Wednesday, 14 March 2018

Privacy OS Tails Introduces Screen Lock


A new version of the privacy-oriented operating system Tails has been released that now also offers users the possibility to lock their screen. When users have set an administrator password, they can unlock the screen.

Otherwise, a separate password can be set for the first time the screen is locked. Furthermore, Tails 3.6 contains various upgrades, security updates and other adjustments. Tails stands for The Amnesic Incognito Live System and is a fully Linux-based operating system that contains all kinds of tools to anonymously use the internet. It can be used from a DVD or USB stick and is recommended by various civil rights movements and privacy experts. Some 22,000 people use Tails every day.

Monday, 12 March 2018

Android Manufacturer: Included Malware Is False Alarm



The Chinese manufacturer of Android devices Leagoo has removed to anti-virus company Doctor Web, which claimed that the manufacturer supplied devices with malware. The virus fighter claimed that it had found the Triada Trojan in the firmware of more than 40 models , including that of Leagoo.

The malware, which can download and execute additional malware and apps, without users knowing this, turned out to be present in a custom Android system library. This system library is used by all Android apps, which means that the malicious code is present in the memory of all running apps. According to Doctor Web, the malware was added at the request of a Leagoo partner and the manufacturer made this request.

Leagoo says in a statement that it is a false alarm. "The problem with the" virus warning "on Leagoo phones is mainly caused by differences in the virus detection of Chinese and foreign anti-virus software", according to the manufacturer. Leagoo states that all phones are scanned for malware by "top Chinese anti-virus software" to ensure that all devices are virus-free. In the future, Leagoo will also use "foreign algorithms" during scanning to prevent new virus warnings.

Recent Adobe Flash Player Vulnerability Leak Attacked Via Exploit Kits



A recently patched vulnerability in Adobe Flash Player is being actively attacked via exploit kits. This means that visiting a hacked website or seeing infected ads with a vulnerable Flash Player version is sufficient to infect with malware.

The vulnerability in question was resolved by Adobe on February 6 through an emergency patch . The vulnerability appeared to have been targeted against South Korean organizations since last November . Here Excel and Word files with embedded Flash objects were used. Now it appears that cyber criminals also have the exploit to use them via the web.

Flash Player was and still is the most popular target for exploit kits. Due to the absence of new exploits, and the fact that more and more browsers are phasing out the support of Flash Player, the effectiveness of exploit kits has declined sharply in the past period . According to researcher Kaffeine of the Malware do not need coffee blog , this is the first new Flash exploit that has been added to an exploit kit since July 2016 for a Flash leak. The new Flash exploit will be deployed via infected ads and will successfully install the Hermes ransomware. Users are therefore advised to upgrade to Flash Player version 28.0.0.161 or later, as the vulnerability has been corrected.

McAfee: Two Botnets Behind 97 Percent Of All Spam In Q4




Two botnets accounted for 97 percent of all spam sent in the fourth quarter of last year, according to McAfee in a new report. These are the Necurs and Gamut botnets, which are rented by spammers for sending spam, phishing emails and malware.

Necurs was the most used with a share of 60 percent, followed by Gamut with 37 percent ( pdf ). According to McAfee, Necurs is currently the largest spambot network in the world. The contaminated machines that are part of the botnet are controlled via a peer-to-peer model. In the fourth quarter of last year, the Locky ransomware and Dridex bank malware were sent via Necurs, among other things. Gamut focused more on e-mails during this period to recruit money mules and phishing e-mails.

Sunday, 11 March 2018

Popular Privacy Plug-In Ghostery Made Open Source



The German software company Cliqz, owner of the popular privacy plug-in Ghostery , has decided to make the tool open source. Ghostery blocks ads and trackers and has millions of users. A year ago Ghostery was taken over by Cliqz .

In the interests of transparency and an open internet, Cliqz has made the choice to make Ghostery open source. By looking at the source code, users can see how Ghostery works and what kind of data it collects. In addition, other developers can now contribute to the privacy plug-in. "Only when people understand what data digital products collect can they make meaningful decisions about what information they want to share and with whom," says Jeremy Tillman , Ghostery's product director.

According to Cliqz, most Ghostery users share stats with which new trackers are found. The software company emphasizes that it is anonymous statistics that also assess the relevance and safety of websites. However, it is also possible to set Ghostery so that no data is shared. The source code of Ghostery can be found on GitHub .

Leaked Source Code Ammyy Admin Uses For Malware



Source code of the remote desktop software Ammyy Admin has been used for malware that has been used for both targeted and large-scale attacks, according to security firm Proofpoint. Ammyy Admin is a program that allows remote access to computers.

Some time ago the source code of Ammyy Admin version 3 appeared on the Internet and cyber criminals have used it to develop malware called "FlawedAmmyy". This malicious version has been used in attacks since the beginning of 2016, but only recently discovered, Proofpoint says. Among other things, the automotive industry would be the target of the attacks.

To spread the malware, the attackers use e-mails that contain Word or ZIP files as an attachment. The Word files have a malicious macro that, when enabled by the user, downloads the malware on the system. Once active on a system, FlawedAmmyy can be used to steal trade secrets, customer data and other information from companies, according to the researchers.

Avast: Attackers CCleaner Also Wanted To Install keylogger



The attackers who hacked software company Piriform last year and added a backdoor to the popular CCleaner tool were also likely to install a keylogger on infected systems, according to anti-virus company Avast , which is the owner of CCleaner.

Last September, Avast announced that attackers had hacked CCleaner developer Piriform and added malware to the official version. This infected version was downloaded by 2.27 million users. The malware was added to the Piriform development platform between 11 March and 4 July 2017. The software company was acquired by Avast two weeks later on 18 July.

The first phase of the malware was to gather information about CCleaner users, such as the name of the computer, installed software and active processes. The second phase consisted of downloading additional malware. However, this was done with a select number of machines. Eventually, 40 computers received this additional malware. These included systems from major tech companies such as Intel, Samsung, Sony, Asus, NEC and the South Korean telecom provider Chunghwa Telecom.

There is no evidence that a third step has been carried out, but Avast has now found information indicating that it may have been planned. During the investigation into the hacked Piriform infrastructure, early versions of the first and second phase of the malware were discovered, as well as a tool called ShadowPad. ShadowPad is used by cyber criminals to control computers remotely. The tool was installed on four Piriform computers on April 12, while the second phase of the malware was already installed on March 12.

The older version of the second phase malware connected to a command & control server. The servers were no longer active at the time Avast analyzed the computers, so it is unknown what was downloaded, but given the time window it was probably ShadowPad. The Avast researchers also discovered ShadowPad log files with keystrokes from a keylogger installed on the computers. The keylogger had been active since 12 April and had stored keystrokes of all kinds of programs. The encountered version of ShadowPad appeared to have been specially made. Avast thinks that the attackers who had adapted especially for Piriform.

In addition to the keylogger, the attackers also installed a password builder and tools to install other software. According to Avast, there are no indications that ShadowPad is installed on the computers of CCleaner users. The virus fighter does state that it was the third phase of the attack. It is not known whether the attackers wanted to install the keylogger on all 40 attacked computers in the second phase, or just a few or not at all, this is still in under investigation.

Wednesday, 28 February 2018

Decrease Of Malicious Advertisements In The Second Half Of 2017



The number of malicious advertisements that Internet users tried to infect with malware, tried to deprive data or attempted to defame it in another way, was reduced in the second half of 2017, security company RiskIQ claims. In the third quarter, the security company detected 53 percent less malvertising than in the second quarter of 2017. In the fourth quarter, this decline continued and 10 percent fewer malicious ads were detected.


The use of advertisements to attack unpatched internet users, for example through vulnerabilities in Adobe Reader or Internet Explorer, decreased by 36 percent in the third quarter and 20 percent in the fourth quarter. Other malware in ads decreased by as much as 67 percent in the fourth quarter. The fourth quarter, however, saw an increase of 16 percent in the number of ads pointing to a scam, but overall there were fewer rogue ads in both the third and fourth quarters.

Coinhive Code Injected On LA Times Website


The website of the American newspaper the LA Times has unknowingly implemented Coinhive code in order to minate Monero's. The code has certainly been on an interactive map of the newspaper about murders in cities since 9 February , researchers from Bad Packet's report have discovered. The code let the CPU run just below 30 percent of its power to remain unnoticed, writes John Dunn from security company Sophos .

The code has been injected via a poorly secured Amazon AWS S3 bucket. This S3 bucket offered visitors write permissions. The researchers also found a message that suggested that someone else had access, in addition to the Bad Packet Report researchers and the cryptojackers themselves. The message was as follows:

Hello, this is a friendly warning that your Amazon AWS S3 bucket settings are wrong.
Anyone can write to this bucket. Please fix this before a bad guy finds it.

After the researchers informed the newspaper about the incident, the code was cleaned up and the cloud environment better secured. Coinhive has also lifted the account that was linked to the code. The researchers suspect that approximately 24 dollars of crypto currencies have been generated.

Veil System: Researchers Make Private Browsing More Private


All modern browsers now have private browsing, a function that ensures that the surfing behavior is not stored on the computer. However, the information that is accessed during private browsing can still be retrieved from the computer by a motivated attacker. Reason for researchers from MIT and Harvard to develop a new system called Veil that should make private browsing more private.

Browsers should delete all stored data after closing a private browsing session. However, modern memory management is complex and can ensure that data is left in the memory somewhere. Veil tries to tackle this problem by encrypting all data that the browser loads into memory until it is displayed on the screen.

The use of Veil

To use Veil, the Veil user goes to the Veil website and enters the url of a website. A special "blinding server" then sends a version of the requested page in the Veil format. The Veil page is similar to a normal web page, but contains code that executes a decryption algorithm. The data on the page is unreadable until it is decrypted by the algorithm. Once the data has been decrypted, it must be loaded into the computer's memory to be displayed on the screen. This temporarily stored data should be much harder to trace when the browsing session is over.

In order not to give attackers a chance, Veil takes an additional security measure. The blinding server adds meaningless code to every loaded page. This code has no effect on how the page before the user looks, but does change the underlying source file. Every page that is loaded by a blinding server, even if it is the same page, looks different. An attacker who manages to obtain part of the decrypted code after closing a Veil session is therefore unlikely to say which website the user visited.

When these measures are not enough, Veil also offers the option to have the blinding server take a picture of the requested page. In this case, the blinding server opens the requested page, makes a screenshot of it and sends it to the user. This prevents executable code from ending up on the user's system. If the user then clicks on the image somewhere, the browser registers this and sends the new request to the blinding server, which then loads a new zoomed image and sends it back to the user.In order to use the system, websites do have to create a Veil version of their website, but the researchers have developed a compiler for this that automatically performs the conversion. A bigger challenge is hosting the blinding servers, which can be done by volunteers, as is the case with the Tor network, or by companies that, for example, want to offer their visitors more privacy. No adjustments to the browser are required for the implementation of Veil.

Researchers Warn Of Android Malware RedDrop



Security researchers warn of a new type of malware for Android phones called RedDrop. Hackers can not only steal a lot of information from the infected smartphone, sounds can be recorded and photos can be taken and Premium SMS messages can be sent.

Security company Wandera has researched the new malware and observes that RedDrop is now nestled in at least 53 Android apps. When such an infected app is opened, at least seven new APKs are installed in the background, each with malicious functions.


With the help of spyware, all kinds of information about the user is collected and then sent to a Dropbox account of the attacker. The data collected includes local files, such as photos, live sound recordings, device and SIM information (IMEI, IMSI, MNC, MCC) and information from the application and Wi-Fi networks in the area.

Also, if a user uses the infected app, a text message is sent to a payment service in the background, which is immediately removed to prevent discovery.

The creators of RedDrop use a content distribution network with more than 4000 domain names to distribute the malware. The researchers suspect that a lot is referred to domains to hide the source of the malware as well as possible.

Malware Infection Chain:



According to Michael Covington, VP Product Strategy at Wandera, this is very sophisticated malware . "The criminals very cleverly offer a seemingly handy app that performs all sorts of complex malicious activities in the background. The attacker not only uses a wide range of malicious applications to tempt the victim, they have also perfected every little detail to ensure that their actions are difficult to trace. This is one of the more persistent malware variants we've seen. "

Decrypting Tool For GandCrab Ransomware Available



Victims of the GandCrab ransomware can regain access to their encrypted files. The decrypting tool for GandCrab was made available today on the site nomoreransom.org by the Romanian police in cooperation with Bitdefender and the European police organization Europol.

GandCrab has been observed in the wild for about a month and has now made more than 50,000 victims worldwide, including many Europeans. It is therefore one of the most aggressive forms of ransomware this year, according to Europol .

GandCrab spreads via manipulated advertisements on websites and via fake invoices that are sent as attachments by e-mail. When the malware is installed, the files on the victim's computer are encrypted and an amount of 300 to 500 dollars in ransom is demanded, to be paid in the virtual currency DASH.

As far as we know, GandCrab is the first ransomware copy that requires payment in DASH. GandCrab also has an affiliate program where the ransomware is offered as a service (ransomware-as-a-service) and the developers receive a commission for each ransom payment received.