Showing posts with label Threat News. Show all posts
Showing posts with label Threat News. Show all posts

Monday, 12 March 2018

McAfee: Two Botnets Behind 97 Percent Of All Spam In Q4




Two botnets accounted for 97 percent of all spam sent in the fourth quarter of last year, according to McAfee in a new report. These are the Necurs and Gamut botnets, which are rented by spammers for sending spam, phishing emails and malware.

Necurs was the most used with a share of 60 percent, followed by Gamut with 37 percent ( pdf ). According to McAfee, Necurs is currently the largest spambot network in the world. The contaminated machines that are part of the botnet are controlled via a peer-to-peer model. In the fourth quarter of last year, the Locky ransomware and Dridex bank malware were sent via Necurs, among other things. Gamut focused more on e-mails during this period to recruit money mules and phishing e-mails.

Sunday, 11 March 2018

Avast: Attackers CCleaner Also Wanted To Install keylogger



The attackers who hacked software company Piriform last year and added a backdoor to the popular CCleaner tool were also likely to install a keylogger on infected systems, according to anti-virus company Avast , which is the owner of CCleaner.

Last September, Avast announced that attackers had hacked CCleaner developer Piriform and added malware to the official version. This infected version was downloaded by 2.27 million users. The malware was added to the Piriform development platform between 11 March and 4 July 2017. The software company was acquired by Avast two weeks later on 18 July.

The first phase of the malware was to gather information about CCleaner users, such as the name of the computer, installed software and active processes. The second phase consisted of downloading additional malware. However, this was done with a select number of machines. Eventually, 40 computers received this additional malware. These included systems from major tech companies such as Intel, Samsung, Sony, Asus, NEC and the South Korean telecom provider Chunghwa Telecom.

There is no evidence that a third step has been carried out, but Avast has now found information indicating that it may have been planned. During the investigation into the hacked Piriform infrastructure, early versions of the first and second phase of the malware were discovered, as well as a tool called ShadowPad. ShadowPad is used by cyber criminals to control computers remotely. The tool was installed on four Piriform computers on April 12, while the second phase of the malware was already installed on March 12.

The older version of the second phase malware connected to a command & control server. The servers were no longer active at the time Avast analyzed the computers, so it is unknown what was downloaded, but given the time window it was probably ShadowPad. The Avast researchers also discovered ShadowPad log files with keystrokes from a keylogger installed on the computers. The keylogger had been active since 12 April and had stored keystrokes of all kinds of programs. The encountered version of ShadowPad appeared to have been specially made. Avast thinks that the attackers who had adapted especially for Piriform.

In addition to the keylogger, the attackers also installed a password builder and tools to install other software. According to Avast, there are no indications that ShadowPad is installed on the computers of CCleaner users. The virus fighter does state that it was the third phase of the attack. It is not known whether the attackers wanted to install the keylogger on all 40 attacked computers in the second phase, or just a few or not at all, this is still in under investigation.

Wednesday, 4 May 2016

Virus Crashes Medical Equipment During Heart Procedure


A medical system that monitors patients crashed during cardiac procedures because the virus carried a specified virus. Reported that the US regulator FDA. It concerns the Merge Hemo, a programmable diagnostic computer of Merge Healthcare.

The system consists of a data module and the patient Hemo-monitor computer. The two units are connected via a serial interface connected with each other. During a heart procedure, the Hemo-monitor computer lost contact with the client and Hemo was the image black. While the patient was anaesthetized, this caused a delay of five minutes because the system had to be restarted. Research showed that the virus was to perform a scheduled virus scan.

According to the FDA this may compromise the patient at risk. In the case of the incident was the heart procedure, after the system was restarted, been successfully completed. The manufacturer states in response that the hospital has not followed the instructions regarding the installation of anti-virus software. These guidelines establish how the virus must be set so that there are no consequences for treatments. As patient data and medical images must be scanned. There, according Merge Healthcare therefore no problem lie with the medical system.

Tuesday, 19 April 2016

Google: Sharp Drop In Android Malware On Google Play


The number of malicious apps in Google Play has dropped sharply last year, says Google in a new report. For the second time the Internet giant published the Android Security annual report ( pdf ). Compared to 2014 took the risk of the installation of malicious applications by 40% in 2015.

The malicious apps are divided by Google in various categories like apps that collect data, spyware, Trojans and apps to download additional software. The percentage of apps which collects data decreased by 40%, to 0.08% of all installations.Spyware decreased by 60% to 0.02% of the installations and malicious downloaders saw a 50% decrease to 0.01% of all installations. However, the category of Trojans rose from 0.01% to 0.02%. Eventually it was less than 0.15% of all Android Devices that download malicious apps from Google Play only apps installed.

About 0.5% of the devices that was downloaded from Google Play apps as well as other resources to deal with malicious apps. In addition, Google says that it also protects users download these apps from other sources. For this, use the Verify Apps. Warnings Verify apps were improved last year, which was an increase of 50% of users decided not to install the app in question after a warning. End of 2014 Android Phones got to it first with ransomware. This category of malware was according to Google last year found only outside of Google Play.

New York Police Launch Campaign Against Encryption



The police force of New York 's Manhattan along with the Attorney General and various organizations for crime victims a campaign against encryption starts. According to the initiators of the campaign "#UnlockJustice 'it is important to highlight the impact of encryption for public safety and crime victims.

"The debate over encryption is often determined by privacy and security, where there is no thought about the impact on victims," ​​said Attorney General Manhattan Cyrus Vance. "That narrow view ignores the impact of encryption for the investigation and prosecution of crimes." According to Vance all consumer must be able to be searched by investigators.

Apple and Google have, however, ensured that this is not currently the case, he said. "Congress should not allow companies to make devices that against his injunctions file. Companies should not be allowed to give criminals a place where they can go about their business. Victims of crime are entitled to greater protection than criminals."

According to Police Commissioner William Bratton undermines the existence of devices for which a court order is not the justice system applies. "This is a crisis in the making and goes beyond a single terror case. Providing shelter for pedophiles, rapists and murderers through their mobile phone affects unprecedented casualties. This exception of the judicial system is unsustainable and must be corrected immediately . "

In addition, hundreds of the initiators point for devices that can not be searched. Through the campaign, they hope to educate the public about this. The created for the campaign hashtag was quickly adopted by proponents of encryption. "People deserve better protection than criminals. Standard strong encryption protects citizens against robbers and thieves," said security expert The Grugq . Other Twitter users claim that it is a campaign of misinformation and encryption just helps in protecting data.

Friday, 12 February 2016

Ads On Skype Spreading Ransomware



Cyber Criminals have managed to show ads to Skype users who were trying to infect computers with ransomware, says anti-virus firm F-Secure. Although the ads appeared within Skype, does not mean that the browser is not open to advertising.


In the case of observed infected ads which showed the browser unnoticed load a page with the Angler-exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player to infect computers with malware. Users who had not patched their Flash Player could become so infected with the Tesla Crypt-ransomware. Like other ransomware encrypts Tesla Crypt sorts files for ransom. The ads on Skype came from the AppNexus-advertising platform, which in the past often for the spread of infectious advertisements used. Meanwhile, the offending ads are no longer displayed.

Thursday, 11 February 2016

Cyber Attack On US Tax System



One of the US IRS Tax system last month attacked by identity thieves who attempted to retrieve PINs that tax could be committed. The attacks were aimed at a web application that allows taxpayers, after entering their name, social security number, address and date of birth, their Electronic Filing (E-File) PIN to retrieve.

This PIN can then be used to apply for the tax refund. The identity thieves used the information to other parties was stolen to retrieve the PIN. In total, with 464,000 unique social security numbers tried to grab the code, which was successful at 101 000 social security numbers. According to the IRS , there was an automated attack. The Tax Administration claims that no taxpayers' data through IRS systems are won. In addition, the IRS will notify all individuals whose data were stolen by other parties.

Microsoft Will Now Provides More Information About Windows 10 Updates



Microsoft will now provide more information about updates for Windows 10. The reason is the customer feedback, so let a spokesman opposite Follower Windows Paul Thurrott know. "To make it easy to create organizations and users to view information on new releases, we have two new pages created will be updated alls changes occur," says Microsoft's Michael Niehaus on a Microsoft blog.

The first page contains the " release notes ". It is in this case to details on every new Windows 10 update, singling out both security- and non-security-related fixes. In addition, a " release information page " with information about current releases as well as a list of all updates that have appeared. Microsoft had to endure a lot of criticism since it first little information about Windows 10 updates, so users do not know what the update did exactly.

Monday, 26 October 2015

Test: How Safe Are Scanners Anyway?


Virus scanners should work against all kinds of malware and other threats, providing protection, but what is it really the security situation of this kind of security suites? That question decided the German test lab AV-Test to answer by looking at both business and consumer products.

Security software should not only be able to detect threats, but also the software required to take security measures in order not to be attacked or make it more difficult for an attacker. Various techniques are available, such as ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention). Anti-virus companies have to add this technology to their own software.

Of the 21 tested products for consumers were found six full DEP and ASLR use, namely Avira, BullGuard, ESET, Kaspersky, McAfee and Symantec. Quick Heal, Norman and K7 do so at less than 30% of stocks. Corporate products outperformed, whereby three of 10 scored the maximum 100%, namely two products and one of Kaspersky from Symantec. 8 products were thereby above 90%. Only Bitdefender (79.7%) and Seqrite (29.8%) scored lower.

Certifications

Looked or all files of the security suites can be digitally signed and whether there was a valid digital certificate used for the second part of the test. Ant-virus companies require other software developers to sign their files digitally, which helps in the detection of malware, says AV-Test. In addition, a virus must be able to monitor their own authenticity and integrity, which help digital signatures with valid certificates and hash values.

Among business products showed that possessed 50% of unsigned files. In consumer products it was 60%. According to AV-Test, the results show that some anti-virus companies to be still awake. On the other hand, there are also companies that have taken steps since last year, the last test. "But many have done absolutely nothing," said the German test lab.

Friday, 16 October 2015

Company Claims Nearly 1,000 New Mac Malware In 2015


An American security company claims it has this year found nearly 1,000 instances of malware for Mac OS X, five times as many as in 2010, 2011, 2012, 2013 and 2014 combined. However, the report from Bit9 and Carbon Black does not know what malware is involved.

Also not reported how it is contracted, how widespread the malware found and whether for instance, there are trails. As a result, it is unclear how large the actual threat is now. The study (pdf) researchers from Bit9 and Carbon Black gathered for a period of 10 weeks in all sorts of places malware specimens, such as blacklists, Cont Agio malware dump, open source and security incidents. In total more than 1400 unique OS X malware specimens were found. 180 examples date from 2010 to 2014. 948 copies were for the first time this year have appeared.

"The number of copies in this analysis is large enough that even the most optimistic Mac OS X user realizes that security is now of paramount importance," said the researchers. They expect the number of Mac malware attacks will increase in the coming months. How that will take place just is not reported. Recently, anti-virus firm BitDefender said that nearly half of all Mac malware is actually adware.

Mac users run mainly via adware bundled software, for example through pop-ups and ads on websites that say that something is wrong may be using the computer or the performance improved. Bitdefender recommends Mac users also to be selective about which programs they download and install. It is also advised to only download apps from the official Mac App Store. Researchers at Carbon Black advised Mac users to install a virus scanner, with free alternatives to Avast, Malwarebytes, and Sophos highlights. Users who wonder if they are infected may be advised the Dynamic Hijack Scanner or Knock Knock use.

Tuesday, 13 October 2015

Anti-Virus Company: Nearly Half Of Mac Threats Consist Of Adware


Almost half of the threats for Mac OS X falls into the category of adware, says the Romanian antivirus company BitDefender on the basis of its own research. The virus fighter analyzed the Mac malware that appeared in the first six months of this year.

Of all Mac malware found in the United States showed 46% can be classified as adware. In Germany, Denmark and Romania was about 45%, 61% and 58% respectively. However, no absolute numbers, so it is unclear how many copies are involved. Once active adware can display unwanted pop-ups and ads and adjust search results.

Mac users run mainly via adware bundled software, for example through pop-ups and ads on websites that say that something is wrong may be using the computer or the performance improved. Bitdefender recommends Mac users also to be selective about which programs they download and install. It is also advised to read the terms and conditions of the software, install a AdBlocker and Mac OS X to keep up-to-date. Earlier it was even called that adware is the main threat for Mac users.

Wednesday, 7 October 2015

Cisco Disrupts Extensive Network Of Cyber Criminals


Network manufacturer Cisco has disrupted an extensive exploit kit network that criminals tried to infect surfers with ransomware and other malware. How many people have been victimized and how many criminals have earned the ransomware is unknown.

The action was directed against the Cisco Angler-exploitkit, used by cyber criminals to infect Internet users via vulnerabilities in Adobe Flash Player, Silverlight and Internet Explorer with malware. Cisco researchers discovered that the Angler-exploitkit used a large number of proxy servers, which were located primarily in the provider Limestone Networks. The study showed that the Angler-exploitkit one party was used extensively. This party was for 50% of all activity of the Angler exploit responsible and tried every day 90,000 people to infect via the aforementioned vulnerabilities.

Infections can only occur when users are using vulnerable software, for example, because they have no security updates have been installed. By working with Limestone was extensive information about the Angler-exploitkit are collected.Eventually all hosting providers where the proxy servers were informed, who then Switch off servers. Therefore, the cyber criminals had no access to the Angler-exploitkit.

Juggling With Figures

Cisco sets the announcement about the operation that cyber criminals through the exploitkit $ 60 million per year earned by ransomware. It is important to mention that this is an assumption and not a fixed amount. There is no hard evidence how many criminals have earned through their ransomware. The estimate of Cisco is based on several assumptions. For example, pointed to previous research showing that 40% of Internet users being attacked via the Angler-exploitkit also touches actually infected.

Further, it would be installed in 62% of infections via Angler ransomware. In addition, the average ransomware amount would be $ 300. According to figures from Symantec would actually pay 2.9% of the victims. Because all that matters to multiply with each Cisco eventually comes to an amount of 60 million dollars. As stated, this is an unconfirmed amount based on certain assumptions.

Thus, researchers from Dell SecureWorks to 0.4% of the ransomware victims pay the demanded ransom. Other studies a percentage of 0.27% to the front. If Cisco with these percentages, the amount would have expected would be much lower outage, which includes fluctuations in the number of successful infections and the number of ransomware installations.

Apple: YiSpecter-Malware Only Works On Old iOS Versions


The YiSpecter malware that security company Palo Alto Networks warned only works on older iOS versions, and only if users themselves downloading malware from untrusted sources, says Apple. The malware is mainly active in China and Taiwan, but the number of infections is unknown.

To spread the malware uses different methods, but a user action is still required to download and install the malware. In a statement to The Loop, Apple says that the problem affects only users of older iOS versions of the malware itself from unreliable sources have downloaded. The specific problem could be resolved in iOS 8.4. This version was published on June 30 of this year.

In addition, Apple has the apps that were used to block the spread of malware. Apple recommends that iPhone owners to install the latest version of iOS apps only from trusted sources such as downloading the App Store. Also, users should be careful when they get warnings when downloading apps.

Monday, 5 October 2015

Amount Of Mac Malware Is Still Very Limited


All years warn anti-virus companies for Mac malware, but the number of copies that attacks Apple users is still very limited. According to a survey from security company Webroot. Every year appear as two new threats for the Mac.

Often these Trojans posing as an application but in fact malware. The most successful Mac malware was hitherto Flashback, which first appeared in 2011 and in 2012, infecting some 700,000 Macs knew. In recent years, such large infections failed to materialize and in 2015, according to Webroot's still not a big threat appeared for the Mac. According to some experts, adware also the biggest threat for Mac users.

Despite the small number of copies Webroot provides in its own overview Mac malware according to the security firm is indeed a serious threat that will only get bigger. "Even after mentioning all these malware will be people who refuse to believe that their Mac is vulnerable to attack, but trust me. It will now only get worse. Apple increases its market share and thus come opportunities for malware authors to make money, "said analyst Devin Byrd.

According to some experts, is the threat especially in user behavior. Macs could become infected mainly because software users outside the site of the supplier or downloading illegal software use. Recently left the Austrian test lab for anti-virus programs AV-Comparatives know which experienced Mac users also can do without virus.

Saturday, 12 September 2015

American Systems Department 159 Hacked



From 2010 to 2014, the systems of the US Department of Energy hacked 159 times, according to government documents (pdf) by USA Today were retrieved. In total, the Department received during the four years to 1131 attacks, mostly malware.

Of these, 1131 attacks there were 159 successful. It seems to go both computers officials as servers. Sometimes a successful attack as a "compromise - root (intrusion successfull)" specified, while for other attacks "compromise - user (intrusion successfull)" is used. For what exactly will the systems and attacks is not mentioned in the document. Also not mentioned whether and what information the attackers managed to steal through the systems.

It also showed that the National Nuclear Security Administration, a semi autonomous government service within the Ministry of Energy and responsible for the management and protection of the American nuclear weapons had to make during the four years with 19 successful attacks. Also in this case, absence details about the attack and attacked systems. In 2013 there was an attack on the Ministry place where servers and workstations were hacked. Last year an audit report of the Inspector General, which found that 41 servers and 14 workstations of the Ministry default or easily guessed passwords used.

Wednesday, 2 September 2015

Victim Phone Scam For 7000 Euro Scammed



Britain is a victim of a phone scam for 7000 euro defrauded, according to what that person comes from a data leak which last year took place at his former provider. In December 2014 it was announced that attackers a database of UK ISP TalkTalk had been hacked.

In addition, the data of millions of customers were captured, including name and phone number. Because of connection problems, the victim decided in May this year to another provider to switch. Not much later, the victim was called by someone posing as TalkTalk employee. He stated that there were problems with some routers and computers. The "employee" then sought to gain remote access to the computer, which the victim downloaded a file.

After the so-called employee had taken over control of the computer, there finally appeared a message on the screen that the user had rights to 270 euros. Via internet banking showed the "employee" that the money was transferred. Instead of 270 euro, however, was paid 7,000 euros. Then asked the "employee" or the excess amount transferred could be returned via Money Gram or he would lose his job. The victim did. Only later it turned out that the 7000 euro of the savings account was transferred to the bank account of the victim and there was a scam.

According to the victim, there is evidence that his computer was monitored from December. TalkTalk will however not cover the damage. The victim then approached the Guardian, but the British newspaper reports that there is no chance of damages. TalkTalk states in a reaction that a small number of clients using the stolen data has been approached by phone scammers. However, the provider says that the customer's own website for scam alerts.

Friday, 24 July 2015

AV Comparatives Test Lab: Experienced Mac User To A Virus Scanner


Experienced Mac users can watch what they download a virus scanner, according to the Austrian test lab AV-Comparatives . The test lab decided to test ten virus for Mac OS X on the detection of malware. In addition, specimens were taken for both Mac and Windows, because the Mac virus indicate that they can also detect Windows malware.

The reason is that Mac computers can also get in touch with Windows malware, for example in the case of e-mail attachments or USB sticks. What is striking about the test, the amount of malware which has been tested. In the case of Mac malware is about 105 newly discovered specimens, while the most prevalent malware specimens were used for Windows. In other tests of AV-Comparatives for Windows be used thousands of malware examples, but the number for Mac is so low that the counter remains stabbing at 105.

Of the ten scanners able to detect seven parcels 100% of all Mac malware, while a similar number this occurs in the Windows malware. Avast, AVG, ESET, Kaspersky and Sophos are the scanners that detect all malware in both areas. When it comes to Windows malware are the only F-Secure (28%) and Intego (50%) who stabbing drop in the detection of Windows malware.Meanwhile, all the anti-virus companies have their signatures updated to missed malware are detected.

The question remains whether Mac users now need a virus scanner. "Experienced and responsible Mac users to be careful with the programs they install and where they get which can reasonably argue that they do not risk running Mac malware," said AV-Comparatives. The lab says that users who are not experts, children and users with regular software experiment there can take advantage of to use a Mac virus scanner.

Wednesday, 24 June 2015

FBI Warns CryptoWall-Ransomware



Both consumers and businesses in the last year lost millions because they were victims of CryptoWall-ransomware, reason for the FBI to issue a warning. CryptoWall a ransomware variant that encrypts files for ransom.

According to the US, it is the most active investigation service ransomware threat in the United States. In addition, the damage is often greater than the demanded ransom, which is between $ 200 and $ 10,000. Many victims would be faced with additional costs due to network security, taking countermeasures, productivity loss, legal fees, IT assistance and arranging credit monitoring for employees and customers.

Between April 2014 and June 2015, the FBI received 992 complaints about CryptoWall, in which victims indicated that they had lost more than $ 18 million. To avoid infection by ransomware advises the FBI to use a virus scanner and firewall, install pop-up blockers, making backups and to be skeptical. "Do not click on e-mails or attachments you do not recognize and avoid suspicious websites." The latter recommendation, however, does not account for the large number of hacked websites and infected ads on legitimate websites that cyber criminals use ransomware to spread.

Saturday, 20 June 2015

Research: Botnets Consist Of Average 1700 Computers



In the first quarter of this year were from botnets average 1700 computers, claims ISP Level 3 on the basis of own research ( pdf ). For the study 600 to 1000 Command & Control servers were monitored allow cyber criminals to control infected computers.

The number of computers part of a botnet accounted fluctuated considerably in the first months of this year. So it went in January to an average of 3,763 computers, but this was dropped in March to 338 computers. According to Level 3 is due to the decline in the "vigilance" by the security community. Computers that are part of a botnet are found mainly in China and the United States, each with more than half a million infected machines, followed by Norway with 213,000 "zombies."

Norway was in the first quarter, also the target of the most botnet traffic, followed by the US and Spain. The presence of Norway is explained by a single incident where a botnet server was hosted within a specific hosting environment.

Netherlands

The report also mentioned several times Netherlands. For example, the Netherlands is in fourth place worldwide in countries that generate botnet traffic and in third place in Europe. "From a global perspective, the Netherlands is higher in relation to other European countries. The top 10 listing is primarily due to a large and heavy port scanner which made a number of victims in the Nordic region," says the report. It is further stated that the Netherlands provides a "robust infrastructure," making it "ideal" is to centralize botnets in the region.

Friday, 19 June 2015

Criminals Steal $ 1.5 Million Over Hacked E-mail Account



Criminals have managed to steal last month $ 1.5 million from the Swedish publisher Bonnier Publications and media group, after they had hacked the email account of then-CEO, as the new CEO in front of the New York Post announced.

It is the well-known e-mail scam that allows companies worldwide last year for 226 million dollars were scammed.Scammers send out whether accounts hacked e-mails to the finance department with payment instructions from the CEO or CFO seem to originate. In the case of Bonnier Publications e-mail account of the CEO was hacked, but exactly how this occurred was not disclosed. Then the criminals sent payment instructions to an employee of the publishing house to make about $ 3 million.

The payment was made through two transactions of $ 1.5 million. The second tans action could be stopped before the money had ended up in a Chinese bank. The employee decided to call the CEO to confirm the transaction. The first transaction however, could not be reversed and according to the publisher the Chinese banking authorities are not very helpful in identifying the account holder.