Symantec have published their Intelligence report that sums up the latest threat trends for December 2019.
The report can be viewed here.
Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts
Friday, January 17, 2020
Sunday, November 17, 2019
Symantec Intelligence Report: October 2019
Symantec have published their Intelligence report that sums up the latest threat trends for October 2019.
The report can be viewed here.
The report can be viewed here.
Labels:
malware,
report,
security,
security threat,
symantec
Thursday, October 17, 2019
Symantec Intelligence Report: September 2019
Symantec have published their Intelligence report that sums up the latest threat trends for September 2019.
The report can be viewed here.
The report can be viewed here.
Friday, April 6, 2018
Microsoft Malware Protection Engine Vulnerability
The Microsoft Malware Protection Engine, mpengine.dll, provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software. There has been found a vulnerability in it. The vulnerability (CVE-2018-0986) may allow an attacker to execute arbitrary code in the security context of the LocalSystem account and take control of the system.
Affected are versions earlier than 1.1.14700.5.
In default settings Malware Protection Engine should update itself automatically. Instructions for checking currently used version can be read here under "Verification of the update installation" section of the correspondent product in use.
More information can be read from the related advisory.
Affected are versions earlier than 1.1.14700.5.
In default settings Malware Protection Engine should update itself automatically. Instructions for checking currently used version can be read here under "Verification of the update installation" section of the correspondent product in use.
More information can be read from the related advisory.
Labels:
antivirus,
malware,
Microsoft,
protection,
security,
security threat,
update,
vulnerability
Tuesday, February 28, 2017
Kaspersky Mobile Malware Evolution 2016 Report
Kaspersky have published a report summing up mobile malware evolution in 2016.
Trends of the year:
- Growth in the popularity of malicious programs using super-user rights, primarily advertising Trojans
- Distribution of malware via Google Play and advertising services
- Emergence of new ways to bypass Android protection mechanisms
- Growth in the volume of mobile ransomware
- Active development of mobile banking Trojans
The report can be viewed here (in pdf -format)
Trends of the year:
- Growth in the popularity of malicious programs using super-user rights, primarily advertising Trojans
- Distribution of malware via Google Play and advertising services
- Emergence of new ways to bypass Android protection mechanisms
- Growth in the volume of mobile ransomware
- Active development of mobile banking Trojans
The report can be viewed here (in pdf -format)
Wednesday, November 9, 2016
Google To Flag Malware Spreading Sites For A Month
Google has introduced a new class in its Safe Browsing anti-malware system called "repeat offenders". This status is reserved for websites "that repeatedly switch between compliant and policy-violating behavior for the purpose of having a successful review and having warnings removed". Once site has been determined as a repeat offender the webmaster will be unable to request additional reviews via the Search Console for 30 days and warnings continue to show to users. According to Google the new class won't be used on hacked websites.
More information in Google's blog post.
More information in Google's blog post.
Tuesday, June 28, 2016
Bart Ransomware
Cyber criminals behind Dridex and Locky ransomware have started distributing a new file-encrypting software named as Bart. According to security company Proofpoint RockLoader malware is used to download Bart over HTTPS. Bart itself will encrypt the files without first connecting to a remote command and conquer (C&C) server.
Malware campaign has included sending messages with the subjects "Photos" containing malicious Javascript code file (e.g. PDF_123456789.js) zipped in as an attachment with name like "photos.zip", "image.zip", "Photos.zip", "photo.zip", "Photo.zip", or "picture.zip".
More information with details can be read from Proofpoint blog post here.
Malware campaign has included sending messages with the subjects "Photos" containing malicious Javascript code file (e.g. PDF_123456789.js) zipped in as an attachment with name like "photos.zip", "image.zip", "Photos.zip", "photo.zip", "Photo.zip", or "picture.zip".
More information with details can be read from Proofpoint blog post here.
Labels:
bart,
malware,
ransomware,
security,
security threat
Monday, June 6, 2016
Bing To Offer More Detailed Warnings About Malware
Microsoft's search engine Bing has been updated to give more detailed warnings about malware. Previously warnings have been a generic type to cover all malware threat types. In addition to make users better aware of the threat with this improvement webmasters are also able to clean their site quicker by having stronger insights into why their site was flagged.
More information in the post in the Bing blog.
More information in the post in the Bing blog.
Friday, April 1, 2016
Petya Ransomware
Ransomware, a type malware that restricts access in computer system and requires a ransom for removing the restriction, is currently a big problem in digital world. New member to this family is Petya. Instead of encrypting just some file types Petya prevents user from accessing all the files on the hard drive by encrypting Master File Table. The user is asked to pay a ransom in order to get the hard drive decrypted.
Petya targets mostly business users as it is being distributed in spam emails that are targeting the human resources departments. First spam messages contained a Dropbox link to a malicious file. Since Dropbox removed the malicious archives the bad guys will likely use other way of distribution.
More information can be read in Kaspersky's blog here.
Petya targets mostly business users as it is being distributed in spam emails that are targeting the human resources departments. First spam messages contained a Dropbox link to a malicious file. Since Dropbox removed the malicious archives the bad guys will likely use other way of distribution.
More information can be read in Kaspersky's blog here.
Labels:
malicious,
malware,
petya,
ransomware,
security,
security threat
Monday, January 4, 2016
Ransom32 JavaScript-Based Ransomware
Security company Emsisoft warns about a new JavaScript-based ransomware. Fabian Wosar from Emsisoft says that a new ransomware family called Ransom32 is using the NW.js platform for infiltrating the victims' computers and encrypting their files with AES encryption.
The best way to protect from ransomware is to have proper backups regularly made of all important files. These should be stored on a disconnected device since a lot of ransomware targets backups specifically. Good option is for example an external hard drive that is usually detached the system.
The Emsisoft blog post can be read here.
"NW.js is essentially a framework that allows you to develop normal desktop applications for Windows, Linux and MacOS X using JavaScript. It is based upon the popular Node.js and Chromium projects. So while JavaScript is usually tightly sandboxed in your browser and can’t really touch the system it runs upon, NW.js allows for much more control and interaction with the underlying operating system, enabling JavaScript to do almost everything “normal” programming languages like C++ or Delphi can do. The benefit for the developer is that they can turn their web applications into normal desktop applications relatively easily. For normal desktop application developers it has the benefit that NW.js is able to run the same JavaScript on different platforms." At the moment only Windows appears to be targetted but at least in theory it could be packaged for Linux and Mac OS X too.
The best way to protect from ransomware is to have proper backups regularly made of all important files. These should be stored on a disconnected device since a lot of ransomware targets backups specifically. Good option is for example an external hard drive that is usually detached the system.
The Emsisoft blog post can be read here.
Labels:
emsisoft,
malware,
ransomware,
security,
security threat
Friday, June 19, 2015
Symantec Intelligence Report: May 2015
Symantec have published their Intelligence report that sums up the latest threat trends for May 2015.
Report highlights:
- Almost 43 percent of spear-phishing attacks were directed at organizations with less than 250 employees during May, up from 31 percent in April.
- Small organizations were most likely to be targeted by malicious email in the month of May as well, where one in 141 emails contained a threat.
- There were more than 44.5 million new pieces of malware created in May, up from 29.2 million created in April.
- The overall email spam rate further declined in May, dropping 0.6 percentage points to 51.5 percent.
The report (in PDF format) can be viewed here.
Report highlights:
- Almost 43 percent of spear-phishing attacks were directed at organizations with less than 250 employees during May, up from 31 percent in April.
- Small organizations were most likely to be targeted by malicious email in the month of May as well, where one in 141 emails contained a threat.
- There were more than 44.5 million new pieces of malware created in May, up from 29.2 million created in April.
- The overall email spam rate further declined in May, dropping 0.6 percentage points to 51.5 percent.
The report (in PDF format) can be viewed here.
Labels:
malware,
report,
security,
security threat,
symantec
Monday, June 8, 2015
MalumPoS Malware Discovered
Trend Micro has discovered MalumPoS named attack tool that threat actors can be reconfigured to breach any PoS (point-of-sale) system they wish to target. Currently, it is designed to collect data from PoS systems running on Oracle MICROS, a platform popularly used in the hospitality, food and beverage, and retail industries. A bulk of the companies using MICROS is mostly concentrated in the United States.
Complete blog post with details can be read here.
Complete blog post with details can be read here.
Wednesday, May 6, 2015
Destructive Rombertik Malware Renders System Inoperable
Talos Group (part of Cisco Systems) researchers have written an analysis that deals with malware named Rombertik. The malware is designed to intercept any plain text entered into a browser window. Rombertik is spread through spam and phishing messages.
What makes this malware special is its way to act if it detects certain attributes associated with malware analysis. If such action is detected Rombertik tries first to destroy Master Boot Record (MBR) which is the first sector of a PC's hard drive that the computer looks to before loading the operating system. If it can't access the MBR then it effectively renders all of the files in a user's home folder inoperable by encrypting them with a randomly generated RC4 key. After overwriting the MBR or encrypting the home folder the computer is restarted. The overwritten MBR contains code to print out "Carbon crack attempt, failed" and then enters an infinite loop preventing the system from continuing to boot.
Complete analysis of Rombertik can be read at Talos blog here
What makes this malware special is its way to act if it detects certain attributes associated with malware analysis. If such action is detected Rombertik tries first to destroy Master Boot Record (MBR) which is the first sector of a PC's hard drive that the computer looks to before loading the operating system. If it can't access the MBR then it effectively renders all of the files in a user's home folder inoperable by encrypting them with a randomly generated RC4 key. After overwriting the MBR or encrypting the home folder the computer is restarted. The overwritten MBR contains code to print out "Carbon crack attempt, failed" and then enters an infinite loop preventing the system from continuing to boot.
Complete analysis of Rombertik can be read at Talos blog here
Wednesday, January 7, 2015
New Emotet Trojan Variant Targets Banking Credentials
Microsoft warns of new variant of Emotet trojan that is targeting banking credentials with a new spam email campaign. The emails include fraudulent claims, such as fake phone bills, and invoices from banks or PayPal.
According to the Microsoft Malware Protection Center the campaign seems to be targeting primarily German-language speakers and banking websites.
More information in Microsoft Malware Protection Center blog post.
According to the Microsoft Malware Protection Center the campaign seems to be targeting primarily German-language speakers and banking websites.
More information in Microsoft Malware Protection Center blog post.
Thursday, October 9, 2014
Cash Dispersal Enabling ATM Malware Discovered
There has been detected a backdoor program allowing cash dispersal on automated teller machines (ATMs) in multiple countries although mostly in Russia. Security company Kaspersky reports that the program, designated Backdoor.MSIL.Tyupkin, requires physical access to the ATM system and booting it off of a CD to install the malware.
The analysis of the malware can be read in Kaspersky blog.
The analysis of the malware can be read in Kaspersky blog.
Thursday, January 9, 2014
Drive-by Download Attacks: Examining the Web Server Platforms Attackers Use Most Often
Drive-by download attacks is one of the most common ways to infect affected system with malware. Tim Rains, the Director of Trustworthy Computing at Microsoft, have written interesting blog post titled as "Drive-by Download Attacks: Examining the Web Server Platforms Attackers Use Most Often". It can be read here.
Saturday, January 4, 2014
CryptoLocker Malware Spreading Via Removable Drives
Ransoms asking malware, named as CryptoLocker, raised its head first time on fall. Security company Trend Micro write in their blog about a new CryptoLocker variant that is able to spread via removable drives. The blog post can be read here.
Trend Micro have collected an info guide about defending against CryptoLocker.
Trend Micro have collected an info guide about defending against CryptoLocker.
Wednesday, October 16, 2013
Look Out For Nasty CryptoLocker
SophosLabs warns in their blog about a really nasty malware named as CryptoLocker. CryptoLocker encrypts files of specified file types on infected system and then asks user to pay a ransom in order to get files decrypted. Details about the infection and how to protect against it can be read from the SophosLabs blog post.
Bleeping Computer has an information guide and FAQ about CryptoLocker too. It can be viewed here.
Bleeping Computer has an information guide and FAQ about CryptoLocker too. It can be viewed here.
Saturday, September 7, 2013
Hesperbot Banking Trojan
There has been discovered a new banking trojan that seems to target online banking users mainly in Turkey, the Czech Republic, Portugal and the United Kingdom. This Hesperbot named trojan uses very credible-looking phishing-like campaigns, related to
trustworthy organizations, to lure victims into running the malware.
"Despite being a “new kid on the block”, it appears that Win32/Spy.Hesperbot is a very potent banking trojan which features common functionalities, such as keystroke logging, creation of screenshots and video capture, and setting up a remote proxy, but also includes some more advanced tricks, such as creating a hidden VNC server on the infected system. And of course the banking trojan feature list wouldn’t be complete without network traffic interception and HTML injection capabilities. Win32/Spy.Hesperbot does all this in quite a sophisticated manner."
More about Hesperbot can be read in Robert Lipovsky's blog post.
"Despite being a “new kid on the block”, it appears that Win32/Spy.Hesperbot is a very potent banking trojan which features common functionalities, such as keystroke logging, creation of screenshots and video capture, and setting up a remote proxy, but also includes some more advanced tricks, such as creating a hidden VNC server on the infected system. And of course the banking trojan feature list wouldn’t be complete without network traffic interception and HTML injection capabilities. Win32/Spy.Hesperbot does all this in quite a sophisticated manner."
More about Hesperbot can be read in Robert Lipovsky's blog post.
Tuesday, May 29, 2012
Highly Advanced Malicious Toolkit Revealed
Kaspersky Labs published yesterday a research about Flame (aka Skywiper), most complex malicious software found to date.
Here are some links about Flame malware:
- Kaspersky Labs blog post
- Iran National CERT (MAHER)
- Technical report by Laboratory of Cryptography and System Security (CrySyS Lab)
"It is a backdoor, a Trojan, and it has worm-like features, allowing it to replicate in a local network and on removable media if it is commanded so by its master." (source: Kaspersky Labs blog)
Here are some links about Flame malware:
- Kaspersky Labs blog post
- Iran National CERT (MAHER)
- Technical report by Laboratory of Cryptography and System Security (CrySyS Lab)
Subscribe to:
Posts (Atom)