Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Monday, October 10, 2011

German hackers find government sponsored malware - R2D2

A group of German hackers say they have discovered trojan software developed by their government that can be used to spy on computer users without their knowledge.

The Chaos Computer Club (CCC) gained access to a copy of the "Bundestrojaner" (State Trojan) and found the program could be used to activate a computer's microphone or camera as well as log a user's online activity.

Since 2008 German police forces have been legally allowed to to install wiretapping software on a suspect's computer in order to monitor voice-over-IP communications through services such as Skype, but they are forbidden from accessing or installing other programs. The CCC analysis suggests the police software is capable of much more than is legally allowed.

"Our analysis revealed once again that law enforcement agencies will overstep their authority if not watched carefully. In this case functions clearly intended for breaking the law were implemented in this malware: they were meant for uploading and executing arbitrary code on the targeted system," say the CCC.

Security firm Sophos has confirmed that the trojan is able to eavesdrop on instant messaging software, log internet browser keystrokes and take screenshots of what appears on user's screens, while also attempting to communicate with a remote website.

Sophos consultant Graham Cluley also says there is no way to confirm the software was written by the German state.

Regardless of who wrote the software, it seems installing it on someone's computer leaves them wide open to any attacker.

The trojan's commands are unencrypted, making it possible for anyone to access an infected system and retrieve or upload data.

"The security level this trojan leaves the infected systems in is comparable to it setting all passwords to '1234'," says the CCC.

Tuesday, February 8, 2011

Mobile Malware threats increasing

New mobile malware threats increased 46 percent in the fourth quarter 2010, compared to a year ago, according to McAfee’s quarterly report on emerging threats.

Not surprisingly, hackers are following popular platforms e.g. email spam continues to decline as usage drops.

Only 80 percent of email traffic was spam in the fourth quarter, the lowest mark since the first quarter of 2007. I do hope it doesn't surprise you that 80 percent of all email is spam and that it's really good news.

Instead of focusing on email, cybercriminals are moving to mobile devices and platforms. McAfee notes “a steady growth in the number of threats to mobile devices.” Key targeted platforms include Android.

SymbOS/Zitmo.A and Android/Geinimi were the two headliner malware threats for mobile. Symbian remains the most targeted for malware—largely due to market share.

McAfee said:
This quarter presented some of the most interesting changes of the year. In the past three months we saw the lowest spam volumes since 2007, but at the same time we identified attacks on new devices such as smartphones using the Android operating system. Mobile malware and threats have been around for years, but we must now accept them as part of the mobile landscape, both in awareness and deployment.

Other key odds and ends from the McAfee report:
  • Auto run malware, banking Trojans and downloaders are the most favoured malware in the fourth quarter.
  • Botnets delivered via spam appear to be dormant for now, but that could change.
  • 51 percent of the top 100 daily search terms lead to malicious sites. These search engine attacks are likely to target mobile devices in 2011.
  • Adobe’s Acrobat continues to be the most favoured software to exploit.

Thursday, December 9, 2010

The Evolution of Malware - An video Interview with Eugene Kasperksy



In the latest edition of the Lab Matters video series, Ryan Naraine talks with Eugene Kaspersky about the state of the malicious Web and the evolution of malware from:-
  • intrusion; viruses and worms, through 
  • Cyber crime; botnets to
  • Cyber Warfare; Stuxnet and beyond.

Sunday, September 26, 2010

Iran Fights Malware Attacking Computers

The Iranian government agency that runs the country’s nuclear facilities, including those the West suspects are part of a weapons program, has reported that its engineers are trying to protect their facilities from a sophisticated computer worm that has infected industrial plants across Iran.

The agency, the Atomic Energy Organization, did not specify whether the worm had already infected any of its nuclear facilities, including Natanz, the underground enrichment site that for several years has been a main target of American and Israeli covert programs.

But the announcement raised suspicions, and new questions, about the origins and target of the worm, Stuxnet, which computer experts say is a far cry from common computer malware that has affected the Internet for years. A worm is a self-replicating malware computer program. A virus is malware that infects its target by attaching itself to programs or documents.

Stuxnet, which was first publicly identified several months ago, is aimed solely at industrial equipment made by Siemens that controls oil pipelines, electric utilities, nuclear facilities and other large industrial sites. While it is not clear that Iran was the main target — the infection has also been reported in Indonesia, Pakistan, India and elsewhere — a disproportionate number of computers inside Iran appear to have been struck, according to reports by computer security monitors.

Given the sophistication of the worm and its aim at specific industrial systems, many experts believe it is most probably the work of a state, rather than independent hackers. The worm is able to attack computers that are disconnected from the Internet, usually to protect them; in those cases an infected USB drive is plugged into a computer. The worm can then spread itself within a computer network, and possibly to other networks.

The semiofficial Mehr news agency in Iran on Saturday quoted Reza Taghipour, a top official of the Ministry of Communications and Information Technology, as saying that “the effect and damage of this spy worm in government systems is not serious” and that it had been “more or less” halted.

But another Iranian official, Mahmud Liai of the Ministry of Industry and Mines, was quoted as saying that 30,000 computers had been affected, and that the worm was “part of the electronic warfare against Iran.”

ISNA, another Iranian news agency, had reported Friday that officials from Iran’s atomic energy agency had been meeting in recent days to discuss how to remove the Stuxnet worm, which exploits some previously unknown weaknesses in Microsoft’s Windows software. Microsoft has said in recent days that it is fixing those vulnerabilities.

It is extraordinarily difficult to trace the source of any sophisticated computer worm, and nearly impossible to determine for certain its target.

But the Iranians have reason to suspect they are high on the target list: in the past, they have found evidence of sabotage of imported equipment, notably power supplies to run the centrifuges that are used to enrich uranium at Natanz.

The New York Times reported in 2009 that President George W. Bush had authorized new efforts, including some that were experimental, to undermine electrical systems, computer systems and other networks that serve Iran’s nuclear program, according to current and former American officials.

This also raises the question as to whether Germany and Siemens are aiding Iran in developing their nuclear capability.

Wednesday, July 28, 2010

Open source Razorback - Attacks Malware & Zero-day exploits

Sourcefire, best known for its Snort intrusion-prevention technology, Tuesday is unveiling a new open source project called Razorback that's designed to spot malware and especially zero-day exploits.

Sourcefire says Razorback is designed with a "defense routing system" that monitors for certain traffic types, such as HTTP, Web or SMTP-based e-mail, in order to forward mirrored data to any means of security analysis system that can be plugged into it.

Security tools supporting Razorback could be either open-source or proprietary.

Razorback monitoring could be integrated directly into security gateways as well as deployed on standalone servers. A typical place to put the main Razorback monitoring component would be directly behind an antivirus filtering point, according to Sourcefire, which also shepherds the open source Clam A/V toolkit. Razorback could also work with security information and event management products.

Razorback "knows the resources in the organization that might have a specific interest in files, such as PDFs, for example," which could have malicious code embedded in them, Watchinski says. Razorback-monitored PDF files could be sent to a forensics tool that could analyze them for zero-day vulnerabilities or possible exploit code.

Razorback's "defense-routing system" is not necessarily real-time and it's not yet designed to directly block suspicious data.The underlying idea of the open source project is to set up multiple paths to simultaneously transmit any mirrored data of specific security concern onward to designated security points for analysis, output and feedback to Razorback.

On a more advanced level, these third-party Razorback-supported tools, after security analysis, could in theory assist Razorback in recommendations to take protective blocking measures or update threat determinations.

Today, Razorback has been developed to work with open source Snort and Clam A/V as well as other open source code, such as Postfix.

Sourcefire has no publicly stated intention as of yet to launch a commercial product based on Razorback. The company does say the defense sector is interested in development of the kind of defense-routing system that Razorback seeks to foster through open source.

Razorback will be licensed by Sourcefire under open source GPLv2 license. In general, Sourcefire expects the code to be available for free to users and vendors -- but if Razorback is modified with the intent to sell it as a commercial product, discussion about licensing fees can be expected.

Wednesday, June 9, 2010

Malware and Trojans use YouTube to spread

Security firm eSoft has alerted web surfers about the dangers of bogus websites using the YouTube brand and format to spread malicious malware, something the company has found on more than 135,000 web pages derived from Google search results.

It appears, according to the firm’s CTO Patrick Walsh, that unsuspecting users looking for videos on recent events like the Gulf of Mexico oil spill are being directed to maliciously crafted websites with videos that appear to be identical to YouTube postings.

The so-called YouTube videos are actually phishing pages says Walsh, and they are built to look like real pages from the online video portal but are hosted on compromised sites.

In a recent Infosecurity blog posting, the eSoft CTO detailed how attempting to play these fake YouTube videos actually installs a downloader trojan with a less than 20% detection rate according to Virus Total, a website that tracks anti-virus detection rates. When the user clicks to run the video, they are instead prompted to install a codec. Of course this ‘codec’ is actually a piece of malware that allows attackers to stealthily control the user’s machine.

“By using websites like YouTube, cyber criminals are taking advantage of a users’ inherent trust in the site and are able to infect more machines”, said Walsh. “We were able to find these sites by searching for common terms like oil search video, so I think it’s fair to say that search engine poisoning was being used to drive people to these sites”.

However, Walsh added that Google appears to be doing a bang-up job in removing these infected results from search queries, as the number of malicious sites has shrunk from 135 000 two days ago to about a half dozen.

Wednesday, December 2, 2009

Caution - Fake H1N1 Alert leads to Malware Attack

Here’s a look at the fake spoofed CDC Web site being used in this attack:
Malicious hackers are using fake alerts around H1N1 (Swine Flu) vaccines to trick end users into installing malware on Windows computers, according to warnings issued by computer security firms.

The latest malware campaign begins with e-mail messages offering information regarding the H1N1 vaccination. The e-mail messages contain a link to a bogus Centers for Disease Control and Prevention site with prompts to create a user profile. During this process, a malware file gets planted on the user’s machine.

This US-CERT advisory contains some of the e-mail subject lines being used in the spam run. Some examples:
“Governmental registration program on the H1N1 vaccination”
“Your personal vaccination profile.”
According to researchers at AppRiver, the scam tricks computer users into believe they are part of a “State Wide H1N1 Vaccination Program” and are required to create a vaccination profile on the CDC website.

“The link provided in the email takes you to a very convincing looking imitation of a CDC web page where you are given a temporary ID and a link to your ‘vaccination profile’. The link is in fact…an executable file that contains a copy of a Trojan most commonly identified as xpack or Kryptik…once installed on your PC, this Trojan will create a security-free gateway on your system and will proceed to download and install additional malware without your authorization. It also enables a remote hacker to take complete control of your computer.”

AppRiver says the messages are being received at a rate of 18,000 per minute, more than one million per hour.

Friday, October 16, 2009

Malware Loses its Impact Power and Surprise Factor After 24 Hours in the Cloud

Security vendors—particularly those with Web filtering and antivirus products, boast about the exponential growth in malware. Symantec, McAfee and others say the number of malware samples detected over the last two years is approaching 3 million. Strange, that's more than all the samples of unique and variant viruses and worms detected in the last two decades.

Volume doesn't necessarily equal damage. 52% of malware lose it's power within 24 hours of being released into the wild (Cloud).

It's a surprising statistic that reflects the changing nature of malware. Many malware writers are using a malicious cloud computing model to capture valuable data. They're spreading worms and Trojans that either direct users to compromised or bogus Websites, or use a specific domain to send command and control instructions to their compromised clients.

McAfee recently reported, the volume of malware that's designed to monitor specific domains such as banks and gaming sites to stealthily steal access credentials increased more than 400 percent in 2008.

We already know that malware creators will not stick around, waiting to get caught. They're quickly moving or deactivating their controlling domains to avoid detection.

Also, carriers, hosting services and law enforcement are acting quickly to block or take down such malicious domains. The result is that those malware bots, dependent upon those malicious domains, are rendered inert within the first 24 hours. Therefore the impact power and surprise factor of malware, decreases over the next 72hours.

This is good news, right? Not always. It takes time for antivirus vendors and researchers to detect and create conventional signatures for new malware, somewhere in the order of 72 hours. This means most organisations are exposed to high infection rates and compromise, during the most dangerous time of malware infection.

The 24-hour window of vulnerability is an opportunity for solution providers to talk with customers about the benefits of adding synergistic security technologies that augment and complement traditional antivirus packages. Technologies such as data loss prevention, intrusion prevention, and Web and traffic monitoring and filtering can help detect and isolate malicious traffic and stop data loss.

Friday, September 25, 2009

Malware, Worms, Viruses - Clampi Trojan Renews Assault on Bank Accounts

Secure Channel - Malware, Worms, Viruses - Clampi Trojan Renews Assault on Bank Accounts

Sporadic reports are surfacing that the authentication credential stealing Trojan Clampi is regaining momentum and poised to begin a new round of stealthily siphoning cash from the bank accounts belonging to compromised users.

Clampi - also known as Ligats, Ilomo and Rscan - was first discovered in January 2008. The Trojan targets machines running nearly all versions of Windows and spreads as a drive-by download through Websites with compromised vulnerabilities in Flash and ActiveX. It sits in the background monitoring Web browsing activity, specifically log-ins to accounts with financial activity. Without impeding connections or PC performance, Clampi stealthily captures users' account IDs and authentication credentials and passes them to its master.

In recent months, Clampi has started spreading like a worm across networks with infected PCs. In a CNET report, SecureWorks' Joe Stewart explained that Clampi uses capture domain registration credentials to leverage the Windows SysInternals tool "psexec" to copy itself across all connected computers within a domain.

What makes Clampi different, according to published reports, is that it's monitoring a vast number of financially sensitive accounts. Banks and financial institutions are its prime target, but it's also monitoring retail sites, utilities, ad networks, government agencies, online casinos and military portals.

The threat is not contained to individual home users. The Washington Post previously reported Clampi is responsible for several large, unauthorized bank transfers. A Kentucky county lost more than $415,000 to cyber-criminals after a treasurer's PC was compromised. A Pennsylvania school district was hit to the tune of $700,000 and an auto parts store in Georgia lost $75,000, the newspaper reported.

The conventional advice for dealing with Clampi is much the same as with all malware in the wild: Update antivirus signatures, monitor inbound and outbound traffic, block traffic from suspicious or known malicious domains, and patch vulnerability applications and services. In his interview with CNET, Stewart went a step further to say that businesses should isolate PCs used for high-value activities such as managing financial transactions and that those same machines should never be used for browsing the Web or accessing e-mail.


Shared via AddThis

Saturday, August 22, 2009

Symantec and Norton Produce list of 100 Dirtiest Websites

Symantec and Norton have produced a definitive listing of 100 of the dirtiest websites i.e. the websites to avoid.

These websites are most likely to damage your PC or laptop system and /or to install viruses, Malware and Mal-bots, intended to cause major disruptions to all web users.

Click here to see the Report.....