Showing posts with label Malicious Documents. Show all posts
Showing posts with label Malicious Documents. Show all posts

Saturday, 26 September 2015

Office Documents Favorite Target Attackers


Microsoft Office documents are the favorite target of attackers at companies and organizations know how to break or there for work, according to research (pdf) Intel Security among more than 500 IT professionals to at least one large data intrusion were given to make.

The intrusions are both performed by external attackers as their own staff. 57% of the attack was the work of external attackers. The remaining 43% came in the name of their own staff. In half of these cases, there was set-up, while in the other half of the internal incidents was unintentional. At both internal and external attackers Office documents are the favorite target, followed by .txt and .csv files.

In most cases, the stolen files contain information about customers and employees. A quarter of the data was stolen by "tunneling 'protocols such as FTP and SCP, while 40% of data thefts occurred stolen via physical media. In the latter case, thus organizations are advised to encrypt data.

Wednesday, 9 September 2015

Microsoft Office: Documents Install Backdoor Through Recent Office Leak



A recent vulnerability in Microsoft Office that in April was patched is already several weeks actively attacked and used to install a backdoor on Windows computers. A problem because many organizations install security updates for Microsoft Office or wait very long time here.

By opening a malicious document, an attacker could then install malware on the computer. A tactic that has been successfully applied. Last year made ​​the British anti-virus firm Sophos study (pdf) to the vulnerabilities that attackers use to this kind of attack. Two leaks, one from 2010 and one from 2012, was attacked by most of the malicious documents. Also from other surveys show that the vulnerability in 2012 the favorite target of attackers.

Although there is an update to the now attacked Office leak for about five months is available, the question is how many organizations have installed. Even before the patch Microsoft released the vulnerability was attacked. Early August saw Sophos, however, pass by a series of papers that try to take advantage of the leak. The documents have subjects like "WUPOS_update.doc", "ammendment.doc", "Information 2.doc" and "Anti-Money Laude Ring & Suspicious cases.doc".

In case the files are opened on an unpatched machine, the code in the document called Uwarrior install a backdoor on the computer. This allows the attackers full control over the machine. To prevent infection, managers and users are advised to patch Office and not to open unexpected or unsolicited documents. Last week warned IBM all e-mail attachments to make a comeback as an attack vector.

Sunday, 5 July 2015

Bitcoin Exchange Bitstamp Hacked Via Word Document



Early this year knew attackers to hack the Bitcoin Exchange Bitstamp, involving some 19,000 bitcoins were stolen. Translated at the current exchange rate it was 4.3 million. A confidential document investigation into the cause of the hack is leaked and includes details about the attack.

The attacker appeared in November and December to have a targeted phishing attack against employees of the company performed. Thus, the CTO of Bitstamp was approached by Skype, which he was offered free tickets to a punk rock festival.The CTO is an avid fan of punk rock and has played in a band, something that had overtaken the attacker. The tickets were in the form of a doc document sent via Skype.

In reality, the document was found to contain a malicious VBA script that had to install malware on the system. Although the CTO opened the document, the script does not seem to have worked. The other employees had more success the attacker.He sent a resume and a questionnaire and he presented himself as a journalist. On December 9, the attacker sent a phishing email to the Gmail account of the system. This system had access to the "hot wallet" of Bitstamp, where bitcoins stored.

In the e-mail suggested the attacker that the Upsilon Pi Epsilon system administrator (UPE) society was invited. The system opened the document then successfully carried out the VBA script and malware placed on the computer. A few days later, the assailant took Skype contact to continue the talks. Eventually, the attacker logged on via the laptop's system on the servers of Bitstamp in order to access the file wallet.dat. The digital file containing the thousands of bitcoins.

In total, found that six employees were targets of phishing attacks, which were sent malicious attachments in four cases. The researchers show in the report, which appeared in February, that the investigation is still ongoing, but they may have identified one of the attackers. The plan then was to lure the attacker to Britain to arrest him, reports Business Insider . As far as is known, however, there is no one still maintained in connection with the hack of Bitstamp.