsoft has with the launch of the .NET framework in 2002 cyber criminals unwittingly provide an unimaginable arsenal, say two experts of the Russian anti-virus firm Kaspersky Lab. According to Santiago Pontiroli and Roberto Martinez has Microsoft .NET software development changed radically, but not just for well-intentioned programmers.

Script kiddies could suddenly clicks their own malware together and experienced malware authors now had access to various forums explaining writing new malicious code. All of them with the purpose of detection by anti-virus software to avoid as long as possible. The .NET frameworks not only offered an extensive library of built-in functions, but also a development environment that supported all kinds of programming languages, including C # and Visual Basic .NET.

The .NET framework has become the de facto standard for software development on Windows, according Pontiroli and Martinez. In addition was added in 2006 to the powerful PowerShell scripting framework. Through the interaction between the programming languages ​​that .NET supports and scripting capabilities of PowerShell provides the system administrators and programmers an easy way to not only Windows, but to interact with almost all Microsoft software.

According to the two experts provide the ready-to-use functionality make the .NET and PowerShell is a deadly combination in the hands of cyber criminals. Something that is also reflected in the amount of .NET malware that has risen sharply in recent years. According to Kaspersky Lab goes between 2009 and 2015 for an increase of 7000%, and tens of millions of copies. If, in the type of malware looks than it appears to be mainly toolbars and Trojans.

Future

Although the malware is now focusing only on Windows this may change in the future. The expert does not exclude that in the short term there is a "cross-platform" infection will show, for example through alternative frameworks such as the Mono Project, an open source implementation of .NET and include several Android users can be attacked.

Monday, 12 October 2015

Kaspersky Close Leak That Windows Update Attacker Left Block



The Russian anti-virus firm Kaspersky Lab has closed a vulnerability in Kaspersky Internet Security poem through which attackers could simply block users' access to Windows Update, the Kaspersky website and other websites, as well as the servers of e-mail provider.

The vulnerability was discovered by Google researcher Tavis Ormandy, who earlier other serious problems in the security of Kaspersky Lab laid bare. Earlier Ormandy also found all vulnerabilities in the software from Sophos, ESET and Avast.The problem with the Internet Security package has been caused by a component called the "Network Attack Blocker".This component aims to protect the computer from malicious network activity. Ormandy discovered that it is actually nothing more than a simple stateless packet filter 'that in the event of an attack on the IP address put on a blacklist.

This design made ​​abuse possible, according to Ormandy. For example, the component was found to recognize a forged TCP packets. Also, the filter did not appear to understand the status of the application layer if there is a packet was received. An attacker could create simple abuse of this by sending the signature of an attack to a Kaspersky user, the IP address was falsified. According to Ormandy, the attacker could, for example windowsupdate.microsoft.com can specify as the sender. The Network Attack Blocker could then access to Windows Update are blocked, preventing users from Windows updates would receive more.

The second problem is a possible such scenario, then only via e-mail. In this case, the security component would have blocked user access to its server. Ormandy warned Kaspersky Lab on September 11, after the update was released last Thursday. Then the Google researcher has decided to details of the vulnerabilities disclose.

Saturday, 3 October 2015

Kaspersky Wins Test Malware Removal



Anti-virus software must be able to not only detect malware, including the removal of an infection is part of a good working virus scanner. The Austrian test lab AV-Comparatives therefore decided to test 16 security packages to consumers on malware removal.

In total, were used for the test 35 different malware instances that had to remove the packages. These criteria include being sought for leave of executable files, MBR or registry changes, custom host files and programs that were disabled by the malware and after disinfection is still not working, like Windows Task Manager and the Windows Registry Editor.

The packages were evaluated for the simplicity with which the malware was removed, like removing normal mode, safe mode, using a rescue disk or calling the help desk to remedy the infection. Eventually, the virus could score up to 100 points. Kaspersky Lab sets with 93 points, the highest score down just before Avast (89) and Bitdefender (89). Sophos (72) and Threat Track Viper (65) put the lowest score down. Microsoft Windows Defender ends up with 80 points in the middle.

Thursday, 24 September 2015

Google: Anti-Virus Software, Kaspersky Still Leak


The anti-virus software of the Russian anti-virus firm Kaspersky Lab still contains multiple vulnerabilities, says Google researcher Tavis Ormandy. Recently released the virus fighter that's been a big leak could poem was found by Ormandy and the system could allow an attacker to take complete without users here had to do something.

The researcher Google has much more major vulnerabilities found in the anti-virus software, so Ormandy late in an analysis of the leak know that are already patched. The analysis was made ​​on the Project Zero blog from Google. Project Zero is a team consisting of Google hackers and researchers looking for vulnerabilities in popular software. This included the anti-virus software from Kaspersky scrutinized.

Not patched

"Many of the bug reports I submitted are still not patched, but Kaspersky has made enough progress that I can talk about some of the problems," as the researcher says. Ormandy had found dozens of bugs in the anti-virus software and reported. The research shows that some of the most dangerous leaks were very easy to abuse. The researcher is pleased that Kaspersky Lab here for additional security rolls out. The impact of a vulnerability will increase in anti-virus software because the virus often file system and network traffic intercepted.

Visiting a website or receive an e-mail is enough to be attacked. It is then not even be necessary to open the e-mail, since the input / output of the reception of the e-mail is sufficient to cause the vulnerability. Besides the discovered vulnerabilities Ormandy also found several major design flaws in other parts of the anti-virus software. These other vulnerabilities to attack his distance. As the updates previously been deferred, he will discuss these issues later.

Security software harmful?

According to Ormandy, there are strong indications that there is an active trade in exploits for antivirus software exists."Research shows that a readily accessible attack surface that exposure to targeted attacks increased enormously," says the researcher. Therefore, he believes that security software developers the strictest security guidelines when developing their software must implement in order to reduce problems caused by the software. Something that fail anti-virus companies. In the past Ormandy has major problems in the software of anti-virus company Sophos and ESET found.

The researcher concludes with a warning and request for anti-virus companies. They would parts of their software does not have to run with system privileges. "Do not wait for the network worm that it has provided in your software, or targeted attacks against your users. Add even today the development of a sandbox to your development plan." Regarding the outstanding vulnerabilities in the software of Kaspersky Ormandy says that the anti-virus company responds very quickly and that a number of critical vulnerabilities in the coming weeks will be patched.

Wednesday, 16 September 2015

Windows User Reports Malware Often Than Mac User


Windows users are more in touch with malware than Mac users, according to research (pdf) from Kaspersky Lab and B2B International among 12,000 consumers worldwide. 45% of consumers surveyed faced the last year at least once with malware.

Windows users was 83%, while 6% of Mac users reported a malware incident. 13% of Android owners came to own say in the last twelve months in touch with malware. Windows users with malware came in contact 89% said they do not know how the infection occurred, but 81% points to visit a suspect or unreliable website. According to 77% of the computer became infected after visiting a hacked website.

According to 78% of the infection was contracted through an infected USB stick, while just over 70% of the debt puts when opening an email attachment. Reduced performance were the main consequences of an infection. 35% of users said that the system after the infection was slow or not working well. 30% were redirected to websites and ads, and 20% had to do with the installation of unwanted software.

Damage

33% of malware incidents led to charges by victims. This mainly involves repair costs, the purchase of a virus, recover lost data, purchase a cleaning tool, replacement of damaged parts, purchasing an entirely new system and the payment of ransom to restore access to the system or data to get. On average, the loss $ 160.

Thursday, 10 September 2015

Spies Steal Confidential Data For Years Via Satellites


A group of cyber spies by several anti-virus companies responsible will be held for attack on the Belgian Ministry of Foreign Affairs and numerous other organizations is already using satellites for years to steal confidential data from infected computers. Reported anti-virus firm Kaspersky Lab today.

The espionage group called "Turla" and is responsible for the Snake rootkit, also known as Uroburos. Through social engineering and zero-day vulnerabilities knows the group of infecting computers for eight years. It involves government agencies and embassies, as well as defense, education, and research organizations and pharmaceutical companies. After valuable targets have been determined using the attackers in the final phase of the attack a wide, satellite-based communication mechanism in order to steal the data and to cover their tracks.

Satellite

Satellite provides mainly people in remote areas access. One of the most widespread and affordable types of satellite-based Internet connections is called a downstream-only connection. In addition, outgoing requests from a user's computer to communicate through conventional lines, such as a dial-up modem or GPRS connection, while all inbound traffic from the satellite. This technology allows the user to achieve a relatively high download speed.

The downstream traffic has the disadvantage that it comes back to the unencrypted computer. A malicious user in the same region as the satellite user can intercept this traffic with the right equipment and software and gain access to the download traffic from users. The Turla group used this weakness to steal confidential data from infected computers without them hereby leave a trail.

The group listens first to the downstream of the satellite to identify active IP addresses of the satellite-based Internet users who are online at that moment. Then they choose an online IP address that they want to use to send the stolen data to, without the legitimate user of this is informed. The infected computer then is instructed to send the data to the IP address of the user satellite.

TCP / IP connection

In order to steal data from the satellite traffic the attacker must have a complete TCP / IP connection between himself and have the infected machine, let Stefan Tanase Kaspersky Lab. When setting up a TCP connection between two machines, the first client sends a SYN packet to the server. Then, the server sends a SYN-ACK packet back.The client replies with an ACK packet, and the connection is established and data can be exchanged.

In the case of the espionage group allows the infected computer to send a SYN packet to the IP address of the user satellite.The satellite provider radiates this SYN packet to earth. The innocent satellite user accepts the package, because he has not asked for here. Therefore there is no TCP / IP connection. The attackers who are in the region and accommodate the satellite traffic received the same package, but accept it. For this, they send back an ACK request, in which they spoof the IP address of the user's satellite. "This way they know parallel a full TCP / IP connection to set up and steal the data," said Tanase.

Hijacking satellite links was discussed at the Black Hat conference in 2009 and 2010 (PDF 1, PDF 2). According Tanase uses Turla group this tactic since at least 2007. Two years before the public was discussed. Other espionage groups would use this tactic. For this own satellite links are used, but in the case of the group-Turla lifts them on the satellite traffic of others.

The use of satellites has the advantage that attackers in this way be able to hide the location of their own server. Also, it is not necessary to have a valid subscription satellite. Hijacking the satellite link can be completely anonymous. As a result, it is also difficult to identify the attackers. This method has some drawbacks, since satellite based Internet can be slow and unstable.

Providers

Another interesting aspect to the tactics of Turla is that satellite Internet service are used in the Middle East and African countries. Thus, the researchers discovered IP addresses of providers in Afghanistan, Congo, Lebanon, Libya, Niger, Nigeria, Somalia and Zambia. Satellites used by operators in these countries usually have no coverage in European and North American regions. This enables most security researchers very difficult to investigate such attacks.

"Turla is able to achieve the ultimate anonymity by using a widely used technology -. One-way Internet via the satellite, the attackers anywhere itself can within the range of the satellite selected by them are, an area that can cover thousands of square kilometers "Tanase know so late. Kaspersky Lab detected worldwide hundreds of infections, although the actual number may be higher is because the virus fighter does not all infections. The attackers are thereby still active and still make use of satellite communications to steal confidential data, according to the Russian anti-virus company.

Tuesday, 8 September 2015

Kaspersky Close Critical Vulnerability In Anti-virus Software


The Russian anti-virus firm Kaspersky Lab last week released a critical security vulnerability in the anti-virus software patched. Through the vulnerability an attacker could completely take over the system without users here had to do something. The leak was discovered by Tavis Ormandy.

Ormandy works for Google, but also carries out research in its own right. According to the researcher, who also critical vulnerabilities in anti-virus software from ESET and Sophos discovered, the problem arose in the default configuration. Ormandy called the leak as bad as it can be. Through the vulnerability an attacker could execute code with system privileges ie, without user interaction.

Where exactly the problem was and how an attacker can use them was not disclosed. At first it was difficult, according to the researcher to a security contact at Kaspersky found. After being informed was the Russian virus fighter within 24 hours with an update that was rolled out to users, so let Ormandy on Twitter know.

Sunday, 16 August 2015

Kaspersky: Angry Ex-Employees Behind Bogus


Yesterday Reuters with a story that Russian anti-virus firm Kaspersky Lab competitors like AVG, Avast and Microsoft did years sabotaged, but according to founder Eugene Kaspersky and the anti-virus company is a nonsense story from angry ex-employees.

The story would have provided the anti-virus company legitimate files from malicious code. These files are then uploaded to the VirusTotal website and shared with other anti-virus companies. VirusTotal is a website where Internet files can be scanned dozens of virus scanners. Uploaded files are shared with participating anti-virus companies. By uploading the files sabotaged legitimate files the virus of anti-virus companies would therefore be regarded as malware.

Kaspersky Lab that the statements are unfounded and untrue and made ​​by angry ex-employees. The anti-virus company shares data correctly with other parties. "Although the security market is very competitive, is the exchange of threat data is an important component of the security of the entire IT ecosystem and we work hard to ensure that this exchange does not jeopardize or sabotaged."

Experiment

Well carried out the anti-virus company in 2009 and 2010, two experiments in which clean files to VirusTotal were sent and Kaspersky Lab files considered intentional malware. A few months later found several other scanners on VirusTotal that the files were infected, even though that was not the case. Kaspersky Lab made ​​the investigation public . In their own words to indicate that the problems with the testing of malware.

Ex-employees

On his own blog is Eugene Kaspersky also on the story and denounces in particular the use of anonymous sources. "Angry ex-employees often say nasty things about their former employer, but in this case the lies are simply ridiculous." According to Kaspersky, the resources possible to convince the journalist of Reuters know, but the story is ultimately published without any evidence. "I therefore ask myself what these ex-workers' media tell us about the next time and who believe their bullshit then."

In the blog posting Kaspersky also discusses the problem with false positives. In 2012 and 2013 had anti-virus companies many problems with false positives. An attacker provided legitimate software from malicious code and spread it. Both Kaspersky Lab and other antivirus companies were targeted. There was then a meeting behind closed doors, where there is information about the attacks was exchanged. This also was the suggestion suggested that another anti-virus company possible was behind the attacks. Symantec confirms the story and says that Kaspersky Lab, in any case, none of the suspects.

Saturday, 15 August 2015

Kaspersky Accused Of Sabotage Anti-virus Companies


The Russian anti-virus firm Kaspersky Lab would have the virus for years of competing anti-virus companies sabotaged to show to clean files for malware, so important files were deleted or quarantined.

Let two former employees facing Reuters know. Kaspersky Lab, however, denies any wrongdoing. According to former employees, there was a secret campaign against Microsoft, AVG, Avast and other competitors that lasted for ten years. The plan would be carried out with the knowledge of Kaspersky founder Eugene Kaspersky. According to former employees, who wish to remain anonymous, Kaspersky found that the competition software imitated.

Microsoft, AVG and Avast showed earlier told Reuters that unknown parties in recent years had tried to cause false positives, such as the improper detection of clean files as malware is called. According to the former employees of Kaspersky were provided important files from malicious code, to upload them then to VirusTotal. This website Google scans files with dozens virus. Uploaded files are then shared with connected anti-virus companies.

If the malicious file seemed adequate to the original, the virus would clean file as malware can label. Microsoft says that in 2013 discovered thousands of these files and warned here at that time also ( pdf ). Kaspersky Lab said in a statement that it has never carried out such a secret campaign to mislead competitors with false positives. "Such actions are unethical, unfair, and if it is legal, at least questionable," said the Russian virus fighter.

Update

Eugene Kaspersky cites Reuters story on Twitter complete nonsense. "Usually I do not read to Reuters, but when I do I see false positives. This story was complete nonsense."

Tuesday, 11 August 2015

Espionage Group Uses Rtlo-Trick In Windows


A group of cyber spies who in the last year, news came as the guests through the WiFi network of their hotel with malware infected, now uses other methods to attack targets, including the rtlo-trick in Windows and a vulnerability that by Italian Hacking Team was discovered.

The group, according to the Russian anti-virus firm Kaspersky Lab since 2007 active and has conducted several attacks this year. The attacks took place among others in Germany, Mozambique, Bangladesh, Thailand, Russia and North Korea. To attack the targets the group makes use of physical access as well as a flaw in Adobe Flash Player that was familiar to Hacking Team. Kaspersky discovered that there are several e-mails were sent with links, pointing to a page on which the Flash Player leak was attacked.

Rtlo

The group also sent emails with RAR attachments that recipients via the rtlo-trick in Windows attempted to mislead. This RAR attachments contain an executable .scr file. By using rtlo seems like a jpg image. Rtlo stands for Right-to-Left Override and ensures that the sequence of characters of a file name can be reversed through a special unicode character. This will SexyPictureGirlAl [rtlo] gpj.exe appear in Windows as SexyPictureGirlAlexe.jpg.

In this case, the .scr file resembled a jpg image. As soon as the recipient opened the file is a real image was shown, while a backdoor was installed in the background. The used backdoors are signed with a valid, stolen certificates, which might help to bypass certain security mechanisms of the operating system and anti-virus software. Windows users who want to protect themselves against rtlo to the detail switch. In this case, Windows will display the jpg image is actually an application.

Thursday, 6 August 2015

Fraudulent Invitation Includes Windows 10 Trojan


Cyber ​​criminals from all over the world seem to grasp the launch of Windows 10 to infect internet users with malware. Earlier this month, already widely English e-mails supposedly sent an installer for Windows 10 offered.

In reality, however, it was ransomware. Now, similar reports have surfaced in Brazil, whereby criminals in their email copied from the Microsoft website. The only addition is a link to a so-called "Windows 10 Installer" allows users to download the new OS. However, it is a VBE script hosted on Google Docs. After having opened the script installs a Trojan horse on the computer to copy keystrokes and opens a backdoor, reports anti-virus firm Kaspersky Lab .

Sunday, 19 July 2015

Voicemail Leads To Malware Attack Via OneDrive


A group of attackers used voicemail messages in combination with malware hosted at onedrive to attack organizations, as several security companies warn. The attack on the organizations begins with targeted phishing mails which contain a self-extracting archive file as an attachment. The attachment occurs when voice mail.

If a user opens the attachment is there as a distraction play a .wav file that looks like a real voice. In the background, however connection with OneDrive made the cloud service from Microsoft. The ultimate malware is then downloaded. Sergey Lozhkin of the Russian anti-virus firm Kaspersky Lab wonders whether this method will be applied by more cyber criminals.

"It is possible because it provides an easy way for attackers to hide malicious behavior. Detecting malicious traffic in legitimate cloud services is much more complex because it involves legitimate services to be blocked," said Lozhkin.Security company Palo Alto Networks has more details about the malware used, which was detected at the time of discovery by 3 of the 54 scanners on VirusTotal.

Thursday, 9 July 2015

Criminals Hacked Apple And Microsoft Still Active



A group of cyber criminals in 2013 Microsoft , Apple , Facebook and Twitter hacked is still active and has provided the large companies, which both malware for Windows and Mac OS X is used. Before the attack on the US Internet companies at the time the attackers used a zero-day vulnerability in Java. At the time of the attack there was no update available for the leak.

After all the attention to the burglaries, the attackers vanished in 2013 for almost a year, but now they are back and they use a previously unknown vulnerability in Adobe Flash Player and use a certificate from the Taiwanese manufacturer Acer to sign with malware. That report anti-virus firms Symantec and Kaspersky Lab today. Both virus fighters have put a group of the analysis.

This is according to anti-virus companies to a group of cyber criminals who operates on a much higher level than other cyber criminals. So is wanted there for credit card information, but to very valuable information. The attacks were the past few years aimed at law firms, Bitcoin-related companies, investment companies, IT companies, health companies and brokers, as well as individual users. Most victims are located in Canada, Europe and the United States.

Attacks

To infect victims they have used the aforementioned zero-day vulnerability in Java and at least one vulnerability in Internet Explorer 10, says Symantec. Kaspersky Lab reports that the attackers have used an unknown vulnerability in Flash Player.The victims are attacked by the leak is unknown. At the first attacks in 2012 and 2013 were hacked websites which targets already visited by itself. How the attackers in the new series of attacks proceed in 2014 and 2015, however, a mystery. In case the attack is successful, the attackers use various tools, including a backdoor for Mac OS X and Windows.

The attackers have mostly provided on mail servers. Once access to the Microsoft Exchange or Lotus Domino servers obtained the e-mail traffic probably bugged, says Symantec. There may also be "fraudulent e-mails" are injected.Furthermore, Kaspersky Lab discovered the malware that was used this year by the group signed with a legitimate certificate from Acer. The certificate has been obtained is unknown. The certificate authority that issued the certificate has been asked to withdraw the certificate.

"Compared with other intelligence groups, this group is one of the most exciting we have analyzed and monitored," Kaspersky Lab says. The virus fighter warns that the criminals are still active. Symantec also warns companies of the group, which not only has excellent operational security, but also succeeded in expanding the activities and not be noticed. "The group is a threat that companies should take seriously," said the virus fighter. The data that the group steals the possible uses for their own financial gain, or by selling to the highest bidder.

Tuesday, 7 July 2015

Building Kit Of Malware That Dutch Banks Attacked Leaked



Researchers have found the kit on the Internet the malware was used in the past to attack Dutch banks. It is the KINS malware, which stands for "Kasper Internet Security Non ', a reference to an eponymous product of anti-virus firm Kaspersky Lab.

It is called a banking Trojan data for Internet banking attempting to steal, to subsequently join defraud. In addition, the malware can also steal passwords for different websites. In late June showed that of the 2.0 KINS "builder" and source code of the control was leaked, so discovered several researchers, including those from Malware Must Die! . They decided after internal consultation to make the discovery public, because they were mostly "bad guys" who knew of it, instead of the "good guys". So the malware can now be downloaded from various websites.

The researchers note that the source code of the malware itself is not leaked. It is the source of the control which information about infected computers can be collected and viewed. Through the "builder" which is also available online can through a few mouse clicks new instances of malware are generated and that can be a big problem, so they claim.

"This is very important information for the security community. The archive will be distributed on a large scale," the researchers said. They also ask others for help in countering the spread of the malware kit. KINS in 2013 was presented as a new digital bank robber. From examination of the Delft security company Fox-IT found that the Trojan horse in the source code of the notorious Zeus banking Trojan was founded and since 2011 it was used to attack banks, especially in Germany and the Netherlands.

Thursday, 25 June 2015

Facebook Lets 2 Million Computers Remove Malware


Thanks to Facebook more than 2 million computers have been virus-free for the past three months again.When logging on to the social networking site Facebook detected that the computers were infected with malware. Then, users were offered a tool to remove the infection.

The removal tool runs in the background and users will see a notification when the scan is performed. Facebook already offered the tools of ESET, F-Secure and Trend Micro, and there is now also the Malware Scan for Facebook joined Kaspersky Lab as the social networking site let know . In total, there would be via the scanner Kaspersky Lab for over 260,000 Facebook users have been helped.

Monday, 22 June 2015

Anti-Virus Companies Were Targeted GCHQ And NSA


Several anti-virus companies in the past have been the target of US and British intelligence, focusing in particular went to the Russian virus fighter Kaspersky Lab, according to documents from whistleblower Edward Snowden in 2008.

The US NSA and the British GCHQ looked for ways to circumvent virus and other security software. The e-mail traffic was monitored in order to bring users of anti-virus software identified. The documents also show that British intelligence software Kaspersky wanted to reverse engineer and that the NSA was looking for vulnerabilities. US intelligence also shows traffic between the servers and Kaspersky users have viewed the software.

In 2008 discovered a research team from the NSA that the Kaspersky software users sensitive information sent back to the company's servers. This information could easily be captured to track users, says a report. The NSA would have intercepted e-mails, which were intended for security companies and which were warned of new viruses and vulnerabilities, reports the intercept today using different Snowden documents.

According to researcher Joxean Koret anti-virus software is an attractive target for attackers. The software often takes the highest rates in the system. An attack on a virus an attacker could cause these rights. Moreover, the security of many anti-virus software to be desired and even years on other client applications such as browsers and document readers behind, Koret said. "It means that Acrobat Reader, Microsoft Word or Google Chrome are much more difficult to attack than 90% of the virus." It was recently announced that Kaspersky Lab was the victim of a sophisticated attack carried out by a state, according to the virus fighter.

Monday, 1 June 2015

Cybercriminals Steal 60 Million Of Russian Banks


Cyber ​​criminals have stolen 60 million last year from Russian banks and their customers, as announced, the Russian Central Bank. This involves both attacks on online banking users as attacks against the banks themselves. So last year was several times for attackers gained access to ATMs and so could control the issuance of banknotes.

An analyst of the Russian anti-virus firm Kaspersky Lab opposes SC Magazine that these attacks are mainly possible because the ATMs are still running on Windows XP. In addition to these direct attacks on banks virus fighter saw the number of Trojan horses that was designed to defraud online banking increase by a factor of nine.

According to a spokesman of the Russian Central Bank passed the number of attacks on bank accounts last year 300,000 operations, allowing the Russian banking system would be the most vulnerable in Europe. Due to the increased activity of cyber criminals looking Russian banks also new guidelines to tighten security.