Showing posts with label rootkit. Show all posts
Showing posts with label rootkit. Show all posts

Tuesday, 14 July 2015

Hacking Team Has BIOS Rootkit For Permanent Infection



The Italian Hacking Team has an UEFI BIOS rootkit to infect computers with spyware permanently from the company. This enables the Japanese anti-virus company Trend Micro on the basis of the data that was recently at the Italian company captured.

Hacking Team offers government agencies a "Remote Control System" (RCS) allows investigators to remotely access the computers, for example, suspects can get. To ensure that the software remains on computers even if the hard drive is formatted or replaced by a new one, Hacking Team has an UEFI BIOS rootkit developed.

The BIOS (Basic Input / Output System) and the Unified Extensible Firmware Interface (UEFI), the successor to the BIOS is a set of basic instructions for communication between the operating system and hardware. It is essential for the operation of the computer, and also the first major software that is loaded. In the case of Hacking Team involves a rootkit for UEFI BIOS, Insyde Software. The company makes BIOS software for laptops.

Physical Access

To install the rootkit do have to have physical access to the system can be obtained. According to analyst Philippe Lin Trend Micro can not be ruled out that it is also possible to remotely install the rootkit. The Italian company also developed a tool to help users of the rootkit and provides support in the event the BIOS image is not compatible. According to Lin, the rootkit can be modified so that it also works with other BIOS software, such as the well-known software vendor AMI.

To protect themselves against the attacks, users of Lin's advice to enable UEFI Secure Flash BIOS, update the BIOS if updates are available and set a password to access the BIOS or UEFI. However, it is in many computers as possible to reset the password, but in this case, a user can see that something is wrong because he forgot no longer have to specify whether his original password no longer works.

Saturday, 11 April 2015

Group bombarded SSH Servers With 300,000 Passwords



A group of cyber criminals that has been active since June last year conducts large-scale attacks against SSH servers, whereby through more than 300,000 unique passwords attempting to log in. Once access to the server is obtained finally installed a DDoS rootkit.

Through this rootkit can execute the attackers acquired server DDoS attacks. The cyber criminals by Cisco and Level 3 as "SSHPsychos" and "Group 93" indicated. The group would generate as much traffic with the login attempts that all joint attacks on SSH from other parties combined into nothing fall. The attacks appeared from different netblocks (ranges of IP addresses) to arise. In cooperation with backbone provider Level 3 was decided that the group netblocks disabling used.


As part of the process, Level 3 warned the responsible providers, which the group cybercriminals suddenly used a new network for their scans and attacks. Because of this sudden transition decided Cisco and Level 3 to remove the routing options for both the old and new netblock. According to Cisco, this will "hopefully" slow down the activities of the group for a certain time.

The networking giant notes that "detectors and protectors" can no longer sit on the side as cybercriminals in such flagrant attack systems. However, the measures affect only the part of the Internet that is provided by Level 3. Cisco calls than other parties in order to block malicious traffic from this group on the Internet. "By working together, we can eliminate a group that makes no effort to hide their malicious activities," the company said.

Thursday, 26 February 2015

Domain Lenovo.com Hijacked Through DNS Adjustment


Attackers there yesterday managed to Lenovo.com hijack the DNS of the domain name to suit . Earlier this week, the attackers used the same technique in the Vietnamese Google website. In both cases Lizard Squad behind the DNS changes, as reported OpenDNS.

The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. The DNS servers Lenovo.com and Google.com.vn change the attackers could then specify the IP addresses where the domain was pointing to. The IP address of the mail server could be modified so that emails for Lenovo.com found themselves at the attackers. In the case of Google.com.vn be the site for a Dutch IP address. Meanwhile, both websites are accessible again and the DNS changes undone.

On Twitter was the Malaysian Registrar WebNIC where both domain names are registered, then with the DNS adjustments in connection brought . IT journalist Brian Krebs reports that Webnic.cc via a command injection vulnerability has been hacked, leaving a rootkit could be uploaded. This rootkit would already have been removed. The website of WebNIC is still unreachable.

Friday, 23 January 2015

Latest Flash Attack Is Part Of Botnet Computers


A new vulnerability in Adobe Flash Player cybercriminals actively use to infect computers with malware and for which no security update is available is the ultimate goal of creating a botnet that among other things used for committing click fraud.

The zero-day vulnerability in Flash Player was wednesday afternoon reported by security researcher 'JuK. Visiting a malicious or hacked website with the latest version of Flash Player would be enough to get infected. The researcher also advised to temporarily disable Flash Player. Adobe will facing the business magazine Forbes that examines the message, but still has not announced any details.


Meanwhile, security Malwarebytes malware examined using the new Flash Player attack is installed on computers. In case the attack is successful, the computer part of the Bedep botnet. This botnet can then, by installing additional malware, use the computer for different purposes. In the case of the malware that saw the researchers concerned the click fraud.

The malware infects the explorer.exe process and let the infected computers to send any requests for ad networks, without the user does this by. According to researcher Jerome Segura are difficult to distinguish them from real traffic requests, allowing advertisers end up paying for impressions and clicks that do not originate from a human and which benefit cybercriminals.

Thursday, 6 March 2014

G Data found Russian cyber weapon - rootkit Uroburos

Uroburos RootKit Malware
Because of its complexity, Uroburos impossible to detect or destroy conventional methods 

Ouroboros - a classic antique symbol of the serpent devouring its own continuously tail. Like taking off her example, «Uroburos» - a new kind of malware which tends to absorb the network - in this case, perhaps as part of a spyware plan.





According to experts, the rootkit that steals confidential information used by hackers since 2011.

The specialists of the German company G Data found a new malicious program designed to steal confidential information. According to the data of professionals engaged in the development of malware Russian special services. Rootkit Uroburos got its name from a mythical dragon, as well as the sequence of characters within the code of the malware: Ur0bUr () sGotyOu #.

Uroburos steals files from infected computers and intercepts network traffic. A malicious program designed to work in P2P mode to establish communication between the infected systems. This feature allows you to remotely access the same computer with an Internet connection in order to control other PCs on a LAN.

It is interesting that in order to hide their activities rootkit uses two virtual file system - NTFS and FAT, which locally are on the infected machine. These file systems could allow attackers to be stored on the victim's PC party tools, tools for post-operation, temporary files, and binary output. Access to virtual file system can be accessed through the device: Device \ RawDisk1 and Device \ RawDisk2, as well as CDs \ \. \ Hd1 and \ \. \ Hd2.

G Data experts say: "The creation of such structures as Uroburos requires huge investments. The development team of this malware, obviously consists of highly qualified IT-specialists. Such a conclusion can be drawn by analyzing the structure and modern design of the rootkit. We believe that the developers are also improved versions Uroburos, which will appear in the future. "

Finding certain specifications (file name, encryption keys, behavior, etc.), representatives of the G Data suggested that a group of authors Uroburos intruders, which in 2008 carried out an attack on the computer systems of the U.S. with the help of malware Agent.BTZ.

Experts say that before installing the system on its victims Uroburos checks for the presence of Agent.BTZ. If present, the new rootkit remains inactive. Evidence that the creation of Russian Uroburos can stand is that in the code of the malware is present Cyrillic.

Recall that after the attack on the system Agent.BTZ United States banned the use of American military USB-drives and other removable media. While it was assumed that infection of the Ministry of Defence was through USB-drive.

According to statements made by G Data, the authors aim Uroburos are large enterprises, the state intelligence agencies and other organizations. Presumably, the rootkit has been used for three years, as the most long-standing version of the program were written in 2011.

Technical details SHA256: BF1CFC65B78F5222D35DC3BD2F0A87C9798BCE5A48348649DD271CE395656341 MD5: 320F4E6EE421C1616BD058E73CFEA282 Filesize: 210944

Detail from G Data Report is available: Here