Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Saturday, 10 September 2011

Cybercrooks prey on 9/11 anniversary

Malware, 'commemorative coin' auctions and fake charity donation



Cybercrooks are gearing up for the 10th anniversary of the 9/11 attacks with a range of malware traps and hacking attempts both on social networks and the wider internet, net security firm BitDefender warns.

The first wave of these attacks comes in the form of the newly established websites offering supposed content such as "Bin Laden alive", "in depth details about the terrorist attack", "police investigation results" and "towers going down" to attract the curious.
The sites are filed with links to scareware and phishing sites. Others have created fraudulent charity donation sites that serve only to line their greedy pockets at the expense of genuine gift-giving sites.

In addition, fraudsters are running fake auctions and sales of items supposedly linked to the devastating attacks such as shards of metal from the twin tower or even "commemorative coins" supposedly minted from silver collected at the attack site.

More scam, perhaps involving malware, can be expected to follow over the coming days.

“Because of the advancement of hacking and spamming technology over the past decade, plus the significance of the anniversary and increased media coverage, Sept 11 this year may prove hectic on the malware front,” said Catalin Cosoi, head of the Online Threats Lab at Bitdefender.

BitDefender says many of the scams likely to be on show are similar to those seen during anniversaries of the London bombings of July 2005.

Cybercrooks marked remembrances of the 7/7 attacks with fake donation requests, spamming of viruses disguised as supposed videos of the assaults and advanced fee fraud email scams. ®

[TheRegister]

People Who Get Malware Also Get Mugged More Than Usual


Our Lifehacker AU comrades point out this interesting fact from Norton's latest Cybercrime report: People who fall victim to malware are statistically more likely to be mugged in real life too. Interesting.
The obvious caveat is that correlation doesn't imply causation, but it is a bit telling to see that these two statistics are linked. Could it be that people who aren't careful online—because honestly, that's what falling victim to malware is—aren't careful in meatspace either?
Norton's internet safety advocate agrees, and says "Clearly these people aren't taking enough care in their real-world interactions and it carries over in their online world." Just think about people you know and how careful they are in their everyday dealings with other people. The more guarded or suspicious you are, the less likely you are to hand over your personal information to a shady site or click a link or open an attachment you're not sure about.
Norton Cybercrime Report (PDF) via [Lifehacker]

Sunday, 20 March 2011

A Good Decade for Cyber Crime

Cybercrime is one of the most successful and lucrative industries of our time, growing by double digits year after year.

Over the last decade, cyber crooks have developed new and sophisticated ways to prey on an explosion of Internet users, with little danger of being caught.

Meanwhile, consumers face greater risks to their money and information each year.

A few famous exploits illustrate different eras of cybercrime:


“I Love You” worm’s false affection: $15 billion estimated damage
Emails with the subject line “I love you” proved irresistible in 2000. Millions of users downloaded the attached file, which was supposedly a love letter but was actually a virus. This infamous worm cost companies and government agencies $15 billion.


MyDoom’s mass infection: $38 billion estimated damage

This fast-moving worm, which first struck in 2004, tops McAfee’s list in terms of monetary damage. It delivered enough spam to slow global Internet access by 10% and reduce access to some websites by 50%, costing billions of dollars in lost productivity and online sales.


Conficker’s stealthy destruction: $9.1 billion estimated damage

This 2008 worm infected millions of computers. It went a step further than the other two worms on our list, downloading and installing a variety of malware that gave hackers remote control over victims’ PCs.
Some of the most common and nefarious scams include:


Fake antivirus software

Selling fake antivirus software is one of the most insidious and successful scams in recent years.
Cyber criminals play on users’ fears that their computers and information are at risk, displaying misleading pop-ups that prompt the victim to purchase antivirus software to fix the problem.
When victims enter their credit card information, it is stolen and, instead of security software, they wind up downloading malware.


Phishing scams

Phishing, or trying to trick users into giving up personal information, is one of the most common and persistent online threats. Phishing messages can come in the form of spam emails, spam instant messages, fake friend requests, or social networking posts.


Phony websites

In recent years, cyber crooks have become adept at creating fake websites that look like the real deal.
From phony online banking to auction sites and e-commerce pages, hackers lay traps in the hopes that you will be fooled into entering your credit card number or personal information.

For your own peace of mind, consider subscribing to an identity theft protection service such as McAfee Identity Protection, which offers proactive identity surveillance, lost wallet protection, alerts when suspicious activity is detected on your accounts, and access to fraud resolution agents. For additional tips, visit CounterIdentityTheft.com.


Robert Siciliano is a McAfee consultant and identity theft expert. See him explain how to protect yourself from identity theft on CounterIdentityTheft.com. (Disclosures)

[InfoSecIsland]

Four Fold Increase in eMail-Based Malware

Recently Network Box have been noticing an unusual increase in eMail-based malware. They have not seen such an increase for several years, and this is occurring globally:

image

Four Fold Increase in Malware

More statistics can be seen at http://response.network-box.com/.

A glance at the malwares-per-hour statistics that our customer boxes are reporting clearly shows that the malware is coming in from hundreds of thousands of sources, in emails with varying subjects.
So far, Network Box heuristics such as NBH-BGTRACK and zero-day Z-scan protection systems are containing this increased threat. 

The increase is more than 4 times baseline, and all the samples that are being seen are emerging, never-before-seen, zero-day threats.

This increased activity is probably caused by botnet herders attempting to increase the size of their botnets, and this will probably be followed by a corresponding increase in spam levels.

Accordingly, Network Box have raised their alert condition to 3.  It might be that the recent decline in Spam may be reversed.

[InfoSecIsland]

Inside the Cybercrime Underworld: 100 Billion Spam E-Mails a Month

American and German researchers who infiltrated and crippled one of the world’s biggest spam-producing networks last summer have released a formal paper on the experience, and the numbers are staggering.

The Pushdo/Cutwail “botnet” sent out 1.7 trillion e-mails over 15 months (about 113 billion per month), had 100,000 enslaved “bots” around the world and had about 30 command-and-control servers in

Europe, North America and Russia.

Its Russian cybercriminal operators bought and sold e-mail addresses by the million and compromised PCs by the thousand, with lower prices for less-desirable countries and volume purchases.

[Read the original research paper here (PDF).]

"The interesting things were just the amount of spam that they were sending and how they operate like a professional business, with detailed statistics and error reporting,” Brett Stone-Gross, one of the researchers and a doctoral candidate at the University of California, Santa Barbara, told Kaspersky Lab’s ThreatPost blog. “This is a real business."

The 16 Pushdo/Cutwail servers that the researchers were able to access contained 2.35 terabytes of data, 24 databases full of details about operations and billions of target e-mail addresses.

The researchers estimate that the botnet’s operators have earned between $1.7 million and $4.2 million since June 2009.

Even one sub-botnet — Pushdo/Cutwail was divided into several domains, each under the control of one gang member — was able to pump out 87.7 billion e-mails in the four weeks between July 30 and August 25, 2010.

"I was most surprised by the sheer number of e-mails sent by this one botnet," another researcher, Thorsten Holz of Ruhr-University Bochum in Germany and Lastline, Inc., in Santa Barbara, told UBM TechWeb’s Dark Reading blog. "It turns out this one botnet sent out billions of spam messages."

Symantec Labs estimated last year that 89 percent of all e-mails are spam.


Takedown

The research team got service providers to pull the plug last summer on about 20 of Pushdo/Cutwail’s 30 command-and-control servers. (The other service providers refused.) The botnet was crippled for several months.

Botnets are illicit networks of computers that have been enslaved by malware, which burrows deep into their operating systems and opens “backdoors” that allow control by remote operators, or “bot herders.”
Malware infection usually happens when a user opens a compromised e-mail attachment (a Trojan) or visits a compromised website (a drive-by download).

The bots, ordinary machines scattered across the globe whose users have no idea they are infected, are used to send out spam touting Viagra and pornography, phishing e-mails and Trojans to harvest more bots.

Almost 40 percent of Pushto/Cutwail’s bots were in India, Holz and his colleagues found. Other countries’ shares were far lower; Australia came in second, comprising 9 percent of the compromised PCs.

Holz and his colleagues also got an archived copy of Spamdot.biz, an online forum used by botnet operators for communication and trade, which provided a fascinating look into the world of mid-level cybercriminals.

More than 90 percent of the posts on Spamdot.biz were in Russian, and less than 9 percent in English. It had nearly 2,000 registered members, who had to be recommended by at least two other existing members to be accepted.

E-mail addresses were bought and sold in blocks of a million, with prices ranging from $25 to $50 per block depending on geographical location, status (free Web-based e-mail services such as Gmail or Hotmail were cheaper) and volume.

Specialized groups sold services, such as infecting new batches of computers with the client’s malware. These sold in blocks of 1,000, with prices ranging from $13 for Asian computers to $125 for PCs based in the United States.


Top-notch software

The software used by the Pushdo/Cutwail botnet was remarkably sophisticated. Each server running Cutwail, the spam engine, constantly tested its messages against a built-in copy of the SpamAssassin e-mail filter.

Pushdo, the Trojan used for command and control, used a proprietary, and often encrypted, communications protocol to direct its bots.

Despite the technological efforts and the sheer volume of spam sent out, only 30 percent of Pushdo/Cutwail’s e-mails ever reached their target servers, the researchers estimate. Half went to invalid addresses, and nearly 17 percent were blacklisted.

"That's quite a big loss," Holz told DarkReading. "And even if the mail is received by the targeted mail server, with filtering and SpamAssassin a large chunk of that 30 percent gets filtered and doesn't necessarily reach the inbox of the user."

Still, having all this information isn’t much of a victory in the fight against spammers.

Pushdo/Cutwail has been rebuilt since last summer and is now back up to its pre-takedown size of about 100,000 bots. It’s the second-largest botnet in the world; the Rustock botnet has an estimated 250,000 enslaved PCs.

How can you prevent your computer from being enslaved by a botnet? No method is foolproof, but your odds of infection drop dramatically if you do two things: Don’t open any unrequested e-mail attachments, even those from friends; and install and constantly update and run anti-virus software, even if you’re using a Mac.

Using a Mac instead of a Windows PC also does help, at least for now. Macs are not immune from infection and a few Mac Trojans have been found in the wild, but Apple’s PC market share is still so small that most cybercriminals don’t bother writing malware for it.

[SecurityNewsDaily]

73,000 malware strains created daily in 2011

The number of threats in circulation has risen in comparison to last year. In the first three months of 2011, PandaLabs identified an average of 73,000 new malware strains, most of which were Trojans. Moreover, there was a 26 percent increase of new threats compared to the same period last year.



While PandaLabs observed a quarter-over-quarter increase of new malware in 2010, the rise was not nearly as notable as the one experienced over the last several quarters.

Trojans remain the most popular type of threat to computer systems, and now account for 70 percent of all new malware. This is unsurprising considering it can be incredibly lucrative for cybercriminals to commit fraud or steal money from Internet users through the online banking channel.


“The proliferation of online tools that enable non-technical people to create Trojans in minutes and quickly set up illegal business – especially when it can provide access to banking details - is responsible for Trojans’ impressive growth”, said Luis Corrons, technical director of PandaLabs.

Not all kind of Trojans grow at the same pace. Taking a look further at the subtypes of malware, PandaLabs found that Banker Trojans have decreased, bots have remained steady, and fake anti-virus or rogueware has descreased in popularity. However, the number of “downloaders” has increased significantly.

Downloaders are a subtype of Trojan that, once it has infected a user's computer, connect through the Internet to download additional malware. Hackers often use this method because the downloader is lightweight – only containing a few lines of code - and can go completely unnoticed unlike other Trojans.

[Net-Security]

Sunday, 13 March 2011

Japan earthquake search results already poisoned

It didn't take long for malware pushers to take advantage of Internet users' hunger for news and videos from Japan after it was hit today by the most powerful earthquake in the last 100 years:



According to Trend Micro, a search for the “most recent earthquake in Japan” will yield many search results that take users to pages where they are offered fake AV solutions.

As always, users are advised to search reputable news sites for up-to-date news. If you feel you must use Google, at least go to http://news.google.com/ to search, since those results are taken from legitimate sources.

As a side note, Google has taken advantage of its search engine popularity to post a Tsunami Alert on the engine's home page for a number of countries that are expected to be hit by waves caused by the tectonic shift.

The company has also launched a version of its Person Finder service for people that search for loved ones and friends in the wake of the earthquake.

[Net-Security]

Wednesday, 9 March 2011

Five Apple Security Myths — and the Disturbing Truths

"I just got a Mac,” think many first-time Apple customers. “I'll never have to worry about a virus again."
So it would seem to many longtime PC users, plagued by virus, e-mail and phishing attacks that require constant vigilance and the installation of often pricey security software. They rarely, if ever, hear their Mac-using friends complaining about the same problems.

But even though it’s true that Macintosh computers, iPhones, iPods and iPads (the latter three of which run Apple’s iOS mobile operating system) are subject to far fewer attacks than their Windows (or Android) counterparts, Apple products are definitely not immune to security flaws.

In fact, as Apple’s market shares increase, so do the chances of malware being written specifically for the company’s devices.

Virgin territory


Apple software is actually ripe for attack. At the 2010 “Pwn2Own” hacking contest, held every March at the CanSecWest security conference in Vancouver, Apple’s Mac OS X, the Safari Web browser and an iPhone 3GS were all exploited with surprising ease, falling quicker than their Windows-based competitors.

The overconfidence many Apple users feel about their gadgets may come from the company itself, said Alex Horan, director of product management at Boston-based Core Security.

“On its website, Apple states that: ‘Mac OS X doesn’t get PC viruses. And its built-in defenses help keep you safe from other malware without the hassle of constant alerts and sweeps,” Horan said.
But it’s a false comparison.

“Traditionally the only reason we haven’t seen a lot of news about viruses and worms targeting Mac systems is because we haven’t seen as many Mac systems in use,” Horan explained.

“The reality today remains that if I want to write some code that will attempt to control the maximum number of systems, then I need to have that code target the most common systems out there [Windows]. But as the number of Mac system grows, so will the attention of the attackers.”

Horan’s colleague at Core Security, Vice President of Security Awareness and Government Affairs Tom Kellermann, added a warning.

“Over the past few years, we’ve seen multiple exploits that have proven that this perception around Apple security is truly misguided,” Kellerman said. “Those people who believe that they are fundamentally more secure simply because they use Apple products will likely someday learn to regret it.”
Five hard lessons


With that in mind, here are five Apple security myths — and the brutal truth behind each:

Myth: I don't need antivirus and spam protection because I work on a Mac.

Truth: The Mac OS X operating system is targeted less frequently by malware only because it’s not as widespread as Windows. It’s no more secure than any other operating system, said Sorin Mustaca, data security expert at Germany-based Avira.

As for phishing attacks, said Mustaca, “the biggest problem in this case is not the computer itself, but rather it's the user.”

Myth: I can't be infected by any malicious software because I get my applications exclusively from the iTunes App Store.

Truth: “We've seen a couple of times already that the App Store is not such a secure fortress as one might have hoped,” said Mustaca. “It is extremely difficult to check every single application that is inserted there.”

Myth: Mac OS X is inherently more secure than Windows.

Truth: Apple’s brand-new products are being hacked almost immediately upon arrival. For example, “jailbreaking” your iPhone is as easy as browsing to a specific website.
“For a while, it was easier to write exploits for Mac OS X systems than it was for Windows, but now they're relatively equal,” said Core Security technical specialist Dan Crowley. “Bugs seem to be just as easy — if not easier — to find in Mac OS versus Windows.”

Myth: Apple's Safari browser is more secure than Microsoft's Internet Explorer.

Truth: Safari had more than twice the number of reported vulnerabilities in 2009 (94) than did Internet Explorer (41), according to Symantec's Global Internet Security Threat Report.

Myth: iPad users are not susceptible to the same sorts of attacks that Windows users experience.

Truth: According to Anup Ghosh, founder and chief scientist of Fairfax, Va.-based Invincea, Apple released the iOS 3.2.2 software update for the iPad specifically to fix a critical vulnerability in Adobe Reader that can be exploited by malicious PDF files.

So what can you do to make your Apple device more secure? First of all, never open an e-mail attachment you’re not expecting, even if it’s from someone you know.

Always check the URL — the long string of characters that begins with “http” — in your browser address window when surfing the Web, even on an iPhone or iPod Touch. Be very careful about using free Wi-Fi hotspots in coffeeshops, libraries or airports — it’s safer to just use your cellular carrier’s data service.

There isn’t any third-party security software for iOS devices as of yet, but a few Mac OS X applications are available, such as Sophos Anti-Virus for Mac Home Edition (free), BitDefender Antivirus 2011 for Mac (starting at $40 per year), Intego Virus Barrier X6 ($50 per year, two users) and various Norton products (starting at $50 per year).

[SecurityNewsDaily]

Barracuda study shows sharp rise in search engine malware, Twitter crime rate

Search engine malware more than doubled in 2010 and the crime rate on Twitter increased 20%, as cybercriminals continue to sharpen their focus and aim attacks at social networking services, according to a new report from Barracuda Networks.


If you're just randomly searching for a trending topic, your chances of getting malware are significantly increased on Twitter.
Daniel Peck,
research scientist
A 2010 study of search engine malware over a 153-day period found that 1 in 5 search topics are connected to malware. The study was highlighted in the Barracuda Labs 2010 Annual Security Report, which found more than 34,000 malware samples over the monitoring period.

Google served up the lion's share of malware-poisoned results (38%), followed by Yahoo (30%), and Microsoft's search engine, Bing, served up 24% of malware during the testing period. Barracuda said its study found malware writers distributing the malicious code more evenly among the search engines. Google began making strides last year, combing through millions of webpages to reduce search engine malware. While Google served up 69% of malware last June, that number decreased 45% by the end of the year.

For example, when LeBron James left Cleveland to play for the Miami Heat in July, trending links on the first page of Google contained rogue antivirus in the first five results, said Daniel Peck, a research scientist who has been studying search engine poisoning and cybercrime on social networks. "If you get there, it's a pretty good chance you're going to be successful," Peck said.

In addition, Barracuda found popular social network site Twitter serving up 8% of malware during the study, evidence that attackers are continually trying to game the system by spreading malware laden links before Twitter's antimalware engines can detect a problem. In a presentation at SecTor security conference in Toronto last year, Fabrice Jaubert of the Google antimalware team said the company continually deploys more technology and people into the process of weeding out malware, but called it a typical cat-and-mouse game, in which savvy cybercriminals find ways to avoid detection.

Barracuda has been analyzing 26 million Twitter accounts for more than two years, and is finding a steady rise in malicious content, Peck said.

Twitter is becoming a victim of its own success, he said. As users are becoming more active, malicious activity also increases, he said. In 2010, the Twitter crime rate (the number of suspended accounts) increased from 1.6% to 2% (20%) from the first half of 2010 to the second half of 2010.

"If you're just randomly searching for a trending topic, your chances of getting malware are significantly increased on Twitter," Peck said, adding that attackers are using many of the same techniques they use on search engine poisoning campaigns.

In addition to shortened URLs, Barracuda cited hijacked accounts as another concern and the ability of attackers to use automated tools to quickly set up fraudulent accounts and spam users of Twitter based on their tweets. Attackers used the NeoSpoloit exploit kit, redirecting users with shortened URLs to poisoned websites. Many of the sites served up rogue antivirus, Barracuda said.

Twitter has been making strides with security, Peck said. The social network had admitted to the Federal Trade Commission that serious security lapses resulted in the hijacking of many high-profile accounts.
The social networking service agreed to periodic third-party reviews of its security program over the next decade. Since then the service has deployed malware analysis engines and is fairly quick to suspend suspicious accounts, Peck said. In September, Twitter began forcing third-party applications using its APIs to use OAuth, a more secure protocol that uses tokens to better protect usernames and passwords, preventing the potential for account hijacking.

"It's kind of like giving someone the ability to enter your house as needed without giving them your full set of keys," said Paul Judge, chief research officer of Campbell, Calif.-based Barracuda Networks Inc.
Judge said the increased security is welcome, but a lot of Twitter accounts are still tied to weak passwords. Some cybercriminals are just guessing the passwords, Judge said. People are also using passwords that they share across different accounts. When the account credentials of as many as 1.3 million users of Gawker websites were stolen by cybercriminals in December, a few days later a large amount of Twitter accounts were hijacked, Judge said.

Judge said password management is getting better, but password managers need better integration with operating systems and browsers to get the human element out of remembering passwords. Peck said two-factor authentication, which is being rolled out with some Google products, could eventually find its way into some social networks.

[Search Security]

Sloppy spelling scuppers DHL malware spam attack

Thank heavens for the poor education of cybercriminals!

If they had paid more attention to spelling and grammar at school (rather than mugging younger kids for their dinner money and inflicting chinese burns behind the bicycle sheds) then maybe some of their scams would be harder to spot.

Take this malware campaign that we are seeing being spammed out right now, for instance.

DHL malicious spam
Subject: DHL notification
Message body:
Dear customer.
The parcel was send your home address.
And it will arrice within 7 bussness day.
More information and the tracking number
are attached in document below.
Thank you.
2011 DHL International GmbH. All rights reserverd.
The email doesn't really come from DHL, of course. This is just the latest in a long line of instances where cybercriminals have distributed malware attacks posing as communications from a delivery firm such as UPS or FedEx.

But take a closer look. There are 37 words in the body of that message, four of which are spelt incorrectly. That's an almost 11% failure rate!

If the spelling mistakes and lack of professionalism weren't enough to get your security sixth sense jangling, then hopefully your anti-virus would have identitifed that the attached DHL_document.zip file contains malware.

Sophos products detect the ZIP file proactively as Mal/BredoZp-B, and its Trojan horse contents as Troj/Agent-QQG.

I, for one, vote against improving the grammar and spelling of cybercriminals. We can't rely on every malicious hacker being a poor communicator, but it certainly can help the general public identify when a message should be treated with suspicion.

[NakedSecurity]

Tuesday, 8 March 2011

One Million Web Sites Infected At End of 2010

There was a sharp jump in the prevalence of malicious Web advertisements in the final quarter of 2010, with loosely monitored "remnant" ad networks responsible for an increasing share of the attacks, according to a report from the firm Dasient. The Dasient Q4 Malware Update reported that more than one million Web sites were infected in the last quarter of 2010. That period saw a 25% growth in malicious advertisements from the previous quarter, as attackers found ways to sneak malicious code into widely used syndicated online ad networks. Its a trend that security experts see accelerating in 2011, as malicious advertisements, sometimes referred to as 'malvertisements,' crop up on high profile sites, said Neil Daswani, Chief Technology Officer at Dasient.

Daswani said that, overall, his company saw a 100% increase in the amount of malicious advertising from the third- to fourth quarters, 2010. However, much of that was due to an expansion of the sites Dasient monitored, with an increasing focus on so-called 'remnant' ad networks, which aggregate 'remnant' advertisements from direct marketers, who often have little oversight about where the ads appear.

Though most remnant ad networks are legitimate businesses, many are also susceptible to manipulation. Malicious hackers have found a variety of ways to insert malicious content into their legitimate ad streams: either compromising the ad network's ad server and replacing a legitimate ad with a malicious one, or by submitting a legitimate ad image, then replacing it with a malicious image after a set period of time, Daswani said.

Those images can find their way even to high value sites, because top tier online ad networks often syndicate ads from other publishers to fill in gaps in their own service, Daswani said. In recent weeks, well-ranked sites such as Autotrader.co.uk, cinema site Myvue.com and londonstockexchange.com were reported to have served up malicious advertisements. Malicious ads are commonly used to display pop up messages with links that will take users to a drive by download Web site download rogue anti virus programs or other threats.

Daswani said that  firms that serve advertisements need to do a better job vetting the content of the images they serve for malicious code, and detecting Web based attacks, including malicious ads, when they appear.

Malicious ads are, by no means, limited to remnant ad networks. In January, major ad networks DoubleClick and MSN were duped into serving malicious ads from attackers who registered a malicious site that masqueraded as AdShuffle.com, an online advertising technology firm.

[ThreatPost]

Saturday, 5 March 2011

Seven Hints to Stay Safe Online

There have been a number of attacks recently against high-profile social networking accounts--French President Sarkozy, teen pop star Selena Gomez, and even social network wunderkind and Facebook founder Mark Zuckerberg have all fallen prey. Web surfing and social networking are here to stay, so the trick is figuring out how to protect your computer and your personal information while you're online.
Similar Articles:

A McAfee spokesperson e-mailed me a list of online security practices recommended by McAfee. Here is an overview of seven steps you can take to secure your online activities:


Attackers are relentless in seeking your personal data, so you have to be diligent about protecting it.

1. Update your browser. Newer browsers have better security controls and protection than older browsers. Make sure you are using the latest version of your Web browser of choice to take advantage of features like phishing filters that can protect you from attacks.

2. Do it in private. Public Wi-Fi hotspots like those at McDonald's or Starbucks are very convenient, but they are also--in a nutshell--insecure. There is typically no security or encryption enabled which means that anyone within range of your wireless connection can potentially intercept your data, including any account numbers or passwords you might type in.
In general, you should stick to reading the news and weather at public hotspots, and avoid ever typing any username, password, or other account data that should be kept private. If you absolutely must log in to Facebook, at least use the new security setting that uses HTTPS to set up a secure, encrypted connection with the social networking site.

3. Keep 'em guessing. Your username and password should be different for each site. Yes, that is more tedious and cumbersome for you to try and remember what your credentials are for each site, but it means that an attacker who compromises your Twitter account will only compromise your Twitter account, rather than having the master key that grants access to every site and service you use on the Web.

4. Double-check the domain. Before you start typing in sensitive information like your password or account number, take a peek at the address bar just to make sure that the site you are logging into is the legitimate site, hosted from the correct domain.
While you might think you are logging in to facebook.com, attackers will often create a realistic-looking malicious spoof site with a domain like facebook.hacker.com, or facebook_login.hacker.com. The bottom line is that the end is the only part that matters. If it says facebook.twitter.google.hacker.org, the real domain is simply "hacker.org" and the rest are simply subdomains created to distract and confuse you.

5. Suspicious messages are suspicious for a reason. Have you ever received an e-mail, or a private Facebook message from someone you know--but who almost never contacts you? Did it seem odd that after months or years or no communication, this person sent you a message out of the blue simply saying "Is this you in this video? LOL.", accompanied by a URL-shortened link to some unknown destination? Did it seem suspicious and make you think twice about clicking the link? It should have. If it seems suspicious--at all--assume that it is malicious and just delete it. If you are concerned that it might be important, then contact the alleged sender directly to make sure it is legitimate.

6. Clear history and log out. If you use a public PC, like at a library or a hotel lobby, to do any Web surfing, make sure you erase your tracks before you leave. You should use the anonymous or private browsing mode of the browser if there is one available. When you are done, you should go into the properties for the Web browser and erase the history and cache to remove traces of your Web-surfing activities.
You also need to make sure you manually log out of sites you log into. Just because you shut down the browser window doesn't necessarily mean you are logged out of the site. Whether intentional or pure accident, the next user of that same PC may find that your account is still actively logged in, granting complete access to a stranger.

7. Protect your PC. It wouldn't be a list of recommended security best practices without a reminder to properly protect the PC. You should have some sort of security suite, or collection of tools, providing personal firewall security and protection against viruses, spyware, phishing attacks, and other malware. As important as installing the protection is, it is more important to make sure the tools are frequently updated. Security software is typically only as secure as its last update. As new threats emerge, security software may be unable to detect or defend against them without the current update data.
There you have it. None of it is rocket science. In fact, most of it is simple, common sense. The dirty secret about PC and online security is that it is 90 percent common sense and healthy skepticism. The security software just helps guard against the other 10 percent.

[PCWorld]

Malware has 'exploded,' says security manager

A report released earlier this year by Panda Security reveals just how sophisticated the business of cyber crime has become. Among its findings: botnets are now available as a service for criminals to rent and launch spam attacks --- with prices that start as low as $15 for the rental of a SMTP server.

Botnets, a network of infected computers controlled by a master bot to send out spam, spread viruses and launch attacks, are responsible for as much as 85 percent of all email spam, according to many estimates. While efforts by some security groups to stop them have been successful, botnets continue to be the attack vector of choice from criminals, making botnet detection and evasion an increasingly crucial part of the security program in many organizations.

More about botnets
So what does an effective strategy look like? CSO spoke with Todd Ferguson, a network security manager at Raymond James Financial, a financial services holding company with subsidiaries engaged in investment, financial planning, investment banking and asset management. According to Ferguson, fighting botnets is like shooting at a moving target -- and there is no clear way to know if you're winning.
CSO: What would you say the threat landscape is like now in terms of botnets?

Ferguson: In my organization, we have a unique situation in that we have both independent and employee advisor models. In the case of our independent financial advisors, they are responsible for their own computing systems, networks, etc. The botnet issue is far more prevalent today than just for corporate users and financial advisors. It really transcends all users. It applies to clients, associates and independent contractors alike. Everyone is potentially at risk today. Botnets are not picky about who they target. Any user can be attacked and become a member of a botnet unwillingly. There are challenges to deal with once one of these devices is located, which includes cleaning and assessing the potential damage.

How do you locate a compromised device?

We are big believers in the layered security methodology. We don't rely on any one technology or intelligence source. We use a mixture, as well as our own internal monitoring. We are using the Damballa Failsafe component to monitor network traffic to identify potentially compromised machines through network behavior and intelligence applied. We also use conventional antivirus, IDS, IPS and some proprietary monitoring.

It's a combination of technologies and leveraging intelligence. There is no one silver bullet out there. Everyone has been struggling with the velocity of malware in the past few years. The landscape has changed quite a bit and we've been looking at some emerging technologies, such as Damballa. Internally, we refer to it as an alternative malware identification technique.

It's all about finding an indicator of compromise. We know that the antivirus vendors have struggled to keep up with the velocity of the malware, so we're looking at other services that can give us indicators of possible compromise. Once we see an indicator, we can intervene before it gets too far down the line.
How have things changed with regard to this threat in recent years?

One of the issues around the malware threat today, and the botnet threat specifically, is that in general creators of malware are no longer seeking notoriety. They're doing it for financial gain. Malware is centered around profit and it will interact with anyone. Once it connects to a device it will communicate with someone to either steal data or take other actions. So we're always concerned around loss of data or credentials that could be used to commit fraud.

I can't give you exact numbers on how much the threat has grown in recent years, but I can tell you it's exploded. You don't have to be technically proficient to write malware anymore. You can pay someone to do it as a service. You can easily find kits that will build malware, and you can even choose what you want it to do. We are to the point now where some of these kits and malware authors even offer support for their product.

Does part of your strategy also include an awareness campaign among employees?

Awareness is critical. One of my colleagues is dedicated to educating our associates and advisors through articles published internally, conferences, educational classes, and our annual attestation for policy review. We offer resources through our e-learning campus, and we initiate awareness campaigns if we see a threat or an emerging threat.

The attackers continue to target the same vectors, such as e-mail campaigns luring users to click on links within e-mails. We still see a lot of that, as do many other organizations.

How do you measure success?

It's a constant challenge. Success is a moving target, because the threats are ever changing. The landscape is not what it was a year ago, even two years ago, but we believe we are managing to stay ahead of the curve.

Friday, 4 March 2011

Trojans still top malware threat


Continuing a trend observed since last summer, the same types of Trojan horse programs have persistently dominated the threat landscape through February, according to GFI Software.

Statistics show that Trojans made up six of the top 10 malware threats of the month. Trojans detected as Trojan.Win32.Generic!BT continue to be the number one threat, accounting for 22.97 percent of total detections. This is an increase from the 21.38 percent in January and 21.93 percent in December of total threats detected.

These Trojans are downloaders associated with rogue security programs known as “scareware”. Once they are on a user’s system, these programs perform a fake scan of a victim’s computer for malware then display false warnings that the machine is infected in an attempt to convince victims to purchase fake security software.

"The Security Shield rogue has become very noticeable. These types of attacks notoriously cause a great deal of stress for the victim in addition to simply infecting their computer," said Chris Boyd, senior threat researcher, GFI Labs.

While Trojans continue to be the most common threat detected, GFI Labs researchers are also seeing a rise in lesser-known attack vectors. Although they are not as common, these forms of attack are especially dangerous because most users may not know how to spot them.

"PDF exploits continue to be problematic, showing a small increase since January. February has also seen continued use of fake Java applet installs to infect PCs with malware, Alureon infected videogame patches distributed on P2P networks and phishing attempts targeting customers of the popular online retailer Play.com,” said Boyd. “With new attacks popping up every day, users need to always stay cautious and research programs they plan to download when there is any doubt.”


[Net-Security]

Microsoft pushes anti-AutoRun update at XP, Vista users

Microsoft last week changed how it delivers an update that disables AutoRun, a Windows feature that big name worms, including Conficker and Stuxnet, have used to infect millions of PCs.

The company is now pushing the update to Windows XP and Vista users automatically.

When Microsoft first deployed the update Feb. 8, it said the patch would be offered as an optional download. To retrieve it, users had to manually checkmark the “KB971029″ update in the “Software, Optional” section of Windows Update in XP, or in Vista’s Windows Update panel under “Important.”

But last week Microsoft changed those rules and began feeding users the update through the Automatic Updates feature of Windows Update, which automatically downloads and installs hotfixes and other software upgrades. In Windows XP, for example, users now see the AutoRun fix under the “High-priority updates” label, and the patch is pre-checked so it downloads and installs without any user action.

The “High-priority updates” section of XP’s Windows Update is the same location where security-related patches appear.

Microsoft’s move to cripple AutoRun is a response to malware’s continued reliance on infection tactics that abuse AutoRun and AutoPlay, the technologies that automatically launch executable files on removable media, especially USB flash drives.

Both Conficker, a worm that spread widely in early 2009, and Stuxnet, the worm that analysts suspect was developed to sabotage Iran’s nuclear programs, used AutoRun and flash drives to infect Windows PCs.

Microsoft changed AutoRun’s behavior in Windows 7 to block automatic execution of files on a USB drive, and first backported the modifications to Windows XP and Vista in August 2009.

When the update is in place, flash drives inserted into a PC running XP or Vista no longer offer the option to run programs; the AutoRun extinction does not affect CDs or DVDs.

Microsoft confirmed the update reset, and said that it changed the delivery process to “minimize the user interaction required to install the updates on systems configured for automatic updating.” However, the company did not respond to questions about why it did not communicate the change to users as it had in early February when it said the patch was optional.

The unannounced automatic deployment of the AutoRun update may cause confusion if users expect files — in particular, setup executables that kick off software installation — to launch when they insert a flash drive in their Windows XP or Vista PCs.

Microsoft noted that the update breaks the functionality of some USB drives. “Users who install this update will no longer receive a setup message that prompts them to install programs that are delivered by USB flash drives. Users will have to manually install the software,” Microsoft warned in a security advisory.

To disable the update’s changes and revert to Windows XP’s and Vista’s earlier behavior, users can run the “Enable Autorun” tool found on Microsoft’s support site.

[ComputerWorld]

ZeuS Targets Mobile Users

As early as 2006, Trend Micro already recognized the fact that the BlackBerry technology could be exploited by cybercriminals. The smartphone may have remained spared from malware attacks over the years although there have been recent news of a ZeuS variant specifically targeting BlackBerry users. As we have said in a recent post, banking Trojans are evolving and more sophisticated attacks involving smartphones are among the most recent developments.

The ZeuS malware specifically targeting the BlackBerry OS is currently detected by Trend Micro as BBOS_ZITMO.B. Just like its desktop counterpart, this ZeuS variant does not display any graphical user interface (GUI) that can prompt users about the infection. Instead, it removes itself from the list of applications, in order to effectively stay under the radar.
Upon successful installation, it sends a confirmation message to the administrator to signal that it is ready to receive commands. It specifically sends the message “App Installed OK” to the U.K. number +447{BLOCKED} as seen in the screenshot below.
Click for larger view

BBOS_ZITMO.B also allows the attacker to remotely change the number to which it forwards SMS messages sent to the affected phone, also known as the administrator number. Thus, in the event that the original administrator number is tracked down and becomes unavailable, the attacker can just send a command to change the administrator number and continue receiving the forwarded messages.

Based on our analysis, BBOS_ZITMO.B is capable of carrying out the following commands:
  • Display SMS: Unmonitored SMS will be treated as a normal SMS and will be displayed on the phone.
  • Delete/Drop SMS: SMS from hacker will not be seen by the user.
  • Forward SMS: Send SMS to hacker without the user’s knowledge.
  • Block Calls
  • Remove Block Calls
  • Set Administrator: Register a new administrator.
  • On/Off
  • Add Sender
  • Remove Sender
  • Set Sender
  • Block/Unblock Phone Numbers
Other smartphone OSs are not immune to this threat either. Variants targeting smartphones running Symbian (SYMBOS_ZBOT.B) and Windows Mobile (WINCE_ZBOT.B) have also been spotted with behaviors that are very similar to those exhibited by BBOS_ZITMO.B.

With the increased popularity of mobile banking goes the increase of mobile threats. Thus users are strongly advised to keep their mobile devices secure, and be cautious in installing applications and clicking links sent by unknown users, as they may lead to the download of malicious applications.

[TrendMicro]

Report: malicious PDF files becoming the attack vector of choice


According to a newly released report by Symantec’s MessageLabs, malicious PDF files outpace the distribution of related malicious attachments used in targeted attacks, and currently represent the attack vector of choice for malicious attackers compared to media, help files, HTMLs and executables.
The report also notes a slight increase in the distribution of executable files, a rather surprising trend given the fact that spam and email filters will definitely pick them up.
PDFs now account for a larger proportion of document file types used as attack vectors. However, it should be noted that office-based file formats are still a popular and effective choice used in some targeted attacks. In 2009, approximately 52.6% of targeted attacks used PDF exploits, compared with 65.0% in 2010, an increase of 12.4%. Despite a recent downturn in the last three months, if this trend were to continue at the same rate it has for the last year, the chart in figure 2 shows that by mid-2011, 76% of targeted malware could be used for PDF-based attacks.
PDF-based malware campaigns are here to stay, though:
PDF-based targeted attacks are here to stay, and are predicted to worsen as malware authors continue to innovate in the delivery, construction and obfuscation of the techniques necessary for this type of malware,” said MessageLabs Intelligence Senior Analyst, Paul Wood.

Are cybercriminals picky? Not necessarily as it’s entirely based on the campaign in question. In this case, they appear to be interested in bypassing spam and email filters by distributing a ubiquitous filetype that’s often allow to pass through them in the first place.

Email attachments combined with social engineering tactics, are among the many attack vectors, cybercriminals take advantage of. Next to email attachments, the use of web malware exploitation kits is growing, with the majority of publicly obtainable data indicating that they continue relying on outdated and already patched vulnerabilities for successful exploitation.

[ZDNet]

Thursday, 3 March 2011

What the bad guys like?

The answer is they like the like button itself and the most of all they like to make you to click on it when you think that it is something else.

Scheme of this scam is simple. Take one picture, add a shocking title for example "Look what happens when father catches doughter on her webcam" or "I cant believe a LITTLE GIRL did this because of Justin Bieber".

Clipboard01

Clipboard02
Do some black magic with the page code to make the facebook button hidden and moving on the background of that picture and you can be sure that your page will be liked like any other.

Clipboard07
Clipboard03
This technique is called the Clickjacking and is prevelant these day. Despite the fact AVG stops these attacks we recommend to be more careful while browsing and clicking and of course make sure your AVG is up to date.

[ComputerSecurityArticles]

Potentially deadly Trojan is a modified security solution


An interesting tactic for hiding a Trojan has recently been spotted by Symantec researchers.

Instead of using entirely their own malicious code, the malware authors have decided to take advantage of the code belonging to the KingSoft WebShield browser protection software (part of the KingSoft Internet Security solution).

"The interesting part of this package is in its configuration, which allows an opportunity for malicious intent," explains researcher Éamonn Young. "Kingsoft WebShield has the ability to lock the home page to a specific domain as well as to redirect URLs based entirely on plain text configuration files. This means that a person with malicious intent can repackage it using malicious configuration files and use this as a home-made Trojan package."

And so they did. The new package contains the legitimate software and its support components, but also two configuration files that practically modify it into the Trojan.

Once the apparently legitimate software is installed and running, one of these files makes it so that the home page is changed to one of the designated URLs - which house advertisement link farms - and locked so that the user can't change it.

The other one makes sure that if a user wants to visit one a number of popular domains listed in it, he is also redirected to one of the aforementioned designated URLs.

The authors of the malware are likely to be Chinese, and so are the targeted users. The misused legitimate software is manufactured by Chinese software developer Kingsoft, and all the websites - the advertisement link farms and the domains from which the user is redirected - cater to Chinese users.

Another interesting thing about this Trojan is that deletes all Quick Launch icons except for the Internet Explorer one. And if there isn't one, it creates it. Since the whole package works as they want to only in Internet Explorer, this is a rather (too) obvious way to make sure the user uses only that browser.

Since Kingsoft WebShield works as it usually does, the user might not spot that there's something wrong with his computer right away upon installation of the tainted package. And even when he finally gets suspicious about the constant redirection, it will take a while before he learns how to deinstall it since the uninstaller has been omitted.

All in all, the authors of this improvised Trojan have manufactured an annoying but not very dangerous piece of malware. Unfortunately, it seems to me that it is only a matter of time until someone changes the configuration files again and the users are redirected to more malicious sites.

E-mail spam drops by half, search malware on the rise

Attackers are making a shift from using e-mail spam to more aggressively targeting the Internet, according to Barracuda Network.



E-mail spam dropped by half during 2010, while search engine malware doubled and the Twitter crime Rate increased 20 percent, signifying a concentrated focus on the more lucrative social networks and search engines as attack vectors.


“Attackers focus on where they can get the most eyeballs and profit, and today that means social networks and search engines,” said Dr. Paul Judge, chief research officer at Barracuda Networks. “As a community we often point to the need for user education as the missing component; however, the levels of social engineering involved in today's attacks suggest that we must continue to elevate our technological approaches. The research community must continue to build innovative defenses and the industry must make efforts to increase the deployment rates of those defenses.”

[net-security]