Price of cryptocurrencies have been on raise and in 2017 for example Bitcoin broke records many times. Cybercriminals have noticed that too and have started to use malicious miners. They infect victims and make coins using CPU or GPU power.
Kaspersky have written a research on these cryptominers. It can be viewed here.
Showing posts with label kaspersky. Show all posts
Showing posts with label kaspersky. Show all posts
Tuesday, March 6, 2018
Tuesday, February 28, 2017
Kaspersky Mobile Malware Evolution 2016 Report
Kaspersky have published a report summing up mobile malware evolution in 2016.
Trends of the year:
- Growth in the popularity of malicious programs using super-user rights, primarily advertising Trojans
- Distribution of malware via Google Play and advertising services
- Emergence of new ways to bypass Android protection mechanisms
- Growth in the volume of mobile ransomware
- Active development of mobile banking Trojans
The report can be viewed here (in pdf -format)
Trends of the year:
- Growth in the popularity of malicious programs using super-user rights, primarily advertising Trojans
- Distribution of malware via Google Play and advertising services
- Emergence of new ways to bypass Android protection mechanisms
- Growth in the volume of mobile ransomware
- Active development of mobile banking Trojans
The report can be viewed here (in pdf -format)
Tuesday, August 4, 2015
Kaspersky Lab's IT Threat Evolution Q2 2015 Report Available
Kaspersky Lab has published its Q2 cyber threats report highlighting key security incidents of the quarter and evaluating the Q2 cyber threat level.
The report can be viewed here.
The report can be viewed here.
Thursday, October 9, 2014
Cash Dispersal Enabling ATM Malware Discovered
There has been detected a backdoor program allowing cash dispersal on automated teller machines (ATMs) in multiple countries although mostly in Russia. Security company Kaspersky reports that the program, designated Backdoor.MSIL.Tyupkin, requires physical access to the ATM system and booting it off of a CD to install the malware.
The analysis of the malware can be read in Kaspersky blog.
The analysis of the malware can be read in Kaspersky blog.
Tuesday, July 29, 2014
Onion Ransomware Under Closer Inspection
Ransomware has become one of the biggest type of malicious software. As its name says it asks affected user for a ransom. Fedor Sinitsyn from Kaspersky Lab writes about the latest one, Onion (aka Critoni), in his blog post.
The blog post can be read here.
The blog post can be read here.
Sunday, June 30, 2013
Role Of Redirects In Spam
Spam is not a new problem for email user. Security company Kaspersky have written an analysis about redirects in spam.
The analysis can be read here.
Spammers frequently use redirects in their emails: after clicking on a link in a spam message, the recipient is often taken through a series of websites before reaching the destination resource.
There are many reasons for using redirects. In most cases, they help spammers to hide the data that enables spam filters to classify a message as unwanted – e.g., the website or contact phone number of the spammers’ customer. As a result, the recipient (as well as the spam filter) sees no links to the website being advertised in the message, no telephone numbers or email addresses that can be used to contact those who ordered the spam mailing. The message only contains a link to an intermediary resource. In addition, if the spammer is a member of an affiliate program, he will need to know how many users followed the link, because his income directly depends on that. As a result the chain of websites through which a user is sent may include redirector sites which function as counters.
The analysis can be read here.
Monday, December 10, 2012
Kaspersky Year 2012 Threat Analysis Report
Kaspersky Lab have published their annual threat analysis report covering the biggest issues faced by corporate and individual users alike as a result of malware, potentially harmful programs, crimeware, spam, phishing and other different types of hacker activity.
Kaspersky's Top 10 security incidents in 2012 is following:
1. Flashback hits Mac OS X
2. Flame and Gauss: nation-state cyber-espionage campaigns
3. The explosion of Android threats
4. The LinkedIn, Last.fm, Dropbox and Gamigo password leaks
5. The Adobe certificates theft and the omnipresent APT
6. The DNSChanger shutdown
7. The Ma(h)di incident
8. The Java 0-days
9. Shamoon
10. The DSL modems, Huawei banning and hardware hacks
About these and Kaspersky security forecast for 2013 can be read in the report here.
Kaspersky's Top 10 security incidents in 2012 is following:
1. Flashback hits Mac OS X
2. Flame and Gauss: nation-state cyber-espionage campaigns
3. The explosion of Android threats
4. The LinkedIn, Last.fm, Dropbox and Gamigo password leaks
5. The Adobe certificates theft and the omnipresent APT
6. The DNSChanger shutdown
7. The Ma(h)di incident
8. The Java 0-days
9. Shamoon
10. The DSL modems, Huawei banning and hardware hacks
About these and Kaspersky security forecast for 2013 can be read in the report here.
Tuesday, May 29, 2012
Highly Advanced Malicious Toolkit Revealed
Kaspersky Labs published yesterday a research about Flame (aka Skywiper), most complex malicious software found to date.
Here are some links about Flame malware:
- Kaspersky Labs blog post
- Iran National CERT (MAHER)
- Technical report by Laboratory of Cryptography and System Security (CrySyS Lab)
"It is a backdoor, a Trojan, and it has worm-like features, allowing it to replicate in a local network and on removable media if it is commanded so by its master." (source: Kaspersky Labs blog)
Here are some links about Flame malware:
- Kaspersky Labs blog post
- Iran National CERT (MAHER)
- Technical report by Laboratory of Cryptography and System Security (CrySyS Lab)
Tuesday, May 24, 2011
MAX++ Malware Back With x64 Version
MAX++ (aka ZeroAccess) trojan is not totally new malware but its x64 version is. "Computers are infected using a drive-by attack on a browser and its components via the Bleeding Life exploit kit. In particular, Acrobat Reader (CVE 2010-0188, CVE 2010-1297, CVE 2010-2884, CVE 2008-2992) and Java (CVE 2010-0842, CVE 2010-3552) modules are prone to attack.", explains Kaspersky Lab Expert Vasily Berdnikov in company's blog.
Detailed description of MAX++ x86 and x64 version behaviour can be read from the related Kaspersky blog post.
Detailed description of MAX++ x86 and x64 version behaviour can be read from the related Kaspersky blog post.
Saturday, March 26, 2011
Another Return of GpCode
Kaspersky warns about a new version of nasty Gpcode ransomware type pest that encrypts files on infected system with a strong encryption and tries to make victim pay for getting those decrypted.
The program spreads via malicious websites as a drive by download. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.bn.
Due to heavy cryptography used, the encrypted files cannot be recovered making existing backups only possible solution (one good reason to have all important stuff always backed up on separate location).
More information can be read from Kaspersky blog.
The program spreads via malicious websites as a drive by download. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.bn.
Due to heavy cryptography used, the encrypted files cannot be recovered making existing backups only possible solution (one good reason to have all important stuff always backed up on separate location).
More information can be read from Kaspersky blog.
Labels:
Gpcode,
kaspersky,
malicious,
ransomware,
security
Tuesday, November 30, 2010
GpCode Makes A Comeback
Kaspersky warns about a new version of nasty Gpcode ransomware pest that encrypts files on infected system and tries to make victim pay for getting those decrypted. Preliminary analysis indicate that RSA-1024 and AES-256 crypto-algorithms are used to encrypt part of files, starting from the first byte.
The program spreads via malicious websites and P2P networks. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.ax.
More information can be read from Kaspersky blog.
The program spreads via malicious websites and P2P networks. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.ax.
More information can be read from Kaspersky blog.
Kaspersky's Spam Report of October 2010
Kaspersky has published their spam report of October 2010.
October in figures:
* The amount of spam in email traffic fell by 3.7 percentage points compared to September’s figure and averaged 77.4%.
* Phishing emails accounted for 0.87% of all mail traffic.
* Malicious files were found in 1.47% of all emails, a decrease of 2.86 percentage points compared with the previous month.
* In October, there were lots of emails containing links that exploited the Halloween theme.
The whole report can be read here.
October in figures:
* The amount of spam in email traffic fell by 3.7 percentage points compared to September’s figure and averaged 77.4%.
* Phishing emails accounted for 0.87% of all mail traffic.
* Malicious files were found in 1.47% of all emails, a decrease of 2.86 percentage points compared with the previous month.
* In October, there were lots of emails containing links that exploited the Halloween theme.
The whole report can be read here.
Monday, February 9, 2009
Kaspersky Breach Exposes Sensitive Database, Says Hacker
"A security lapse at Kaspersky has exposed a wealth of proprietary information about the anti-virus provider's products and customers", writes The Register.
"In a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing "users, activation codes, lists of bugs, admins, shop, etc." Kaspersky has declined to comment, but two security experts who reviewed the evidence said the claims appeared convincing."
Assuming that the hack is real it wouldn't be the first time that Kaspersky site has been hacked with a SQL injection. In July 2008, Kaspersky's Malaysian site and several subdomains were harmed by hacker leaving pro-Turkish slogans behind.
"In a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing "users, activation codes, lists of bugs, admins, shop, etc." Kaspersky has declined to comment, but two security experts who reviewed the evidence said the claims appeared convincing."
Assuming that the hack is real it wouldn't be the first time that Kaspersky site has been hacked with a SQL injection. In July 2008, Kaspersky's Malaysian site and several subdomains were harmed by hacker leaving pro-Turkish slogans behind.
Subscribe to:
Posts (Atom)