Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Tuesday, September 14, 2021

Apple issues fix for flaw linked to Pegasus spyware

Apple released a fix Monday for a weakness that can let the spyware at the heart of the Pegasus scandal infect devices without users even clicking on a malicious message or link.

The Pegasus software from Israeli firm NSO Group has been under intense scrutiny since an international media investigation claimed it was used to spy on the phones of human rights activists, journalists and even heads of state.

Researchers at Citizen Lab, a cybersecurity watchdog organization in Canada, found the problem while analyzing a Saudi activist's phone that had been compromised with the code.

"We determined that the mercenary spyware company NSO Group used the vulnerability to remotely exploit and infect the latest Apple devices with the Pegasus spyware," Citizen Lab wrote in a post.

In March Citizen Lab examined the activist's phone and determined it was hacked with Pegasus spyware introduced via iMessage texting and that it didn't even require the phone's user to so much as click.

Hours after releasing the fix, Apple said it had "rapidly" developed the update following Citizen Lab's discovery of the problem.

"Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals," the company said.

NSO did not dispute Pegasus had prompted the urgent software upgrade, and said in a statement that it would "continue to provide intelligence and law enforcement agencies around the world with life saving technologies to fight terror and crime."

- No click needed -

Pegasus has evolved to become more effective since it was uncovered by Citizen Lab and cyber security firm Lookout five years ago.

Pegasus can be deployed as a "zero-click exploit," meaning that the spyware can install itself without the victim even clicking a booby-trapped link or file, according to Lookout senior manager Hank Schless.

"Many apps will automatically create a preview or cache of links in order to improve the user experience," Schless said.

"Pegasus takes advantage of this functionality to silently infect the device."

UN experts recently called for an international moratorium on the sale of surveillance technology until regulations are implemented to protect human rights following an Israeli spyware scandal.

An international media investigation reported in July that several governments used the Pegasus malware, created by NSO Group, to spy on activists, journalists and politicians. 

Pegasus can switch on a phone's camera or microphone and harvest its data.

"It is highly dangerous and irresponsible to allow the surveillance technology and trade sector to operate as a human rights-free zone," the United Nations human rights experts said in a statement at the time.

The statement was signed by three special rapporteurs on rights and a working group on the issue of human rights and transnational corporations and other businesses.

Israel's defense establishment has set up a committee to review NSO's business, including the process through which export licences are granted.

NSO insists its software is intended for use only in fighting terrorism and other crimes, and says it exports to 45 countries.

 Agence France-Presse

Friday, April 15, 2016

US govt worse than all major industries on cyber security: report


Add caption
WASHINGTON — U.S. federal, state and local government agencies rank in last place in cyber security when compared against 17 major private industries, including transportation, retail and healthcare, according to a new report released Thursday.

The analysis, from venture-backed security risk benchmarking startup SecurityScorecard, measured the relative security health of government and industries across 10 categories, including vulnerability to malware infections, exposure rates of passwords and susceptibility to social engineering, such as an employee using corporate account information on a public social network.

Educations, telecommunications and pharmaceutical industries also ranked low, the report found. Information services, construction, food and technology were among the top performers.

Government agencies have struggled for years to keep pace with malicious hackers and insider threats, a challenge that came into focus after it was disclosed last year that more than 21 million individuals had their sensitive data pilfered during a breach at the Office of Personnel Management.

SecurityScorecard said it tracked 35 major data breaches across government from April 2015 to April 2016.

President Barack Obama has made improving cyber defenses a top priority of his remaining year in office. His administration asked Congress to dedicate $19 billion to cyber security in its fiscal 2017 budget proposal, which would include $3.1 billion for technology modernization at various federal agencies.

Federal agencies scored most poorly on network security, software patching flaws and malware, according to SecurityScorecard, which said they may be more vulnerable to risk due to their large size.

Of the 600 government entities tracked, NASA performed the worst, the report found. The space exploration agency was vulnerable to email spoofing and malware intrusions, among other weaknesses, according to SecurityScorecard’s analysis.

Other low-performing government organizations included the U.S. Department of State and the information technology systems used by Connecticut, Pennsylvania, Washington and Maricopa County, Arizona.

Government organizations with the strongest security postures included Clark County, Nevada, the U.S. Bureau of Reclamation, and the Hennepin County Library in Minnesota.

source: interaksyon.com

Wednesday, August 28, 2013

Android mobile main target for malware — US security agencies


SAN FRANCISCO — Google Inc’s Android, the dominant mobile operating system, is by far the primary target for malware attacks, mostly because many users are still using older versions of the software, according to a study by the Department of Homeland Security and the Federal Bureau of Investigation.

Android was a target for 79 percent of all malware threats to mobile operating systems in 2012 with text messages representing about half of the malicious applications, according to the study from the government agencies, which was published by Public Intelligence website.

Google did not respond to a request for comment. DHS declined to comment.

By comparison, about 19 percent of malware attacks were targeted at Nokia’s Symbian system and less than 1 percent each at Apple Inc’s iOS software, Microsoft Corp’s Windows and BlackBerry Ltd.

Android continues to be a “primary target for malware attacks due to its market share and open source architecture,” said the study, which was addressed to police, fire, emergency medical and security personnel.

source: interaksyon.com

Friday, March 22, 2013

Candy Crush players warned vs ‘dubious’ Android apps


MANILA, Philippines — It was only a matter of time, but security experts have already issued warning against “dubious” applications trying to latch on to the success of Candy Crush, an Android game with Facebook integration that has already surpassed the likes of Farmville in terms of popularity in the social network.

In a security alert, Trend Micro Technical Communications Specialist Gelo Abendan warned that “dubious developers” have already started creating suspicious app that ride on the Candy Crush fame, which could become launchpads for malware attacks in the future.

Candy Crush Saga, a free mobile game developed by King.com, has amassed widespread popularity among users worldwide. It is a puzzle strategy game that requires players to connect matching “candies” to score points, and comes with a social component that makes the game a lot more addictive.

According to Abendan, Trend Micro was able to detect “adware” apps that contain code for the Leadbolt and Airpush ad networks, which were among the most prevalent form of adwares found in 2012.

“While not inherently malicious, adware can be abused by cybercriminals for their own gains. Adware not only uses aggressive advertising tactics such as persistent notifications, but also collects information about the user. This could be construed as a violation of the user’s privacy,” Abendan explained.

Some of the dubious apps detected by the security software company includes an app that offers tips and tricks for getting through the game, as well as another that recommends playing another game through persistent notifications. Trend Micro said the same kinds of apps have been detected for popular mobile applications such as Instagram, Bad Piggies, and Temple Run.

So as their device will not be hit with by one of the more than 1 million malicious Android apps predicted to hit devices this year, Trend Micro suggests taking extra security precautions when installing apps on their devices, such as reading thoroughly through the app’s description page.

“Comments can be a goldmine of information, since you’ll know what other users are saying about their experience with the app. Once you install any apps, make sure that you check out the permissions that they are asking for,” Abendan added.

Touted as the most insecure mobile platform today thanks to its “openness,” Android has become a breeding ground for malware in the past several years, especially with the ease of distributing apps through the Google Play Store.

In 2012, 293,091 apps on the Android platform were found to be malicious and of these, 68,740 were found on the official Google Play store. Around 22% of these malicious apps were found to leak information about the user.

Such developments are crucial in a market like the Philippines, where one out of every four mobile phones are powered by the Android platform, and where games such as Candy Crush Saga enjoy a huge following.

source: interaksyon.com

Tuesday, August 28, 2012

Latest Java software opens PCs to hackers: experts


BOSTON — Computer security firms are urging PC users to disable Java software in their browsers, saying the widely installed, free software from Oracle Corp opens machines to hacker attacks and there is no way to defend against them.

The warnings, which began emerging over the weekend from Rapid7, AlienVault and other cyber security firms, are likely to unnerve a PC community scrambling to fend off growing security threats from hackers, viruses and malware.

Researchers have identified code that attacks machines by exploiting a newly discovered flaw in the latest version of Java. Once in, a second piece of software called “Poison Ivy” is released that lets hackers gain control of the infected computer, said Jaime Blasco, a research manager with AlienVault Labs.

Several security firms advised users to immediately disable Java software — installed in some form on the vast majority of personal computers around the world — in their Internet browsers. Oracle says that Java sits on 97 percent of enterprise desktops.

“If exploited, the attacker will be able to perform any action the victim can perform on the victim’s machine,” said Tod Beardsley, an engineering manager with Rapid7′s Metasploit division.

Computers can get infected without their users’ knowledge simply by a visit to any website that has been compromised by hackers, said Joshua Drake, a senior research scientist with the security firm Accuvant.

Java is a computer language that enables programmers to write one set of code to run on virtually any type of machine. It is widely used on the Internet so that Web developers can make their sites accessible from multiple browsers running on Microsoft Windows PCs or Macs from Apple Inc.

An Oracle spokeswoman said she could not immediately comment on the matter.

Security experts recommended that users not enable Java for universal use on their browsers. Instead, they said it was safest to allow use of Java browser plug-ins on a case-by-case basis when prompted for permission by trusted programs such as GoToMeeting, a Web-based collaboration tool from Citrix Systems Inc

Rapid7 has set up a web page that tells users whether their browser has a Java plug-in installed that is vulnerable to attack: www.isjavaexploitable.com/

source: interaksyon.com

Tuesday, June 5, 2012

Computer users warned vs malicious PowerPoint file

Computer users were warned against a malicious Microsoft PowerPoint file making the rounds of the Internet, via an attached file in email messages.
Security vendor Trend Micro said the file actually contains an embedded Flash file that exploits bugs in older versions of Flash Player to drop a backdoor on infected machines.
"Users who open the malicious .PPT file triggers the shellcode within the Flash file that exploits CVE-2011-0611, and then drops 'Winword.tmp' in the Temp folder. Simultaneously, it also drops a non-malicious PowerPoint presentation file 'Powerpoint.pps,' tricking users into thinking that the malicious file is just your average presentation file," Trend Micro said in a blog post.
It said its analysis showed “Winword.tmp” is a backdoor that connects to remote sites to communicate with a possible malicious user.
Also, the file is capable of downloading and executing other malware leaving infected systems susceptible to other, more menacing threats such as data stealing malware, it added.
Trend Micro products can detect the malicious PowerPoint file as TROJ_PPDROP.EVL and the dropped backdoor file as BKDR_SIMBOT.EVL.
"Reports, as well as our own analysis, confirmed that this kind of malware has been used for targeted attacks in the past," it said.
Trend Micro also noted recent threats are no longer limited to malicious files disguised as ordinary binaries (such as .EXE file) attached to emails.
It said these specially crafted files can be embedded in commonly used files such as PDF, DOC, PPT or XLS files.
"In this particular scenario, users are unaware of the attack since TROJ_PPDROP.EVL also displays a non-malicious PowerPoint file to serve as a decoy," it said.
On the other hand, it said this case also shows that cybercriminals are continuously exploiting previously reported vulnerabilities in popular software such as Microsoft Office applications and Flash.
Trend Micro also pointed out old and reported software bugs are still being exploited by attackers.


"This finding highlights two things. First, exploits created for reliable vulnerabilities remain effective cybercriminal tools. Second, most users do not regularly update their systems’ with the latest security patch, which explains why attackers are continuously exploiting these bugs," it said. — RSJ, GMA News

source: gmanetwork.com


Sunday, April 22, 2012

Kaspersky Lab appeals to Global Programmers to help fight DUQU


Manila, Philippines - Kaspersky Lab, a leading secure content and threat management solutions developer, appeals to the programming community to solve the deep mystery in the Duqu saga that sparks theories that it was launched as a way to conduct high-level cyber-espionage and sabotage.

Duqu is a sophisticated Trojan that was created by the same people who created the infamous Stuxnet worm. Its main purpose is to act as a backdoor into the system and facilitate the theft of private information.

In an effort to find out Duqu’s intentions and where it would be going, security experts from Kaspersky Lab ask the vast programming community worldwide to share in the analysis of Duqu.

Kaspersky Lab Chief Security Officer Alexander Gostev said that the help of the programming community would help identify how Duqu was made and to track down its creators. Doing such would prevent attacks that would use it as a weapon.

The big unsolved mystery of the Duqu Trojan relates to how the malicious program was communicating with its Command and Control (C&C) servers once it infected a victim’s machine. The Duqu module that was responsible for interacting with the C&Cs is part of its Payload DLL.

After a comprehensive analysis of the Payload DLL, Kaspersky Lab researchers have discovered that a specific section inside the Payload DLL, which communicates exclusively with the C&Cs, was written in an unknown programming language. Kaspersky Lab researchers have named this unknown section the “Duqu Framework.”

Gostev reveals that Duqu has been found to be using either a totally new or an unknown programming language, unlike most malware that were developed by traditional programming languages like C++ or Visual C++.

Having such a different programming language already points out to the type of sophistication in creating the Duqu malware, which in turn reveals the high-level programming skill sets used by its creators.

According to Alexander Gostev, the creation of a dedicated programming language demonstrates just how highly skilled the developers working on the project are, and points to the significant financial and labor resources that have been mobilized to ensure the project is implemented.

“Given the size of the Duqu project, it’s possible that an entirely different team was responsible for creating the Duqu Framework. With the extremely high level of customization and exclusivity that the programming language was created with, it is also possible that it was made not only to prevent external parties from understanding the cyber-espionage operation and the interactions with the C&Cs, but also to keep it separate from other internal Duqu teams who were responsible for writing the additional parts of the malicious program,” Gostev says.

So far, the majority of Duqu infections have been found in Iran. However, it does not stop its creators to target other newly-industrialized countries, especially those in Asia where many industries are already adopting technology in their business, since the country has already become a major hub for IT outsourcing services.

The Philippines, for one is already a major hub for IT outsourcing services. The spread of Duqu in the Philippines could have dire effects on its multibillion-dollar outsourcing business.

source: mb.com.ph

Sunday, April 15, 2012

Kaspersky finds largest attack on Mac OS by malware Flashback/Flashfake

Manila, Philippines - Kaspersky Lab, a leading secure content and threat management solutions developer, recently analyzed the Flashfake botnet and discovered a massive number of infected computers worldwide, most likely running Mac OS X. The botnet is being distributed via infected websites as a Java applet that pretends to be an update for the Adobe Flash Player.

About 670,000 computers worldwide, 98 percent of them running Mac OS X, were infected by Flashfake. Kaspersky Lab attests that this is the largest Mac-based infection to date, with the largest number of victims targeting developed countries. The United States had the most infected computers (300,917) followed by Canada (94,625), the United Kingdom (47,109) and Australia (41,600).

Infections also found in France (7,891), Italy (6,585), Mexico (5,747), Spain (4,304), Germany (4,021), Japan (3,864) and Philippines is among the countries that contribute the average count of 1- 2,547 said Kaspersky Lab security expert, Igor Soumenkov in his blog.

Security expert Alexander Gostev also stated in his blog that they were able to reverse-engineer the Flashfake malware that enabled them to successfully analyze the communications between infected computers and the command and control (C&C) servers of Flashfake.

“After intercepting one of the domain names used by the Flashback/Flashfake Mac Trojan and setting up a special sinkhole server last Friday, April 6, we managed to gather stats on the scale and geographic distribution of the related botnet. We continued to intercept domain names after setting up the sinkhole server and we are currently still monitoring how big the botnet is. We have recorded a total of 670,000 unique bots. Over the weekend of April 7 to 8, we saw a significant fall in the number of connected bots,” added Gostev.

Kaspersky Lab is also directing users to visit the website www.flashbackcheck.com, specifically made to determine if a computer is infected with the malware using a tool that looks into the device’s universal unique identifier (UUID). It also has instructions on how remove the malware if it is found.

source: mb.com.ph