Showing posts with label MALWARE. Show all posts
Showing posts with label MALWARE. Show all posts

Monday, 13 July 2015

Popular Android games stealing your Facebook credentials

Researchers with two security firms independently observed apps on the Google Play store that are stealing Facebook credentials, and one of the apps has been downloaded by up to a million Android users.
Cowboy Adventure is a working game by Tinker Studio that has between 500,000 and 1,000,000 downloads, but it is also malware – upon launching the app, certain users are met with a fraudulent Facebook login window that steals entered credentials and sends them to the attackers.
“If you have basic knowledge about OAuth, you should know that no [third] party could ask your [Facebook] account in this way,” a Wednesday post from security firm Trustlook said.

Sunday, 2 September 2012

Natural gas giant RasGas targeted in cyber attack

Reports have surfaced that liquified natural gas (LNG) producer RasGas, based in the Persian Gulf nation of Qatar, has been struck by an unidentified virus, this time shutting down its website and email servers.

Theories have linked the malware that infected 30,000 workstations at oil company Saudi Aramco this month with the recent RasGas attacks, which has, since Monday, reportedly caused a blackout in parts of its computer systems. But Bloomberg News quoted a company official who said that RasGas' production operations were not impacted by the virus.

RasGas and Saudi Aramco have yet to name the malware that's infected them. However, researchers are examining whether data-wiping virus Shamoon was the culprit at Saudi Aramco.

Saturday, 1 September 2012

Facebook cracks down on fake "Likes"


Facebook Inc is weeding out fake "Likes" on its social network that are being caused by spammers, malware and black marketeers as it strives to maintain credibility as an advertising platform.

Facebook said the number of Likes, or endorsements by users, on corporate pages is likely to drop by less than 1 percent, on average, after the crackdown.

"Newly improved automated efforts will remove those Likes gained by malware, compromised accounts, deceived users, or purchased bulk Likes," Facebook said in a post on its official blog on Friday.

"While we have always had dedicated protections against each of these threats on Facebook, these improved systems have been specifically configured to identify and take action against suspicious Likes," the post continued.

Thanks to a growing black market, companies can instantly raise their profile on Facebook by purchasing thousands of Likes at a time - a practice that is forbidden by the No. 1 social network, which has 955 million users.

Tuesday, 28 August 2012

Saudi Oil firm says 30,000 computers hit by virus


Saudi Arabia's oil company, Saudi Aramco, says its main internal network is back up after a virus affected 30,000 work stations in mid-August, but the source of the attack remains unclear.
Saudi Aramco said all of the affected workstations have all been cleaned and restored to service and normal business resumed on Saturday when employees returned to work following the Muslim Eid holidays. The primary enterprise systems of hydrocarbon exploration and production were unaffected because they are kept on isolated network systems. Meanwhile, remote Internet access to online resources has been restricted, the statement said.
Saudi Aramco blamed a "malicious virus that originated from external sources" and said it was continuing to "investigate the causes of the incident and those responsible for it," in a statementreleased yesterday. There was no direct mention of hackers who had claimed responsibility for attacking the energy company.
"Saudi Aramco is not the only company that became a target for such attempts, and this was not the first nor will it be the last illegal attempt to intrude into our systems, and we will ensure that we will further reinforce our systems with all available means to protect against a recurrence of this type of cyber-attack," Khalid A. Al-Falih, president and CEO of Saudi Aramco, said in the statement.
At least one main Aramco Web site remained down today.
A group calling itself Cutting Sword of Justice posted a message on the Pastebin site on August 15, the same day Saudi Aramco started having problems, claiming to have sent a malicious virus to destroy 30,000 computers in the energy company. The group said it was targeting Aramco, "the largest financial source for Al-Saud regime," because it supports "crimes and atrocities" against citizens in Syria, Egypt, Lebanon and other neighboring countries.
There have been a series of posts, from that group, as well as Arab Youth Group, and possibly a third. The next day another Pastebin post claimed that data and operating system files were wiped out on the client computers and that 2,000 servers were affected, while another post listed what it said were the IP addresses supposedly from Aramco's internal network.
A subsequent post referred to the "Shamoon attack." Shamoon is malware that destroys data, according to a Symantec report on August 16. The malware was being used in targeted attacks including against at least one energy company in the Middle East, but researchers have not named the victim.
Security expert Jeffrey Carr, CEO of Taia Global, speculates in a blog post today that the attack was orchestrated by Iran to retaliate against Saudi Aramco for committing to make up for cuts in Iran's oil exports as a result of the U.S.-European Union embargo.
by Elinor Mills
 

Sunday, 26 August 2012

Phishing emails targeting BlackBerry, iPhone users

BlackBerry users are being targeted in a new round of phishing emails that try to infect computers with malware.

The messages claim that the recipient's "BlackBerry ID" has been created, and to retrieve it, they need to click on an attachment included in the email, according to Websense Security Labs, which detected the threat. But doing so results in the installation of malware.

“The binary that [victims] load with this attack is a backdoor, which could download another malicious binary meant to steal your bank card details, or to attack websites, or whatever they can do by getting into your computer,” Chris Astacio, manager of security research at Websense, told SCMagazine.com on Friday.

A similar email campaign in targeting iPhone users, according to Astacio.

The malware being used has gone undetected by many anti-virus programs, he said.

Wednesday, 22 August 2012

Nude wallpaper Apps infect of Android devices with Malware


Thousands of Android devices are thought to have been infected by a strain of Chinese Malware which sends costly SMS messages to earn cash for its creators.
Some reports have claimed that over 500,000 Android devices are infected with the malware, which is detected by Sophos's free Android anti-virus as Andr/SMSZomb-A.
Users are tricked into believing that they are installing GIF wallpaper onto their Android device, and a provocative message is shown suggesting that a secondary app is installed that would allow permanent use of the images.

Wednesday, 15 August 2012

Airport virtual private network hacked using Malware

The pervasive Citadel trojan, typically reserved for financial theft, was used to beat two-factor authentication and hack into the virtual private network (VPN) of a major international airport, researchers revealed Tuesday.
Security firm Trusteer discovered the attack, which launched a two-step assault on its victims in order to compromise the airport's VPN.
The man-in-the-browser (MITB) assault first used form-grabbing malware, which steals data entered into web forms before it is passed over the internet, to steal the airport employees' VPN usernames and passwords, Amit Klein, Trusteer's chief technology officer, said in a blog post on Tuesday. Next, screen-capturing technology was employed to take a snapshot of an image created by the VPN's strong authentication product.

Saturday, 11 August 2012

Government Finfisher Spyware Spreading Across the Globe

A commercially available spyware tool intended for law enforcement agencies is turning up in countries where it should never have been sold, raising concerns that it could be commandeered by cyber crooks.

Security firm Rapid7 has managed to identify the the IP addresses of a handful of command and control (C&C) servers using the FinFisher snooping tool, which is developed by Gamma Group.

The firm said it has analysed characteristics that enable it to identify communications between the tool and C&C servers.

Rapid7 used this fingerprint to track the spyware and found 12 C&C servers in the US, Indonesia, Australia, Qatar, Ethiopia, Czech Republic, Estonia, Mongolia, Latvia and Dubai.

Security researcher Claudio Guarnier said that while the company could not confirm whether agencies or governments were actively using the tool to mount cyber spying campaigns, it was unlikely the spy tool was yet being used by cyber criminals.

Thursday, 9 August 2012

Beware of Malicious Olympic 2012 Android Apps


Crave's Eric Mack looks at some of the digital threats taking advantage of the Games and at how to protect yourself.
When the Summer Olympics roll around, you can count on some intense competition in key events like gymnastics. But for 2012, the action isn't just on the mat. It seems that distributing and battling malware and phishing efforts disguised as Olympics apps and info are practically an exhibition sport this summer.
An app called "London Olympics Widget" seems harmless enough, but according to Webroot's security blog, it actually rifles through your contacts, device info, and text messages.
It's no longer available via the Google Play store, but it's still listed on an Australian site aggregatingAndroid apps, where there are plenty of the telltale signs of skeezy code, including this odd Gmail contact address and English grammar that's not quite right:
Any issues or questions just feel to email us:
Lebara.sydney.au@gmail.com
We will reply you as soon as possible. (no more than 24 hours)
Other bits of evidence suggest the app isn't what it appears to be: it's digitally signed from New Delhi, and its own screenshots reveal that, well, it's a pretty lame-looking widget.
GFI Software also claims to have found Russian servers hosting sites posing as legit app stores to push out the nasty code to unsuspecting Android devices, making the former Soviet republic competitive in both the medal and malware count this year

Wednesday, 8 August 2012

Mobile Apps are New Cyber Crime Attack Vector: RSA

Anuradha Shukla Added 7th Aug 2012
Mobile apps have emerged as a new cyber crime attack vector for phishing and malware, says RSA, the security division of EMC.
To combat this issue, the company has introduced the RSA FraudAction Anti Rogue App Service that can identify and take action against rouge mobile apps that are out to serve up malware or phishing attacks.
The release of this application is well timed as a report from TrendMicro TrendLabs indicates that the number of malicious Android apps jumped over 20,000 in July 2012. RSA also notes an April 2012 report from Goode Intelligence that shows about 71 percent of organisations allow their employees to use their own mobile devices for company business.

Tuesday, 7 August 2012

Quit Surfing Porn Sites says US Pentagan to Missile Agency Worker


The director of the US Pentagon's Missile Defense Agency (MDA) has chided employees and contractors for using government computers to surf porn.
The MDA, an agency of 8,000 employees, develops, fields, and upgrades the country's ground-and sea-based missile defense programs.
On July 27, Executive Director John James Jr. sent out a memo citing instances of workers accessing x-rated sites as well as emailing explicit images—usage that exposes the network to malware or malicious code.
Bloomberg News quotes the memo:
These actions are not only unprofessional, they reflect time taken away from designated duties, are in clear violation of federal and [Department of Defense] regulations, consume network resources and can compromise the security of the network though the introduction of malware or malicious code.

Tuesday, 31 July 2012

Free Android apps could hijack your phone


Those annoying pop-up ads are back. This time, they're on your smartphone, and they're badder than ever. Here's how you can avoid aggressive adware on your mobile device

Downloading free Android apps could make you vulnerable to aggressive adware, according to San Francisco-based security firm Lookout.

In fact, as much as five percent of those free apps have spammy ads that may be parceling out your information to third parties according to CTO Kevin Mahaffey.

That number may seem small at first, but not after you consider how many hundreds of millions of times those free apps are downloaded. To combat the problem, Lookout has developed its own app that scans other apps to tells you which ones are engaging in bad behavior. It's up to you to delete the offender(s).

The Android platform is the Wild West, and the good, the bad and the ugly are all present in abundance. The good, of course, is some seriously creative app development and an open platform that allows for some very cool innovation.

Monday, 30 July 2012

"Groupon discount gifts" titled e-mail maybe malware

by Graham Cluley on July 30, 2012 
Cybercriminals have spammed out malware, attached to emails claiming to be related to discounts for offers on Groupon.
The emails, which have the poorly spelt subject line of "Groupon dicount gifts" (in itself something which should ring alarm bells), pretend to come from Groupon, and claim that one of your friends has found a deal on the website.
The website says that your friend has decided to share the deal with you, and that you are receiving a discount code as a result.

Part of the email reads:
Hi there!
You're going to love it
We are glad to inform you that one of your friends has found a great deal on Groupon.com!
And even shared it with you!

Yeah! Now Groupon.com gives an opportunity to share a discount gift with a friend!
Enjoy your discount gift in the attachement and share it with one of your friend as well.
All the details in the file attached. be in a hurry this weekend special is due in 2 days!
Attached to the emails is a file called Gift coupon.zip, which contains a Trojan horse designed to infect Windows computers.
Sophos products detect the malware as Troj/Bredo-ABB and Mal/BredoZp-B.
As always, keep your anti-virus up-to-date and your wits about you. It's easy for anyone to make a professional-looking email using the branding of a well-established website in their attempt to lure you into opening an attached file or clicking on a dangerous web link.
Source-NakedSecurity