Showing posts with label kaspersky. Show all posts
Showing posts with label kaspersky. Show all posts

Tuesday, March 6, 2018

Research On Cryptominers

Price of cryptocurrencies have been on raise and in 2017 for example Bitcoin broke records many times. Cybercriminals have noticed that too and have started to use malicious miners. They infect victims and make coins using CPU or GPU power.

Kaspersky have written a research on these cryptominers. It can be viewed here.

Tuesday, February 28, 2017

Kaspersky Mobile Malware Evolution 2016 Report

Kaspersky have published a report summing up mobile malware evolution in 2016.

Trends of the year:
- Growth in the popularity of malicious programs using super-user rights, primarily advertising Trojans
- Distribution of malware via Google Play and advertising services
- Emergence of new ways to bypass Android protection mechanisms
- Growth in the volume of mobile ransomware
- Active development of mobile banking Trojans

The report can be viewed here (in pdf -format)

Tuesday, August 4, 2015

Kaspersky Lab's IT Threat Evolution Q2 2015 Report Available

Kaspersky Lab has published its Q2 cyber threats report highlighting key security incidents of the quarter and evaluating the Q2 cyber threat level.

The report can be viewed here.

Thursday, October 9, 2014

Cash Dispersal Enabling ATM Malware Discovered

There has been detected a backdoor program allowing cash dispersal on automated teller machines (ATMs) in multiple countries although mostly in Russia. Security company Kaspersky reports that the program, designated Backdoor.MSIL.Tyupkin, requires physical access to the ATM system and booting it off of a CD to install the malware.

The analysis of the malware can be read in Kaspersky blog.

Tuesday, July 29, 2014

Onion Ransomware Under Closer Inspection

Ransomware has become one of the biggest type of malicious software. As its name says it asks affected user for a ransom. Fedor Sinitsyn from Kaspersky Lab writes about the latest one, Onion (aka Critoni), in his blog post.

The blog post can be read here.

Sunday, June 30, 2013

Role Of Redirects In Spam

Spam is not a new problem for email user. Security company Kaspersky have written an analysis about redirects in spam.

Spammers frequently use redirects in their emails: after clicking on a link in a spam message, the recipient is often taken through a series of websites before reaching the destination resource.

There are many reasons for using redirects. In most cases, they help spammers to hide the data that enables spam filters to classify a message as unwanted – e.g., the website or contact phone number of the spammers’ customer. As a result, the recipient (as well as the spam filter) sees no links to the website being advertised in the message, no telephone numbers or email addresses that can be used to contact those who ordered the spam mailing. The message only contains a link to an intermediary resource. In addition, if the spammer is a member of an affiliate program, he will need to know how many users followed the link, because his income directly depends on that. As a result the chain of websites through which a user is sent may include redirector sites which function as counters.

The analysis can be read here.

Monday, December 10, 2012

Kaspersky Year 2012 Threat Analysis Report

Kaspersky Lab have published their annual threat analysis report covering the biggest issues faced by corporate and individual users alike as a result of malware, potentially harmful programs, crimeware, spam, phishing and other different types of hacker activity.

Kaspersky's Top 10 security incidents in 2012 is following:
1. Flashback hits Mac OS X
2. Flame and Gauss: nation-state cyber-espionage campaigns
3. The explosion of Android threats
4. The LinkedIn, Last.fm, Dropbox and Gamigo password leaks
5. The Adobe certificates theft and the omnipresent APT
6. The DNSChanger shutdown
7. The Ma(h)di incident
8. The Java 0-days
9. Shamoon
10. The DSL modems, Huawei banning and hardware hacks

About these and Kaspersky security forecast for 2013 can be read in the report here.

Tuesday, May 29, 2012

Highly Advanced Malicious Toolkit Revealed

Kaspersky Labs published yesterday a research about Flame (aka Skywiper), most complex malicious software found to date.
"It is a backdoor, a Trojan, and it has worm-like features, allowing it to replicate in a local network and on removable media if it is commanded so by its master." (source: Kaspersky Labs blog)


Here are some links about Flame malware:
- Kaspersky Labs blog post
- Iran National CERT (MAHER)
- Technical report by Laboratory of Cryptography and System Security (CrySyS Lab)

Tuesday, May 24, 2011

MAX++ Malware Back With x64 Version

MAX++ (aka ZeroAccess) trojan is not totally new malware but its x64 version is. "Computers are infected using a drive-by attack on a browser and its components via the Bleeding Life exploit kit. In particular, Acrobat Reader (CVE 2010-0188, CVE 2010-1297, CVE 2010-2884, CVE 2008-2992) and Java (CVE 2010-0842, CVE 2010-3552) modules are prone to attack.", explains Kaspersky Lab Expert Vasily Berdnikov in company's blog.

Detailed description of MAX++ x86 and x64 version behaviour can be read from the related Kaspersky blog post.

Saturday, March 26, 2011

Another Return of GpCode

Kaspersky warns about a new version of nasty Gpcode ransomware type pest that encrypts files on infected system with a strong encryption and tries to make victim pay for getting those decrypted.

The program spreads via malicious websites as a drive by download. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.bn.

Due to heavy cryptography used, the encrypted files cannot be recovered making existing backups only possible solution (one good reason to have all important stuff always backed up on separate location).

More information can be read from Kaspersky blog.

Tuesday, November 30, 2010

GpCode Makes A Comeback

Kaspersky warns about a new version of nasty Gpcode ransomware pest that encrypts files on infected system and tries to make victim pay for getting those decrypted. Preliminary analysis indicate that RSA-1024 and AES-256 crypto-algorithms are used to encrypt part of files, starting from the first byte.

The program spreads via malicious websites and P2P networks. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.ax.

More information can be read from Kaspersky blog.

Kaspersky's Spam Report of October 2010

Kaspersky has published their spam report of October 2010.

October in figures:
* The amount of spam in email traffic fell by 3.7 percentage points compared to September’s figure and averaged 77.4%.
* Phishing emails accounted for 0.87% of all mail traffic.
* Malicious files were found in 1.47% of all emails, a decrease of 2.86 percentage points compared with the previous month.
* In October, there were lots of emails containing links that exploited the Halloween theme.

The whole report can be read here.

Monday, February 9, 2009

Kaspersky Breach Exposes Sensitive Database, Says Hacker

"A security lapse at Kaspersky has exposed a wealth of proprietary information about the anti-virus provider's products and customers", writes The Register.

"In a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing "users, activation codes, lists of bugs, admins, shop, etc." Kaspersky has declined to comment, but two security experts who reviewed the evidence said the claims appeared convincing."

Assuming that the hack is real it wouldn't be the first time that Kaspersky site has been hacked with a SQL injection. In July 2008, Kaspersky's Malaysian site and several subdomains were harmed by hacker leaving pro-Turkish slogans behind.