Showing posts with label Malicious Emails. Show all posts
Showing posts with label Malicious Emails. Show all posts

Thursday, 15 March 2018

Microsoft: Shift From Ransomware To Cryptominers



Millions of computers have come into contact with cryptominers in recent months, while the number of cases of ransomware has declined, according to Microsoft today. From September last year to January of this year, an average of 644,000 unique Windows computers were detected each month and encountered a cryptominer.

This involves malware that can be installed on the computer in various ways and allows the system to mine cryptocurrency. While there is a clear increase in the number of cryptominers, the number of computers encountered by ransomware is decreasing. A possible reason is that cryptominers are now also distributed via exploit kits, as well as via malicious e-mail attachments.


"It is unlikely that cyber criminals will completely abandon ransomware in the short term, but the increase in trojanised cryptominers shows that attackers are exploring the possibilities of illegally earning money with this newer method," said Eric Avena of Microsoft. Because cyber criminals now choose more for cryptominers, this malware will also take over the behavior of already known threats, according to Avena. As an example, he points to the NeksMiner, who places a copy of himself in shared network folders and on USB sticks to propagate further, like all kinds of other malware.

Tuesday, 20 October 2015

US Defense Officials: Think Before You Click


US officials increasingly are targeted by so-called spear phishing attacks, reason for the US Department of Defense to issue a brochure with advice. The brochure follows two major break-ins at the Office of Personnel Management (OPM) earlier this year.

In addition, the data of millions of civil servants were stolen. The brochure explains how phishing attacks exactly and how phishing mails can be recognized. During an exercise of the army with a phishing test was a phishing email with a malicious Excel file sent to seven users. Two user opened the file, making the 'attackers' ultimate domain administrator on more than 6800 user and computer accounts were 5400. Officials are therefore given in the leaflet to stop the advice to first and think before they click on something.

Monday, 27 April 2015

Employees IT Company Target Of Malware After Acquisition


Employees of the US IT security company Websense have become the target of malware after the company earlier this week was taken over by the US defense company Raytheon. The workers received an email with the subject "Welcome to join Raytheon" and attach a zip file. The zip file contains the installer of Kaspersky Anti-Virus, plus a DLL.

Once the installation was carried out, was the DLL loaded from the zip file. However, this was the malware. According to Websense it comes to "dll sideloading", also known as "DLL hijacking". A well-known problem that is caused by some of the programs first search in the opened directory to .dll files that are necessary for the execution of the software. An attacker could execute malicious DLL files in this way.

According to Websense, the attack failed because the attackers in their haste had prepared a very sloppy email, without preamble, introduction or explanation. The message consisted of only two sentences, including the password to open the enclosed zip file. "Always use caution with attachments and links in an email and make sure everyone is alert during a takeover. Attackers leave no chance and one click is enough to get infected," said analyst Wang Ulysses.