Showing posts with label Macro. Show all posts
Showing posts with label Macro. Show all posts

Tuesday, 10 March 2015

Attack With Malicious Macros In XML Files


Cyber ​​criminals use to spread again some time macros in documents to malware, but now there are also attacks observed with XML files were deployed. Macros allow users to automate various tasks and were used years back on a large scale by malware. Because of the security risks, Microsoft decided therefore to block macros by default in Office.

A year ago, appeared more and more .doc and .xls documents containing macros were hidden. The documents users were summoned to enable macros. Once the user the macro switch is downloaded and installed malware instance in the background. One tactic that seems to be successful, because the beginning of this year, Microsoft already gave a warning off for macro malware. Now warns security firm Trustwave for a new attack in which malicious macros are used via XML files.

XML stands for Extensible Markup Language and XML-based formats have become the standard for various office tools, including Microsoft Office. When a user loads the XML file opens Office and will appear again indicating that macros must be enabled. After switching a malicious script is executed that downloads and installs a Trojan horse. It is the Dridex banking Trojan, malware specifically designed to steal money from online bank accounts. The Internet Storm Center (ISC) gives organizations advice how this kind of XML files can be filtered.

Wednesday, 19 March 2014

Windows Spyware WinSpy and GimmeRAT monitors Android devices

If you are using Android Phone and syncing with the Windows Operating System for backup and transferring files, Then Be Careful.
Mechanism of attack on financial institution employing WinSpy

Researchers have found by analysis of an attack on a U.S. financial institution Windows spyware that is also able to monitor. Android devices The institution was attacked by a spear phishing email, which had a large NSIS file as an attachment.
Once the file was opened, the recipient was a picture of a payslip to see while installed in the background. WinSpy This is commercially available Windows-spyware which makes it possible to monitor, according to the authors. Computers but also Android devices In a second attack on the institution was again used WinSpy, only the malware was now hiding in an Excel document with a macro.
Once the malware on your computer is active, the attacker can control the webcam, capture screenshots, saving keystrokes, disable security software, downloading and surfing habits chat conversations via the microphone shoot, upload and download files and send messages to the computer.

Android



During the analysis of the malware security company FireEye also discovered various Android components that can be used to monitor the victim. It involves three different applications, one of which only works when the device is connected to the Windows computer while the other two make it possible to control. Android device via SMS
Deployment Scenarios for Android Components

To install the Android spyware must be connected, then the installation takes place. On the infected computer Windows phone Through the Android spyware screenshots can be stolen and it is possible to find out. The location of the target
"These attacks and tools to confirm that we live in an age of digital surveillance and theft of intellectual property. Commercial Remote Administration Tools (RATs) continue to proliferate and are increasingly being used by attackers," said analyst Thoufique Haq. He notes that the rise of mobile platforms like Android, a new market has emerged which also asked about RATs that support these platforms.