Showing posts with label Spyware News. Show all posts
Showing posts with label Spyware News. Show all posts

Saturday, 17 October 2015

Belgian Government Suspected Of Using FinFisher Spyware


The Belgian government is suspected of also using this year to have the controversial FinFisher spyware made. According to a new report published by the Canadian Citizen Lab, an organization dealing with human rights, security and IT.

The reason Citizen Lab with FinFisher concerned that some regimes used these spyware in the past, journalists and spy on law firms. FinFisher is being developed by International Gamma and consists of client software, which must be installed on the computer of a target, and server software. Via the server, which is installed on the server of the relevant government authorities, FinFisher the infected computer can be spied upon. In order to infect other computers, for example, be deployed counterfeit websites from Adobe.

Citizen Lab researchers were able to locate several of the FinFisher servers. On the basis of the IP addresses has drawn up a list of countries that are suspected FinFisher this year to have used it. As would have been operating a Belgian FinFisher server in January this year. In Europe, including Spain, Italy and the Czech Republic use the software. In total, 32 countries were identified. Last year the Belgian Government had already known that the vendor FinFisher 18,000 euros paid.

Friday, 25 September 2015

Lenovo Again Accused Of Installing Dubious Software


Computer manufacturer Lenovo is again accused of installing dubious software on laptops. Previously, the company came under fire because the Superfish spyware bundled with laptops. Later it turned out that on some models a BIOS rootkit was installed to install the software on their own computers, even though Windows is installed from a clean DVD.

This time enables IT expert Michael Horowitz Lenovo tracking software to install so-called refurbished laptops. Horowitz had two such laptops purchased directly from IBM. The computers were provided with a clean installation of Windows 7 Professional. When analyzing the software on the computer expert saw that the program "Lenovo Customer Feedback Program 64" was performed daily.

According to the description of the program will send the data every day to Lenovo. In the configuration of the software he found a DLL file named Omniture, a company that deals with web analytics and online marketing. "While there appear no additional ads in the ThinkPads, there is something to monitor and track," said Horowitz. "On the one hand, it is surprising because the machines were refurbished and sold by IBM. On the other hand, it is in view of the past of Lenovo not at all surprising."

Lenovo has made ​​a separate page put on the software online. In it, the computer giant announced that Lenovo systems include programs that can communicate with servers on the Internet. It is non-personal and non-identifying information about using the Lenovo software are sent to the company. To avoid this, users with administrative privileges, the scheduled tasks of the Lenovo Customer Feedback Program off.

Saturday, 21 March 2015

Ransomware Steals For The First Time Passwords


Researchers have for the first time discovered a ransomware variant installs simultaneously spyware to steal all kinds of passwords from the system. According to the Japanese anti-virus company Trend Micro is the first time that ransomware is bundled with spyware. However, the infection method of "CryptoWall 3.0" is equivalent to previous versions and other crypto ransomware.

Users receive an e-mail with a zip annex, which would contain a so-called CV. In reality it is a Javascript file. Once the user opens this file are downloaded two "JPG files." However, the extension is only intended to circumvent security systems.Once the files are downloaded performed by JavaScript. It is a variant of CryptoWall and Fareit spyware. CryptoWall encrypts all kinds of data on the computer and then asks for a sum of 500 euros to decrypt it.

Is not paid on time, then the user must pay 1,000 euros. While the user is thus inferred Fare it steal all types of passwords from FTP programs, browsers, email clients and bitcoin wallets says analyst Anthony Joe Melgarejo. He argues that there are several reasons why the spyware is bundled with ransomware, perhaps because people refuse to pay the ransom and thereby steal passwords is a backup plan. "

Even if the user refuses to pay would be the cyber criminals, for example via the passwords of the bitcoin wallets, still can steal money. To infections with these and other species to prevent ransomware, users advised to not open attachments from unknown senders. "In fact, they should ignore or delete e-mail from unknown senders," says Melgarejo.

Thursday, 5 February 2015

IOS Spyware Used For Cyber-Espionage


Researchers from the Japanese anti-virus company Trend Micro have discovered spyware that is designed specifically for iOS devices and is used in cyber espionage. How the spyware is distributed is unknown, but the researchers believe that used previously infected computers. Once an iPhone or iPad is connected to the infected computer, the spyware is installed.

It involves two malicious iOS applications called XAgent and Madcap, the latter is the name of a legitimate application. The XAgent app hides the icon and runs in the background. Once the process is stopped will restart the malware itself almost immediately. Once active attempts spyware text messages, address books, photos, geo-location data, processes, collect installed apps and WiFi status. Audio recordings are made as well.

It seems that the malware for iOS 7 is designed as XAgent operates here fully. In the case of iOS 8 of the spyware the icon is not hidden and the app itself does not automatically restart. If known, the spyware are used against a variety of purposes, including governments, the military, the defense industry and the media.

"The exact method of installation of this malware is unknown. We know that an iOS device jailbroken not necessarily have to be," said the researchers. XAgent example uses Apple's ad hoc provisioning, which is the default distribution method for iOS app developers. Through ad hoc provisioning malware can be installed simply by clicking on a link. The malware was found with an iOS Developer Enterprise to be signed certificate. Another possible method of infection is to connect an iPhone or iPad via USB to an infected Windows computer.

The hashes of the related files are:

05298a48e4ca6d9778b32259c8ae74527be33815
176e92e7cfc0e57be83e901c36ba17b255ba0b1b
30e4decd68808cb607c2aba4aa69fb5fdb598c64