Showing posts with label fireeye. Show all posts
Showing posts with label fireeye. Show all posts

Wednesday, 18 November 2015

FireEye: Precision Attacks Possible Thanks Analytics


Webanalytics may be used to collect online information to let go then very targeted attacks on those visitors. Such practices to gather information would be even sponsored by certain governments. Claiming security company FireEye in the report pinpointing targets.

WITCHCOVEN

According FireEye is information about visitor behavior gathered through more than 100 websites that were hacked and manipulated. Anyone who visits such a site, imperceptibly redirected to a second site where the script WITCHCOVEN in is processed.

This script collects detailed information from the user's computer and install a "super cookie" to track the visitor. The information from the computer used according FireEye for later use very targeted exploits that work on those specific configuration and software of the user.

Monday, 9 November 2015

FireEye Gives Cyber Treaty With China Debt Losses



The American security firm FireEye lost last week a quarter of the market capitalization, which according to the company is partly due to the cyber treaty between the United States and China. Both countries have recently committed themselves not to engage in industrial espionage.

This would 'threat landscape' have become smaller, which has come down in the demand for the products of FireEye.However, Wall Street analysts are skeptical, especially now that more and more companies choose to tighten their security, reports news agency Reuters. According to Eric Johnson's Owen School of Management at Vanderbilt University is therefore an excuse FireEye for more tactical and implementation problems. Also, competition from other parties would play tricks on the company.

Thursday, 5 November 2015

Thousands Of iOS Apps Discovered Backdoor


Researchers have discovered thousands of apps for iOS an ad library malicious enables users to print and listen to steal sensitive information. The problem is in different versions of the saga mobi SDK. An ad library that developers add to their app in order to generate income.

Security firm FireEye now reports that some versions of the library have backdoor functionality. It is currently unclear whether that was added by the developers of mobi saga or attackers have done this. The backdoor to the ad library offers makes it possible to record audio, take screenshots, to retrieve location data, modify files and install additional apps. For this last action, however, is user interaction required.

In total FireEye discovered in the Apple App Store over 2800 apps with the potentially backdoored versions of the saga mobi SDK. In addition, the apps tried more than 900 times in order to achieve a adSage server that would have been able to activate the back by functionality. According to the security company this is especially a problem if attackers manage to hack the servers of adSage. In that case, they can activate the backdoor functionality. Apple was informed in October, but it is unclear whether the apps in question have also been removed from the App Store.

New XcodeGhost-Malware For iOS Developers Discovered


Researchers have identified a new variant of the XcodeGhost malware discovered trying to infect iOS developers so they put infected apps in the official Apple App Store. There are more than 200 companies worldwide, which infected iOS users roam.

XcodeGhost is spread via infected versions of Xcode, Apple's official tool for developing iOS applications. Because of its size, the program is 4GB in size, some developers in China choose not Xcode via Apple's website, but can be downloaded via unofficial download sites. The Xcode on these websites provide the XcodeGhost malware. The apps that developers were thus also became infected.

After the discovery of the infected apps in the App Store, Apple decided to remove and arranged so that Chinese iOS developers can program easier downloading. Although the hit iOS developers new clean apps have provided, there are still users who continue to use the affected versions. These include to the popular chat app WeChat.

It also notes that users with infected iOS apps also walk around within companies. Security firm FireEye discovered 210 enterprises which infected apps were trying to communicate to the outside. However, most companies are located in Germany and the United States.

New version

There is also a new version of XcodeGhost discovered in unofficial versions of Xcode 7. This is the Xcode iOS version 9. In this version added new features to iOS infect 9 and bypass static detection by Apple. Also, there is one app is discovered which had become infected via the new XcodeGhost malware and ended up in the Apple App Store. It is a Chinese shopping app that also was offered in the US store. Apple has the app been removed.

Thursday, 8 October 2015

Kemoge Adware: Aggressive Android Adware Trying To Rooten Devices


There is a new instance of aggressive Android adware discovered spreading via unofficial app stores and tries to Android devices through various vulnerabilities to 'rooting'. Although for years advised by experts and security to only download apps from official app stores, there are still users who use so-called "third party" app stores.

The now discovered Kemoge-adware poses as many different apps. The makers have taken the original apps and features the adware. Then placed the packaged apps in the unofficial app stores. Once active adware makes use of eight different exploits to get onto the phone via known vulnerabilities root privileges. The app collects all kinds of information from the device and lets see ads everywhere, even on the Android home screen. The name given to the malicious Adware family is because of its command and control (C2) domain:aps.kemoge.net.


Then the adware makes contact with a command-and-control server and wait for further instructions. The server can install any apps on the infected device, uninstalling or starting. The adware is found worldwide, says security firm FireEye. To avoid infection, users advised never to click on suspicious links in emails, text messages or advertisements. No apps outside the official app store to install, and finally to keep the Android device up to date. This is to prevent malicious apps to the device via known vulnerabilities can rooting.

Wednesday, 16 September 2015

Hacked Cisco Routers Equipped With Infected Firmware



Worldwide, several hacked Cisco routers discovered that the firmware was modified so that the attackers held permanent access to the network. That leaves the US security firm FireEye know. Recently warned even though Cisco for attacks through custom firmware.

The routers are detected hacked custom firmware in Ukraine, Philippines, Mexico and India. It involves a total of 14 devices. How the attackers access to the routers were able to get is unknown, but according to FireEye is probably not using a zero day attack. "It is believed that were the default login data set or to be discovered by the attacker to install the backdoor," said the security guard. The router would be an ideal target for further attacks because of its position in the network.

Once active it can through the backdoor different modules are placed on the router. For now goes to the Cisco 1841, 2811 and 3825 routers, but FireEye warns that other models are or will be attacked. Also expects the security guard that this attack method popular among attackers will be. Because the firmware is updated, the attackers retain, maintain access to the router, even though the device will restart. In addition, to detect the custom router-firmware difficult.

Friday, 11 September 2015

FireEye Sues German Researchers Due To Bug Message


The American security firm FireEye, which recently in the news as a trainee developed malware, has now sued a German security firm for the information to be published about several vulnerabilities in the software of FireEye.

German ERNW discovered earlier this year, five vulnerabilities (pdf) in the Malware Protection System (MPS) of FireEye.Through one of the vulnerabilities could allow an attacker access to the system. ERNW FireEye inquired in April about the problems. After 90 days, the German company was planning to put an advisory on vulnerabilities out. Other companies like Google use a deadline of 90 days for information leakage is brought out.

Advisory

FireEye found that ERNW in the advisory had placed too much information on the operation of the MPS. According to the German company was necessary to better understand the context of the vulnerabilities. ERNW finally decided to remove the details right from the advisory. According Enno Rey, founder of ERNW, both companies had in August reached an agreement on the final text of the advisory. Rey was with some colleagues went to Las Vegas to discuss the situation with FireEye there in person.

Less than a day later FireEye however sent a 'cease and desist' letter, which ERNW was accused of violating intellectual property. FireEye also stated in the letter that there was no agreement between the two sides reached. Before ERNW could respond FireEye had already gone to a German court to seek an injunction, which the company received as well. This annoys Rey.

"We think it's an inappropriate strategy to complain that report vulnerabilities responsibly to researchers," as the late founder in a blog posting know. He also says that they had shaken that nothing would be published with permission FireEye hands.Rey is also very disappointed in the way the US security and argues that this sends the wrong signal to researchers. The vulnerabilities in the software of FireEye have been patched.

Thursday, 27 August 2015

Trainee Security Company FireEye Developed Malware


A trainee of the American security company FireEye has developed malware that cyber criminals Android phones infected and could control completely. It is a 20-year-old American who was arrested in July as part of an operation against the Darkode forum.

This was a great forum for cyber criminals. The American was active in this forum and sold here, along with a Dutch accomplice, his Dendroid malware. Facing a US judge the man known to be guilty and made his apologies to the victims of his malware. He also said that he would use his skills in the future to protect computer users. FireEye security company had already announced in July that the trainee was sued by the authorities.

The Dendroid malware was offered at a cost of $ 300. Once active on a machine could steal the malware files and text messages, take pictures, surf the history readout and record conversations without casualties this had passed. The American was in his own words over a year working on the development of the malware. If convicted, the men could be imprisoned up to 10 years and a fine of $ 250,000, so inform the AP and the Pittsburgh Post-Gazette. The judge will rule on December 2.

Wednesday, 12 August 2015

IE Vulnerability Used To Distribute Ransomware


A vulnerability in Internet Explorer that Microsoft only three weeks ago patched is now actively used to infect computers with ransomware. The vulnerability exists in IE6 to IE11. Visiting a malicious or hacked website or see getting an infected ad is enough for an attacker to install malware on the computer for example.

The exploit that uses the vulnerability has been developed by the creators of the Angler Exploitkit. According to security researcher ' JuK 'of the blog Malware do not need Coffee makers could possibly since July 24 with the development of the exploit have been busy, two days after the release of the update. The makers of Angler developed previously often very quickly just exploits for unpatched vulnerabilities in Adobe Flash Player. Many Internet users are slow to patch. Even though there are security updates available, there are still computers are not up-to-date and can be attacked.

Adobe

According to security firm FireEye is noteworthy that the creators of the Angler Exploitkit now suddenly focus on an IE vulnerability. In recent months, were in fact only developed exploits for Flash Player vulnerabilities, with an exploit for Microsoft Silverlight as an exception. One possible explanation, according to the security at the security measures Adobe has taken to prevent abuse of vulnerabilities.

Depending on the software installed Internet, try the Angler Exploitkit attacks through vulnerabilities in Flash Player, Silverlight and Internet Explorer. In case the attack is successful CryptoWall-ransomware is installed. This ransomware encrypts files on the computer and then asks for a fee to decrypt them.

Friday, 17 July 2015

Trainee Security Company FireEye Suspected Of Cyber Crime


A trainee of the American security company FireEye is suspected by the US government to develop and distribute Android malware. The 20-year-old man Dendroid the malware could have developed. With this malware, it is possible to infect Android devices and to control remotely. According to the indictment , the trainee would Dendroid-malware offered by the Darkode Forum, yesterday by the FBI offline was extracted.

The man is studying at Carnegie Mellon University in Pittsburgh and was twice an intern at FireEye. There he was engaged in researching Android malware. In a statement to CNN FireEye confirms that the trainee is indeed indicted by US authorities and that his training has been discontinued for the time being. There is now an investigation into the activities of the man's place. According to CNN, there are concerns that the intern has compromised software FireEye and has the knowledge and tools of the company used to commit cyber crime.

Anti-virus firms Symantec and Trend Micro warned in the past for the Dendroid malware, which attackers full access to can get an Android device. Then data from the device can be stolen and it is possible to listen in on calls and take pictures.Dendroid was for a sum of $ 300 on forums offered for cyber criminals.

Thursday, 25 June 2015

New Flash Player Flaw Attacked Through The Link In Emails


A critical vulnerability exists in Adobe Flash Player which yesterday an emergency patch released was attacked from links in emails. That informs the American security company FireEye that the zero-day vulnerability discovered and reported to Adobe.

A China-based group, according to FireEye behind the attack. The attacks were aimed at companies and organizations in different sectors, such as aerospace, defense, telecom, engineering and transport. The targets were emails sent with a link.Remarkably, there is no targeted emails were used, but messages that seemed almost on spam. "Save between $ 200-450 by purchasing an Apple Certified Refurbished iMac through this link. Refurbished iMacs come with the same one-year extendable warranty as new iMacs. Supplies are limited, but updated frequently. Do not hesitate...> Go to Sale , "the text in the message.

The link in the email pointed to a compromised server where the target was profiled via JavaScript. Once the victim was determined downloaded a malicious SWF and FLV file. Eventually this led to the installation of a backdoor. Through this backdoor received the attackers access to the system and the network of the organization was infiltrated. In announcing the emergency patch let Adobe know that IE users on Windows 7 and older and Firefox users on Windows XP were the target of the attack.

Wednesday, 24 June 2015

Emergency Patch For Active Attacked Flash Player Flaw



Adobe has a vulnerability in Flash Player that is actively used to infect computers with malware repaired via an emergency patch. According to the company involves limited, targeted attacks, where IE users on Windows 7 and older and Firefox users on Windows XP are targeted.

Through the leak, which was reported by the US security firm FireEye Adobe, an attacker can execute arbitrary code on the computer. Visiting a malicious or hacked website or see getting an infected ad is sufficient. System administrators and users are strongly advised to within 72 hours to update to Flash Player 18.0.0.194 to install.

Updating via the built-in updater and Adobe.com . In the case of Google Chrome and IE10 and IE11 on Windows 8 and Windows 8.1, the embedded Flash Player will be updated via the browser. This page shows which version is installed on the computer.

Friday, 29 May 2015

Apple Blocks Unsafe Versions Adobe Flash Player


A little later than usual, Apple released an update to block insecure versions of Adobe Flash Player on Mac OS X, however, are Windows users who certainly have to ensure that they have the latest version.Mac OS X has a "Web Plugin blocking mechanism" that Apple can update to block insecure browser plug-ins and to protect users from potential attacks.

On May 12, Adobe patched 18 vulnerabilities in Adobe Flash Player that could allow an attacker in the worst case, the underlying system could take over completely. Safari users not using the latest version of Flash Player and a site visit to see the plug-in call have since today a notification. The report says that Adobe Flash Player is outdated and there is a newer version can be downloaded from Adobe. The blockade applies to all Flash Player versions prior to 17.0.0.188 and 13.0.0.289.Apple blocks more vulnerable versions of Flash Player, but does so usually a few days after the update in question appeared.

But they are Windows users who must surely check whether they are using the most recent version, as cyber criminals have begun attacking one of the vulnerabilities that Adobe patched two weeks ago. Again, there is a trend whereby the exploit to attack the vulnerability soon after the release of the security appears. In this case it is the Angler Exploit kit which is now able to Flash users with version 17.0.0.169 and earlier attack, warns security firm FireEye . Through this page, users can see whether and which version of Flash Player is installed on their system.

Wednesday, 27 May 2015

E-mail Resumes And Internship Requests Infects Tills


Researchers have discovered a new variant of checkout malware that spreads via e-mail. The emails focus on companies and have different topics ranging from training requests and resumes, to ask if there are job vacancies. Attached is added to the e-mail a Word document. This document states that it is a secure document and the user macros must turn to see the content.

Once macros are enabled, the document will download the malware. This malware additional malware can be downloaded and installed. Through the malware that is first the attackers can determine what malware is then to be actively installed. It is then possible to install malware that targets POS systems that run on Windows. Several retail chains, especially in the US, using payment terminals that are connected to a Windows computer.

Once the computer is infected, the malware can intercept the data of credit cards and collect processed through the POS system. With the stolen payment card data can then be fraudulent. According to security firm FireEye shows that even attack cyber criminals engaged in random spam operations include cash and malware that can be used to infect some of their victims.

Sunday, 17 May 2015

Victims Ransomware In Conversation With Extortionists


Globally, still a large number of people and organizations affected by ransomware, the infection can sometimes have serious consequences for their lives and business, says FireEye. The US security was given access to the conversations between the victims and the makers of the Tesla Crypt-ransomware.

Within three months, the creators managed to extort about 67,000 euros from 163 victims, which amounts to about 410 euros per victim. There was also a victim who paid 875 euros. It turned out 13% of the victims to make the requested amount.Tesla Crypt offers an online chat functionality, the victim may ask the makers about paying via bitcoin. Therefore also the effect of ransomware on the lives of the victims clearly.


The victims were scattered around the world, students in Iran and Spain to people in the United States, Germany, Argentina, Croatia and Mongolia. Some were afraid that they would be expelled from school or dismissal by their employer if they would follow the files were not returned. Fathers and mothers were torn apart by the loss of their family photos.

Several organizations were targeted, including an organization that conducts research into blood cancers. According FireEye many of the victims are not able to pay the amount requested and then gave up. Below is a portion of the chat conversations where the security given access.

Friday, 15 May 2015

Microsoft TechNet Used To Control Infected Computers


Cyber ​​Spies have Microsoft TechNet used to control infected computers. TechNet is a Microsoft portal where IT professionals can find all kinds of information and documentation for Microsoft products. There is also a forum there for questioning.

A group of cyber spies, according to the American security company FireEye from China operated TechNet used to control infected computers. Forum topics and sections were coded IP addresses hidden. The infected computers used to connect to TechNet and were able to identify the IP address which they then had to connect.

This would make it difficult for network administrators to detect an infection or the actual location to figure out the Command & Control server who opted infected computers. FireEye notes that TechNet itself has not been hacked, but there just was placed on a public information forum. The use of well-known websites such as Twitter , Evernote and Dropbox malware is already longer.

After FireEye Microsoft and the tactics of the attackers had discovered the IP addresses in the forum topics and sections were replaced by IP addresses of American companies. In addition, the board accounts were locked so that cyber spies could not change the custom IP addresses. In this way FireEye and Microsoft could identify the victims of the spying campaign.How many organizations victim of this group were infected and how they were let security know.

Tuesday, 21 April 2015

Flash Player Vulnerabilities Ever Attacked Quickly After Patch



Vulnerabilities in Adobe Flash Player are getting faster attacked after the release of a patch, which increases the pressure on users to install available updates as soon as possible. On April 14, patched a critical vulnerability in Adobe Flash Player that could allow attackers the underlying computer in the worst case can take over completely if a malicious or hacked website is visited or appear infected ads.

Only three days later, on April 17, there appeared an exploit that allows the vulnerability abuse. The exploit was added to the Angler-exploit kit, making all kinds of cyber criminals have access. By cyber criminals exploit kits can easily Internet attacks by placing on hacked websites iframes and JavaScript, pointing to the exploit kit. In case users do not patched malware can be installed on the computer.

There has been a trend in which leaks in Flash Player, after the release of an update, still attacked quickly. On the basis of the updates, the attackers can find out where exactly is the vulnerability and develop an exploit here. A development that reveals security experts worry, says security firm FireEye . The observed now operates first look at the user's system and then determines whether a parent or Tuesday patched vulnerability to be attacked. What kind of malware is distributed via the new exploit is unknown.

Sunday, 19 April 2015

Zero-Day Vulnerabilities Attacked In Flash Player And Windows



Attackers have recent period zero-day vulnerabilities in Adobe Flash Player and Windows uses to break into organizations. The vulnerability in Flash Player has been patched , but Microsoft is still working on an update. According to security firm FireEye involves targeted attacks.

For carrying out the attack must open a link target of the attackers. Subsequently, a site loaded that leak in Flash Player used to execute code. Through the Windows Player attackers can then increase their rights on the computer. At the time of the attack were both vulnerabilities not yet been patched.

Although Windows still waiting for an update, users should install the latest Flash Player security risk no longer walk. The attack on the Windows play would effectively observed only in combination with the Flash Player leak, according to the American FireEye. In case the attack is successfully installed malware on the system that allows full access to the attackers. Who is behind the attack is unknown, but FireEye calls it "likely" that it is a Russian spy group.

Sunday, 22 March 2015

Just Patched Flash Player Flaw In sight Cybercriminals



A critical vulnerability in Flash Player that last week was patched used to attack Windows users. Through the vulnerability an attacker can place malware on your computer, for example if the user visits a malicious or hacked website or see a banner gets infected.

Report that security company FireEye and anti-virus company Malwarebytes . The exploits of the leak abuse is added to the Nuclear Exploitkit. This makes it easy for cybercriminals to attack unpatched Flash Users via the vulnerability. In the case, the attack is successful, a Trojan horse is installed there.

Although the update is available for a week does not mean that everyone who has installed, says analyst Jerome Segura."We know that in some cases, consumers, but usually companies, can not immediately install patches. In many cases, there must first be internally tested so that the patch does not disturb any business processes." The analyst advises organizations in this case to shield these systems from other systems on the network.

Wednesday, 25 February 2015

Cyber ​​Spies Often Pose As IT Staff


Cyber ​​Spies trying to break in organizations often pose as IT staff of the attacked organization. Also, they often send phishing emails that are security and seem related example of an anti-virus company originates. That reports the American security company Mandiant in a new report. 78% of targeted phishing mails which saw passing by the company were IT or security-related.

Social engineering, in which users are tricked into opening an email attachment or open a certain website, combined with unpatched vulnerabilities are also the principal way in which attackers to gain access to organizations know. Most phishing emails that were analyzed were found to be shipped on Saturday.

The report also shows that 69% of organizations affected an intrusion on the network through a third party comes to know, while 31% of the victims discovered it yourself. Average attackers would have had last year 205 days access to networks attacked before they were noticed. A decrease of 24 days compared to 2013. At one organization knew the attackers to hide even 8 years.

For passwords, hashes and certificates of compromised systems and networks to steal attackers would increasingly use the Mimikatz program, warns Mandiant. Mimikatz is freely downloadable from the Internet and according to the developer a tool to "experiment" with Windows security too. Using the tool, passwords, hashes and Kerberos tickets are retrieved from the memory. In almost all cases that were analyzed and Mimikatz was deployed the existing anti-virus software turned out not to stop the tool.