Showing posts with label Palo Alto Networks. Show all posts
Showing posts with label Palo Alto Networks. Show all posts

Wednesday, 7 October 2015

Apple: YiSpecter-Malware Only Works On Old iOS Versions


The YiSpecter malware that security company Palo Alto Networks warned only works on older iOS versions, and only if users themselves downloading malware from untrusted sources, says Apple. The malware is mainly active in China and Taiwan, but the number of infections is unknown.

To spread the malware uses different methods, but a user action is still required to download and install the malware. In a statement to The Loop, Apple says that the problem affects only users of older iOS versions of the malware itself from unreliable sources have downloaded. The specific problem could be resolved in iOS 8.4. This version was published on June 30 of this year.

In addition, Apple has the apps that were used to block the spread of malware. Apple recommends that iPhone owners to install the latest version of iOS apps only from trusted sources such as downloading the App Store. Also, users should be careful when they get warnings when downloading apps.

Thursday, 24 September 2015

Apple Will Host Xcode In China to Prevent Malware


To new malware in the App Store has Apple decided to prevent the development program Xcode to host locally in China. That Apple chief executive Phil Schiller against the Chinese website Sina.com announced. Last week showed that infected apps in the App Store had ended.

The apps were infected with the XcodeGhost malware. Several Chinese Xcode developers had downloaded from an unofficial website. Xcode is Apple's official tool for developing apps for iOS or OS X. The version that the developers had downloaded were infected with malware, which also became infected by their developed apps. These apps were then placed in the App Store, where Apple controls the malware did not notice.

Download

For Chinese developers may take a very long time to download the 3GB large Xcode. "In the US there is only 25 minutes to download, in China, it may take three times longer," said Schiller. That is also a reason that Chinese developers are trying to download software through unofficial channels. Apple recommends that developers use Xcode and other development software, only download via the official website.

To make this easier for Chinese developers has now decided to host the development programs locally, so they can be downloaded quickly. Regarding XcodeGhost malware according to Schiller, there are no indications that the infected apps user data forwarded.

Wednesday, 23 September 2015

Researchers: Thousands Infected Apps In App Store


In the Apple App Store have been infected thousands of apps and a number of infected apps is still offered, say researchers from the Chinese Pangu Team. They have an app developed to iOS users can check whether they have downloaded an infected app.

The infected apps with the XcodeGhost-malware become infected. The name refers to Xcode, Apple's official tool for developing apps for iOS or OS X. Several Chinese developers had an infected version of Xcode which also downloaded the apps they developed became infected. Last Friday, September 18th, Apple began with the removal of the infected apps. On Sunday, let Apple know that all known infected apps was removed.

Monday, however, showed that there are still familiar with XcodeGhost infected apps were in the App Store, says security company Palo Alto Networks. How many apps now have become infected is unclear. Palo Alto first suggested that they were 39. China's Qihoo 360 did a survey of 344 apps, while Pangu Team says the 3418 infected apps have been identified. The researchers say that the actual number is much higher. In addition, not all infected apps from the App Store removed.

In previous posts Palo Alto Networks said that the malware was able to carry out phishing attacks on users by showing warning windows where people than their passwords might fill. This appears to be wrong afterwards. Today's malware is there not capable, but can be easily modified to do this.

Advice

In addition to turning the Pangu Team app and remove any found infected apps, users can also have two-factor authentication as an additional layer of security set, so advises Palo Alto Networks. Furthermore, app developers are advised to download development tools only through the official provider. Xcode should therefore only through the Apple website to download and no other location. Also need developers during development Gatekeeper protect their OS X machine set at the default level. Finally app developers are advised to check the integrity of their development tools and libraries before they release a new version of the app.

Monday, 21 September 2015

Apple Removes Infected Apps From App Store


Apple has malware-infected apps from the App Store removed after investigators here last week warned. The apps were created with an infected version of Xcode, Apple's official tool for developing apps for iOS or OS X.

Several Chinese developers had downloaded an infected version of the development software through unofficial download sites, which then also developed apps became infected. The malware in apps called XcodeGhost is able to send information about the device and apps and can try different ways to steal passwords. Thus the malware on the device can display a warning dialog box where users enter their login details and the contents of the clipboard can be read and modified.

The infected apps were both in the Chinese App Store and the App Stores offered in other countries. "We have the apps from the App Store away that we know that are made ​​with counterfeit software," a spokeswoman told news agency Reuters. "We are working together with the developers to ensure that they use the correct version of Xcode to make their apps again." What iPhone and iPad users can do to see if their device is infected Apple has not said. Also, Apple does not report how many apps it has been removed, but the Chinese security company Qihoo argues that the total of 344 with XcodeGhost infected apps found.

Sunday, 20 September 2015

Dozens Of Malware Infected Apps In App Store Discovered


Researchers in the official Apple App Store dozens of malware infected apps discovered, reports security company Palo Alto Networks. The malware sends information about the device and the infected app to the attacker and can receive remote commands from the attacker.

Through these assignments, the malware can show an alert box that attempts to steal login information. Also, certain URLs can be hijacked and it is possible to read data in the clipboard of the user and adapt. In this way, pirated for example, passwords can be stolen. The malware XcodeGhost mentioned. Xcode is Apple's official tool for developing apps for iOS or OS X.

At various Chinese websites and forums were posted links to an infected version of Xcode. These infected version was downloaded again by Chinese developers and used to develop their apps. However, the infected Xcode version added to the malware apps, which were then placed by the developers in the App Store. According to analyst Claud Xiao some developers choose to make because of the slow internet in China nearly 3GB large Xcode not be downloaded directly from Apple, but through unofficial download sites.

At first it seemed to be two infected apps that were offered only in the Chinese version of the App Store. Now Palo Alto Networks announced that it has detected 39 infected apps, including apps for banking, stock trading, instant messaging and games. These include to WeChat, developed by the Chinese Internet giant Tencent, Didi Chuxing, a kind of Uber-like app and China Railyway 123 036, the only official app in China for purchasing train tickets.

Some of the apps developed by Chinese developers are also available on the App Store from other countries, such CamCard and WeChat. The infected apps have been downloaded by millions of people. The Dutch company Fox-IT checked the domain names used by the attackers and discovered much more infected apps, including Winzip and PdfReader. In total hit Fox-IT more than 50 infected apps on.

Sunday, 19 July 2015

Voicemail Leads To Malware Attack Via OneDrive


A group of attackers used voicemail messages in combination with malware hosted at onedrive to attack organizations, as several security companies warn. The attack on the organizations begins with targeted phishing mails which contain a self-extracting archive file as an attachment. The attachment occurs when voice mail.

If a user opens the attachment is there as a distraction play a .wav file that looks like a real voice. In the background, however connection with OneDrive made the cloud service from Microsoft. The ultimate malware is then downloaded. Sergey Lozhkin of the Russian anti-virus firm Kaspersky Lab wonders whether this method will be applied by more cyber criminals.

"It is possible because it provides an easy way for attackers to hide malicious behavior. Detecting malicious traffic in legitimate cloud services is much more complex because it involves legitimate services to be blocked," said Lozhkin.Security company Palo Alto Networks has more details about the malware used, which was detected at the time of discovery by 3 of the 54 scanners on VirusTotal.

Wednesday, 25 March 2015

Half Of Android Users Would Be Vulnerable To Attack APK


Android Users who install apps outside of Google Play and an old Android version use are vulnerable to a new attack. It was estimated to be half of all Android users, warns security company Palo Alto Networks.The actual number is probably much lower.

Through the vulnerability could allow an attacker to break into the installation of a seemingly safe APK file and replace it with an app of choice, without the user noticing. The security issue is caused by an error in the system service "Package Installer" of Android, allowing attackers unnoticed can get unlimited access rights. During installation let Android Apps see what permissions they need in order to work properly. A Messages app, for example, require access to SMS messages, but not to the GPS location.

The vulnerability gives attackers the ability to deceive users by a false, smaller set to allow access rights to see. In reality, the user, if he chooses to install the app, just give access to all services and data on the device, including personal information and passwords. The problem is present in Android 2.3, 4.0.3-4.0.4, 4.1.x, and 4.2.x and some distributions of 4.3. According to Palo Alto Networks uses about half of Android users one of these versions.

The actual number of users that are at risk is likely to be much lower. The security issue because only occurs at Android apps that are downloaded from third parties and unofficial marketplaces. It does not apply to apps downloaded from Google Play. These files are downloaded namely in a safe environment that can not be modified by an attacker. Owners of Android devices vulnerable therefore be advised to only download apps from Google Play.