Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Wednesday, 15 August 2012

Airport virtual private network hacked using Malware

The pervasive Citadel trojan, typically reserved for financial theft, was used to beat two-factor authentication and hack into the virtual private network (VPN) of a major international airport, researchers revealed Tuesday.
Security firm Trusteer discovered the attack, which launched a two-step assault on its victims in order to compromise the airport's VPN.
The man-in-the-browser (MITB) assault first used form-grabbing malware, which steals data entered into web forms before it is passed over the internet, to steal the airport employees' VPN usernames and passwords, Amit Klein, Trusteer's chief technology officer, said in a blog post on Tuesday. Next, screen-capturing technology was employed to take a snapshot of an image created by the VPN's strong authentication product.

Saturday, 11 August 2012

Government Finfisher Spyware Spreading Across the Globe

A commercially available spyware tool intended for law enforcement agencies is turning up in countries where it should never have been sold, raising concerns that it could be commandeered by cyber crooks.

Security firm Rapid7 has managed to identify the the IP addresses of a handful of command and control (C&C) servers using the FinFisher snooping tool, which is developed by Gamma Group.

The firm said it has analysed characteristics that enable it to identify communications between the tool and C&C servers.

Rapid7 used this fingerprint to track the spyware and found 12 C&C servers in the US, Indonesia, Australia, Qatar, Ethiopia, Czech Republic, Estonia, Mongolia, Latvia and Dubai.

Security researcher Claudio Guarnier said that while the company could not confirm whether agencies or governments were actively using the tool to mount cyber spying campaigns, it was unlikely the spy tool was yet being used by cyber criminals.

Friday, 10 August 2012

Gauss trojan targets Lebanese banks, likely U.S. creation


Researchers have come across another sophisticated piece of Middle Eastern-targeted espionage malware, which, at the very least, is capable of stealing bank login details, and, at the most extreme, is another Stuxnet.
Dubbed Gauss, the malware was discovered by analysts at Russia-based Kaspersky Lab, the same outfit that detected the Flame virus, which used world-class cryptographic functionality to spread and infect hundreds of machines in Iran to gather intelligence. And researchers found that Gauss, whose main module is named after the 19th century German mathematician Carl Friedrich Gauss, was built using the same platform as Flame.
Flame, as well as Stuxnet, are both believed to be collaborative creations of the United States and Israel.
Like Flame, Gauss contains several modules so that it can be customized to attack a victim in a certain way, Roel Schouwenberg, a senior anti-virus researcher at Kaspersky, told SCMagazine.com on Thursday. So far, researchers have only gleaned insight about its password-stealing capabilities.
Experts who studied the trojan, which began spreading sometime late last summer, can confirm at least 2,500 computers, mostly in Lebanon, have been hit with the malware. It is capable of siphoning the usernames and passwords of a half-dozen banks in Lebanon, as well as Citibank and PayPal. The malware also can hijack data related to emails and social networking sites.

Thursday, 9 August 2012

BlackBerry, Android users targeted by new Zeus trojan


Kaspersky Lab researchers say they have detected five new variants of a mobile trojan known as ZitMo, and four of them target BlackBerry devices, which typically have gone untouched by hackers

ZitMo, which stands for "Zeus in the mobile," first appeared roughly two years ago. It is designed to steal mobile transaction authentication numbers (mTANs), or one-time passwords, that some banks, mostly in Europe, send via SMS message to mobile users as an additional layer of security.

In the past, the malware has posed as a legitimate banking security application. Once installed, the bogus app intercepts all incoming SMS messages and forwards them to a remote server.

The latest samples are targeting users in Germany, Spain and Italy, said Denis Maslennikov, a Kaspersky senior malware analyst, in a blog postTuesday.

The BlackBerry samples are masqueraded as .cod and .jar files, while the Android strain hides itself as a security app, he said.

Wednesday, 8 August 2012

Mobile Apps are New Cyber Crime Attack Vector: RSA

Anuradha Shukla Added 7th Aug 2012
Mobile apps have emerged as a new cyber crime attack vector for phishing and malware, says RSA, the security division of EMC.
To combat this issue, the company has introduced the RSA FraudAction Anti Rogue App Service that can identify and take action against rouge mobile apps that are out to serve up malware or phishing attacks.
The release of this application is well timed as a report from TrendMicro TrendLabs indicates that the number of malicious Android apps jumped over 20,000 in July 2012. RSA also notes an April 2012 report from Goode Intelligence that shows about 71 percent of organisations allow their employees to use their own mobile devices for company business.