Showing posts with label Spyware. Show all posts
Showing posts with label Spyware. Show all posts

Thursday, 12 November 2015

Website Ammyy Admin Spread Infectious Download



The official website of the remote desktop software Ammyy Admin has recently been hacked and has offered several days a contaminated version allowing users by a group of cyber criminals were spied upon. Ammyy Admin makes it possible to record on remote computers.

According to the developers make more than 50 million people, both business and private use of the software. It is used by companies in the Fortune 500, as well as banks. Also telephone scammers use the software. Some detect anti-virus programs Ammyy Admin whatsoever as unwanted software. According to the Slovak anti-virus company ESET is the remote desktop software especially popular in Russia.

On October 26 ESET discovered that on the website malware was offered. The free version of Ammyy Admin was replaced with an infected version. Until November 2 the infected version was offered. The installer installed the real Ammyy Admin software, as well as a file called AmmyyService.exe or AmmyySvc.exe that contained the malware. Then analyzed the malware existing software and websites visited.

If the computer had sufficient value was additional malware being installed. This malware was signed with a certificate from Comodo, which has been withdrawn. The malware spies on users, records all keystrokes, enumerate smart cards and communicates with a command & control server. It is unclear when the site was hacked and how long exactly malware is offered. ESET tried the developers of Ammyy Admin several days and warn in different ways, but received no response.

Tuesday, 14 July 2015

Hacking Team Has BIOS Rootkit For Permanent Infection



The Italian Hacking Team has an UEFI BIOS rootkit to infect computers with spyware permanently from the company. This enables the Japanese anti-virus company Trend Micro on the basis of the data that was recently at the Italian company captured.

Hacking Team offers government agencies a "Remote Control System" (RCS) allows investigators to remotely access the computers, for example, suspects can get. To ensure that the software remains on computers even if the hard drive is formatted or replaced by a new one, Hacking Team has an UEFI BIOS rootkit developed.

The BIOS (Basic Input / Output System) and the Unified Extensible Firmware Interface (UEFI), the successor to the BIOS is a set of basic instructions for communication between the operating system and hardware. It is essential for the operation of the computer, and also the first major software that is loaded. In the case of Hacking Team involves a rootkit for UEFI BIOS, Insyde Software. The company makes BIOS software for laptops.

Physical Access

To install the rootkit do have to have physical access to the system can be obtained. According to analyst Philippe Lin Trend Micro can not be ruled out that it is also possible to remotely install the rootkit. The Italian company also developed a tool to help users of the rootkit and provides support in the event the BIOS image is not compatible. According to Lin, the rootkit can be modified so that it also works with other BIOS software, such as the well-known software vendor AMI.

To protect themselves against the attacks, users of Lin's advice to enable UEFI Secure Flash BIOS, update the BIOS if updates are available and set a password to access the BIOS or UEFI. However, it is in many computers as possible to reset the password, but in this case, a user can see that something is wrong because he forgot no longer have to specify whether his original password no longer works.

Friday, 10 July 2015

Hacking Team Warns Leaked Software



The Italian developer of government spyware Hacking Team, which was recently the victim of a major burglary, has issued a warning for the software that was stolen at the company and has appeared online.According to the Italian company has sufficient code captured by which malicious attack other Internet users.

"For Hacking Team could determine the attack who had access to the technology, which was only sold to governments and government agencies." Through the work of criminals were now "terrorists, extortionists and others" to use the technology, according to the warning from the company. It is the first reaction to the incident Hacking Team via the website has brought out. According to the Italian company, the resulting situation is very dangerous. Hacking Team would also check whether it is possible to reduce the risk.

In addition, the company expects that will take anti-virus companies measures. Hacking Team develops software that allows investigators computers of suspects can control remotely. Because of the incident investigation services were requested to make temporary use of the software. Meanwhile, we are working on an update so that investigators can monitor the systems that have been infected with software Hacking Team again.

Furthermore, the Italian company has denied the reports that backdoors are present in the software that can control it. "That's just not true. Our customers use the technology on their own computer, and are therefore customers need to take action to cease operations," the statement said.

Tuesday, 7 July 2015

Hacking Team Had Zero Day Vulnerabilities For Windows And Flash



The Italian developer of government spyware Hacking Team had zero day vulnerabilities for Windows and Adobe Flash Player, according to the files that were stolen from the company. Yesterday published attackers a file of about 400GB with all sorts of information that was captured by Hacking Team.

The files have now discovered two vulnerabilities for which no security update available yet, says security researcher The Grugq . It is a vulnerability in Windows that allows an attacker can increase his rights on the system. In this case, the attacker must already have access to the computer in order to use the leak. The second vulnerability is in Adobe Flash Player. Through this vulnerability, an attacker computers or completely take over, for example, when users visit a hacked or malicious website.

The embedded Flash Player in Google Chrome is vulnerable. According to security researcher Kevin Beaumont makes the leak is possible to escape from the sandbox of Chrome. Researcher Rik van Duijn of security Dear Bytes however, leaves know that a sandbox escape "through the published code is not possible and therefore a second exploit is required. Hacking Team, which develops spyware for government agencies, has in statement confirming that it has been hacked. "We think there are documents of the company have been stolen. We have launched an investigation to determine the extent of the attack and to determine what exactly is captured," said a spokesman. The company's website has been offline since yesterday.

Update

The National Cyber ​​Security Center (NCSC) government has a warning issued for the flaw in Flash Player. Through the leak, an attacker execute arbitrary code on the computer with the rights of the logged in user. The NCSC states that there is no update available for the leak yet.

Update 13:48

The attack on Hacking Team is claimed by the hacker who last year by spyware developer Gamma International managed to break in and there gigabytes of data was captured, says Vice Magazine . The hacker says soon come up with the details of how he managed to break into Hacking Team.

Update 15:09

Anti-virus company Symantec confirms that this is a zero-day vulnerability in the latest version of Flash Player. The virus firefighter expects that attackers will probably make use of the vulnerability.

Update 15:19

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also the vulnerability and says that users can protect themselves by installing Microsoft EMET unreliable or not Flash content to perform.

Hacking Team Gets Control Back Hacked Twitter Account


The Italian company Hacking Team spyware for governments to develop and victim of a very large hack became possible where all data was captured, has regained control over its own Twitter account after about 10 hours.

A group of attackers who "HackedTeam" named used the hijacked Twitter account to spread links to a torrent file containing the data that was captured at the break. It would go together to such a 400GB 500GB of data. How the attackers were able to gain access to the network is still unknown. The leaked documents would prove, however, that surveillance company weak passwords like "Passw0rd" used. In addition, should the software company SQL Injection vulnerabilities contain.

The burglary was also the source of all kinds of programs, as well as the software itself stolen. A number of the programs has now been on GitHub placed. Furthermore, it seems that the attackers hacked not only the company but also at least one employee of the company. The Gmail account of this employee would be hacked and his Twitter account. Meanwhile, the Gmail password changed and raised the Twitter account, so says a security engineer with the alias "bcrypt" via Twitter.Hacking Team's website is now also no longer accessible.

Monday, 6 July 2015

Disguised As MP3 EXE Get Hundreds Of Clicks Per Day



Drive-by downloads and email attachments are still very popular ways to infect internet users with malware, so get daily also infected many users as they download executable files that they think are mp3s or illegal software.

It mainly involves users who search on Google for example songs. By manipulating the results cyber criminals know their pages with "tracks" to get high in the index of Google and so these users to lure to their website. The songs offered themselves as MP3 files, but in reality .exe files. However, Windows displays the default file extension is not. Once the files may contain malware or potentially unwanted software downloads, warns security company Blue Coat .

Software piracy

Security firm Zscaler recently paid attention even to the same strategy for infecting Internet users, only through so-called illegal software. Again it goes to sites offering exe files that occur for example as popular games, software and drivers. In reality, it is adware / spyware named OutBrowse and Multiplug. The programs collect information about the user and send them back and show unsolicited ads.

According to analyst Chris Mannon the problem lies mainly with the awareness of Internet users "Users know reliable download sites for software such as Flash Player or Skype, but as they search for pirated software and media, any link that promises results suddenly familiar." Mannon also advises users to content that is obtained illegally not to be trusted. "Users make bad decisions if they think the desired content can be obtained free of charge. We recommend downloading illegal content occasionally advise to pay just for the desired media."

Thursday, 19 February 2015

Victim Fanny-Espionage Worm Early In 2010 Already To Help


A victim of this week unveiled Fanny spy worm, which through two zero-day vulnerabilities in Windows spread that later were used by Stuxnet, early in 2010, all Internet users for help. However, they received no answer. That discovered Maarten van Dantzig Fox-IT.

A Malaysian forum posted a user with the alias "dkk" a call on July 13, 2010 how he could prevent his computer became infected with this virus. The user notes that he is infected via its USB stick, even though they are Autorun and Autoplay disabled. Much to the surprise of the user, different files found on the USB stick and the names also mentioned this, including Fanny.bmp. He also added a copy of the virus. However, there was no response.

Fanny.bmp is the same file that the report ( pdf ) from anti-virus firm Kaspersky Lab is known about the malware. The report also stated that Malaysia is among the countries where the worm is still active. Opposite Ars Technica confirms Kaspersky Lab that files who names the forum user match those of the Fanny worm. The worm was developed by a highly sophisticated espionage group and would have been deployed since 2008.

Thursday, 15 January 2015

Researcher Warns Of Software On Download.com


Download.com is a popular download site, but how secure is the software that is actually offered here?A researcher from How-To Geek decided the ten most popular programs from Download.com to install and startled by the result that he advises users not to repeat the experiment on their own computer. For the experiment, the programs were completely installed by default, as a typical user would do.

Download.com , which is part of CNet News, sets the policy that all downloads are offered free of adware, spyware or other malicious software. Many of the software appeared to be bundled with a variety of other programs. Via Download.com users can download the software directly, but there is also a Download.com -installer, which is much more apparent. This includes an installer that in addition to the desired program installs all sorts of other programs. It appears to include "browser hijackers" and fake "registry cleaners" to go.

Remarkably, the virus Avast is one of the first programs were installed and then some other downloads blocked because they were labeled as malicious. "Free software vendors to bundle earn almost all money through complete nonsense and scareware that mislead users to pay to clean up their PCs, regardless of the fact that you can avoid this by this" crappy "freeware nothing to install," says Lowell Heddings .

The experiment was repeated for several months and each time ended Heddings with other software on the computer. "Every software that unifies itself brings with it the same culprits: browser hijackers that hijack your search engine and home page and place ads everywhere because if the product is free, you are the real product.."

Tuesday, 16 December 2014

FBI used Metasploit to identify Tor users



The FBI has used a component of the popular Metasploit hacking tool to identify Tor users. Metasploit is a tool that penetration testers and security experts test the safety of systems and networks. It is now being developed and managed by security company Rapid7.


Wired reports that the FBI in 2012 set in part of Metasploit to successfully identify different Tor users through Adobe Flash Player. The US investigation department made ​​use of an abandoned Metasploit project called " Decloaking Engine ". It was one in 2006 developed experimental concept where multiple tricks were used to identify users of a service such as Tor anonymity via a specially crafted Web site. In case the Tor user had his installation secure he could not be identified through the website. However, if users made ​​a mistake their real IP address is visible.

Flash Player

One of the tricks was the use of a Flash application. Adobe Flash Player can set up a direct connection to the Internet and thus leak the IP address of the user. A known problem and the Tor Project advises users therefore not to install Flash Player. Finally appeared in 2011, a version of the Tor Browser, the software to access the Tor network, allowing users were better protected and the test site that was set up for the Decloacking Engine almost no users identified more.

However, the FBI used Decloaking Engine as a basis for an operation against child pornography sites on the Tor network. The investigation department had access to several of these sites and then let them run Flash programs in visitors' browsers in order to determine their true IP address. A total of 25 users in the United States were identified and an unknown number elsewhere. According to Wired is to use the first time the FBI spyware-like software to all visitors of a website started in place against certain individuals.

Identification

However, it is unknown whether the FBI standard Decloaking Engine has used or a customized version. HD Moore, the original developer of Metasploit and Decloaking Engine, argues that his release could barely identify Tor users. Only suspects with very old Tor version or who had gone to great lengths to install Flash Player would have been at risk.

In this way, the FBI would only have to suspects with the worst operational security-oriented instead of the worst offenders. A few months later, the FBI provided the weather on Tor users. Then there was an exploit for a known Firefox vulnerability used to determine the IP address and MAC address of Tor users. Again it came to users with poor operational security, as it attacked Firefox leak was already in the latest version of Tor Browser solved .

Monday, 8 December 2014

"More openness required --> Antivirus companies on government spyware"

Regin Malware

Anti-virus companies have to be more open about the government spyware that they find, says security expert Bruce Schneier . Schneier reigns on the discovery of the highly advanced Regin malware , which would be by the US and British intelligence developed .

Anti-virus companies have known for some time of the malware, but made ​​the existence of Regin until the end of November to the public. It was the first that Symantec came out with a publication because it knew that another party would reveal the malware. This party was news The Intercept. After the report, Symantec also followed F-Secure and Kaspersky Lab with their own findings. All three follow the anti-virus companies said Regin years, where she copies of years ago found.

"Why were all these companies Regin long secret and why they showed us all this time vulnerable?" Schneider asked. Self thinks the expert that the anti-virus companies no incomplete picture wanted to express. Unlike malware cybercriminals is the effect of government spyware much more complex. In addition, Regin was only used against specific targets, which makes it difficult to obtain copies.

"If you're big in the press comes with a newly discovered malware copy you want to have the whole story. Apparently no one thought they had it with Regin," said Schneier. The expert, however, find this no excuse. "Now government malware more often will come we will often not have the whole story." As long as nations will fight each other over the internet, according to the expert, some individuals or organizations are the target and the residual risk to be hit inadvertently by this type of malware.

Even more

Schneier believes that anti-virus companies are at the moment even more incomplete stories on all government malware. "But they should not do. We want and need that our anti-virus companies us all about these threats tell as soon as they can, and not wait for the appearance of a political story so they can no longer remain silent."

Monday, 14 April 2014

Top 5 of imaginary viruses that would make the world more fun



Why bugs should always be evil? What if they would like you to reconcile with your ex fun and useful things, or that awful Tumblr account before you delete?
Stuart Heritage describes in The Guardian five imaginary viruses that would make the world. enjoyable. He calls virus creators to show another side of himself, and actively improve to helping people instead of harassing. Positive viruses the world

1. Facebook privacy virus

The privacy settings on Facebook are all an eyesore. Every few months, Facebook decision or something which leads to a sudden anyone 5 years old photo, where you say the least not too flattering on state, can be seen. Then you have to login again and again confirm what you want to share and what not. What if a virus would be that would ensure that all of your pictures remain private forever? Would not that be nice?

2. Spotify playlist virus

No one will just have to play Spotify playlists at a party. Sane Indeed, there is a high probability that a track is played where you actually die ashamed of you and so you end up with your tail between your legs to leave the party. But think of a virus scan on playlists of songs you could possibly embarrass and removes them for you before anyone else can hear? That way you'll never laughed!

3. Tumblr itself destroyer

The world is full of teenagers who cram their Tumblr account with hand-drawn Justin Bieber fan art or other bad things. There will come a day when these teens will apply. Their potential employer will google their name and find the Tumblr account, with all its consequences. Rising unemployment is the result. Why does no one a virus that all traces of your Tumblr account automatically deleted on the day of your 18th birthday? That would be the best for everyone!

4. Reconcile virus

Gmail still read all all emails. Why is there no peaceful virus maker who does something here? What if somehow the phrase "How could you cheat on me" pops up. Reconcile the virus would see this and immediately, of course with a stolen credit card, buy a huge bouquet and have it delivered. Indignant at the partner Bingo! Everyone is happy again because everyone loves flowers, regardless of the sender.

5. Reminder Flickr

Just a virus that sends emails to you to remind that the Flickr account that you created in 2004 still exists ...

Sunday, 13 April 2014

U.S. sues nine people for spreading Zeus Trojan



The U.S. Justice Department has nine alleged members of a criminal organization accused of distributing and using the Zeus Trojan.
According to the prosecutor, they are responsible for infecting thousands of corporate computers with malware. Most of the suspects are from Ukraine.
Two of the suspects, Yuriy Konovalenko (31) and Yevhen Kulibaba (36) were arrested. The Ukrainians were arrested in the UK and have recently been extradited to the United States. Three other Ukrainians and Russian are also indicted but remain at large. The rest of the indicted individuals are not identified and included in the indictment. As "John Doe".

Indictment

All defendants are accused of conspiring to computer fraud and identity theft, conspiracy to commit extortion, several cases of bank fraud and identity theft qualified.
The suspects are accused of using Zeus or ZBot order bank account numbers, passwords, personal identification numbers, RSA SecureID token codes and similar information needed to log in to steal. On online bank accounts In the indictment was read to the accused banks were wise they were employees of the victims and were authorized to make transfers from the bank accounts of the victims.
Among the victims of the scam Zeus were the Bank of America, First National Bank of Omaha, Nebraska and the Franciscan Sisters of Chicago and Key Bank.

Method

The suspects reportedly used U.S. citizens as straw men. The straw men took the money and then returns to a foreign bank account of the criminals.
Kulibaba ran allegedly laundering network in the UK, while Konovalenko would have settled and was responsible for forwarding the information to Kulibaba. Straw men and the bank details The other members of the organization were responsible for the development of the malware and the financial and technical management.
"The Zeus Trojan is one of the most damaging financial malware ever used," said Assistant Attorney General David O'Neil. "As the charges demonstrate, we are determined to make the Internet safer and protect. Personal data and bank accounts of American consumers".

Research

The British police, the Dutch High Tech Crime Team and the Ukrainian Secret Service have the U.S. Department of Justice assisted with the investigation.
In 2007 Zeus botnet infected millions of computers worldwide. In 2010, a study by security firm RSA that almost all the "Fortune 500" companies have some form of a Zeus infection showed. From 2011 Zeus is sold as a commercial product.

Tuesday, 8 April 2014

Symantec: New era of mega-data leaks' has arrived

According to Symantec, a new era of "mega-data leaks' dawned. Cyber ​​attacks are becoming larger and cost tens of millions of dollars in damage.



At the end of 2013, the most damaging cyber attacks occurred in history, according to the annual Internet Security Threat Report (ISTR) from Symantec. The report shows a significant change seen in the way cybercriminals operate. Kept criminals rather mainly with fast attacks that had a small profit result, now they take months to prepare that generate a lot of money. Larger data leaks for
"A mega attack produces sometimes the same as 50 smaller attacks," said Tom Welling, Security Expert at Symantec Benelux. "Although the level of attacks continues to rise, more and more criminals have more patience and they wait until they can commit to deliver more money with a major attack."

Netherlands
The report also reveals that cyber criminals often use networks in the Netherlands to commit cyber attacks. If so-called "threat-source country rises Netherlands internationally from place to place 7 4. In the top ten of threat-source countries, only the Netherlands and Russia increased relatively strongly in 2013.



Increase
The number of data breaches in 2013 increased by 62 percent compared with 2012. As a result, more than 552 million online identities exposed to cyber criminals. So Cybercrime remains a real and damaging threat to both consumers and businesses. In the Netherlands, the favorite sector of cybercriminals each attack varies. The telecom industry is the biggest target for spam (77 percent), followed by the financial sector (64 percent). When it comes to malware, it is the largest retail target.



Compared to 2012, targeted attacks increased by 91 percent in 2013. Moreover, the attacks in 2013 lasted on average three times as long. Looking at occupations, personal assistants and PR staff are most attacked, because they are often a prelude to prominent figures such as celebrities or executives of large corporations.



Protect
According to Symantec, there are certain steps that businesses and consumers can take to protect against possible data leaks, targeted attacks, or general spam better.

Tips for Business
Know your data: information should be the focus of protection are not the devices or the data center. Knowing where sensitive information is located and where it is flowing, helps determine the best policy and the best procedures to protect the data.

Organization
Inform employees supervised workers in protecting their information. Give them an insight into the corporate policies and procedures for protecting sensitive data on personal and corporate devices.
Implement proper security infrastructure: strengthen the security infrastructure through prevention practices aimed at data loss, network security, endpoint security, encryption, strong authentication and defensive measures, such as reputation-based technologies.



Tips for consumers
Be smart in the field of security: Choose a strong password and update all your devices with the latest security software.
Pay attention: check bank and credit card statements for irregularities and be careful when responding to unsolicited or unexpected emails. Also be alert for online deals that seem too good to be true, because usually they are just that.
Know with whom you work, make sure you are familiar with the policies of retailers and online services that can retrieve bank or personal information. If this information should be shared, please do so via the official website of the company and not through an email link.

Detailed Report

Wednesday, 19 March 2014

Windows Spyware WinSpy and GimmeRAT monitors Android devices

If you are using Android Phone and syncing with the Windows Operating System for backup and transferring files, Then Be Careful.
Mechanism of attack on financial institution employing WinSpy

Researchers have found by analysis of an attack on a U.S. financial institution Windows spyware that is also able to monitor. Android devices The institution was attacked by a spear phishing email, which had a large NSIS file as an attachment.
Once the file was opened, the recipient was a picture of a payslip to see while installed in the background. WinSpy This is commercially available Windows-spyware which makes it possible to monitor, according to the authors. Computers but also Android devices In a second attack on the institution was again used WinSpy, only the malware was now hiding in an Excel document with a macro.
Once the malware on your computer is active, the attacker can control the webcam, capture screenshots, saving keystrokes, disable security software, downloading and surfing habits chat conversations via the microphone shoot, upload and download files and send messages to the computer.

Android



During the analysis of the malware security company FireEye also discovered various Android components that can be used to monitor the victim. It involves three different applications, one of which only works when the device is connected to the Windows computer while the other two make it possible to control. Android device via SMS
Deployment Scenarios for Android Components

To install the Android spyware must be connected, then the installation takes place. On the infected computer Windows phone Through the Android spyware screenshots can be stolen and it is possible to find out. The location of the target
"These attacks and tools to confirm that we live in an age of digital surveillance and theft of intellectual property. Commercial Remote Administration Tools (RATs) continue to proliferate and are increasingly being used by attackers," said analyst Thoufique HaqHe notes that the rise of mobile platforms like Android, a new market has emerged which also asked about RATs that support these platforms.



Sunday, 9 March 2014

Hackers attacked government computer in the U.S. and E.U, said the attack came from Russia



Detailed Report


Hundreds of government computers in Europe and the USA in silence infected sophisticated malicious applications. According to Reuters, it is one of the most comprehensive programs for cyber espionage, which has so far been discovered. Some security analysts and Western intelligence agencies have concluded that this so-called spyware, known as Turla is the work of the Russian government, and that is related to software used for massive hacking U.S. military, which was unveiled in 2008.

Hackers using Spyware Turla building in the contested networks "focal points", thanks to which the computer searches for data, save your information and, where necessary data to send to their servers. 

"It's sophisticated malware, which is associated with another Russian malicious program. It uses encryption and targeting Western governments.Shows traces of Russian work, "said Jim Lewis, who previously worked in the diplomatic service for the U.S. State Department, and now works at the Center for Strategic and International Studies in Washington.


They watch them in years

Security experts warn that can not be proven truly Russian origin.
Experts from established security companies monitor turly several years. Symantec estimates that malware Turla with relatives Trojan Horse to infect Agent.BTZ thousand networks. Symantec has not communicated the names of the victims, said only that it is mostly a government computer.
Anti-virus firm F-Secure with truly met for the first time last year, when examined contested organization. "Although it looks like the Russians, there is no way to determine with certainty," said Mikko Hypponen of F-Secure. Nor did he mention the names affected.
Reuters addressed this matter in several European governments, many of them, but the malware Turla refused to comment. Government sources from the Czech Republic, Estonia, Poland and Romania, however, indicated that this malicious program were not affected immediately.

The threat of a snake


On the question of public threats in connection with this program came this week when the less well known German company G Data Antivirus published a report on the virus identified as Uroburos.
The name is derived from part of the program code and the ancient symbol that shows a snake or dragon devouring its own tail.
British company BAE Systems Applied Intelligence, formerly known as Detica, which is a cybernetic arm of a prominent British defense contractor, has issued its own report on this malware, which it describes as "a snake". The sheer sophistication of the software goes much further than what we have encountered so far, says a British document without mentioning one's responsibility for the attack.
Detail from BAE System Report is available: Here
Více na: http://e-svet.e15.cz/internet/hackeri-napadli-vladni-pocitace-v-usa-i-eu-utok-pry-prisel-z-ruska-1067660#utm_medium=selfpromo&utm_source=e15&utm_campaign=copylinkVíce na: http://e-svet.e15.cz/internet/hackeri-napadli-vladni-pocitace-v-usa-i-eu-utok-pry-prisel-z-ruska-1067660#utm_medium=selfpromo&utm_source=e15&utm_campaign=copylink