From Sophos Naked Security:
The Google Play apps that say they don’t collect your data – and then do
"Adware is typically viewed as a nuisance that does no real harm. But in recent research, SophosLabs has seen adware in Google Play that does more than just deliver ads. This strain can collect the user’s personal information, including email address, and send them to a remote server.
Sophos detects this adware library as Android XavirAd and the information-stealing component as Andr/Infostl-BK."
The purpose of this blog is to help small-medium businesses (SMB's) deal effectively with their unique cyber security needs. With over 15 years experience in IT and cyber security I will show SMB's how they can leverage their limited resources to develop effective cyber defenses to the most common threats using information security best practices and no/low cost tools.
LinkedIn: http://www.linkedin.com/in/ecissorsky/
Twitter: @ecissorsky
Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts
Thursday, May 11, 2017
Monday, May 8, 2017
Homeland Security Issues Warning on Cyberattack Campaign
From DataBreach Today:
Homeland Security Issues Warning on Cyberattack Campaign
"The Department of Homeland Security is warning IT services providers, healthcare organizations and three other business sectors about a sophisticated cyberattack campaign that involves using stolen administrative credentials and implanting malware, including PLUGX/SOGU and RedLeaves, on critical systems."
Homeland Security Issues Warning on Cyberattack Campaign
"The Department of Homeland Security is warning IT services providers, healthcare organizations and three other business sectors about a sophisticated cyberattack campaign that involves using stolen administrative credentials and implanting malware, including PLUGX/SOGU and RedLeaves, on critical systems."
Software Download Mirror Distributes Mac Malware
From Security Week:
Software Download Mirror Distributes Mac Malware
"A download mirror server for the video converting tool HandBrake was recently compromised and configured to distribute a remote administration Trojan (RAT) for Mac computers.
The company has posted a security alert on its website, informing Mac users that from Tuesday to Saturday of last week they might have downloaded a Trojanized version of the application. According to HandBrake, while not all users might have been affected, all of them should verify the downloaded file before running it."
Software Download Mirror Distributes Mac Malware
The company has posted a security alert on its website, informing Mac users that from Tuesday to Saturday of last week they might have downloaded a Trojanized version of the application. According to HandBrake, while not all users might have been affected, all of them should verify the downloaded file before running it."
And Now a Ransomware Tool That Charges Based On Where You Live
From Dark Reading:
And Now a Ransomware Tool That Charges Based On Where You Live
"Malware is designed to charge more for victims in countries with a higher cost of living, Recorded Future says.
The creators of "Fatboy," a new and somewhat politically incorrectly named ransomware tool that surfaced recently on a Russian crimeware forum, appear to have adopted an interesting economic approach in designing the malware."
And Now a Ransomware Tool That Charges Based On Where You Live
"Malware is designed to charge more for victims in countries with a higher cost of living, Recorded Future says.
The creators of "Fatboy," a new and somewhat politically incorrectly named ransomware tool that surfaced recently on a Russian crimeware forum, appear to have adopted an interesting economic approach in designing the malware."
Friday, May 5, 2017
ATM Security Software Found to Have Serious Vulnerability
From DataBreach Today:
ATM Security Software Found to Have Serious Vulnerability
"A security application for ATMs that's designed to thwart "jackpotting" attacks, where cash machines are commanded to surrender their holdings, has been found to have a serious vulnerability.
The software called Checker ATM, developed by the Spanish company GMV, now has a patch. Positive Technologies, a security company, found the vulnerability (CVE-2017-6968), which is a type of memory-related hiccup known as a buffer overflow, in versions 4.x and 5.x."
ATM Security Software Found to Have Serious Vulnerability
"A security application for ATMs that's designed to thwart "jackpotting" attacks, where cash machines are commanded to surrender their holdings, has been found to have a serious vulnerability.
The software called Checker ATM, developed by the Spanish company GMV, now has a patch. Positive Technologies, a security company, found the vulnerability (CVE-2017-6968), which is a type of memory-related hiccup known as a buffer overflow, in versions 4.x and 5.x."
Attackers Unleash OAuth Worm via 'Google Docs' App
From DataBreach Today:
Attackers Unleash OAuth Worm via 'Google Docs' App
"A malicious app named "Google Docs" by attackers has been making the rounds, attempting to trick Google users into logging in and giving the app access permissions to their account.
The phishing campaign began with an email to victims from an address they likely would have recognized, according to multiple analyses of the attack that have now been posted online by security researchers. But the campaign quickly turned into a worm, as users authorized the bogus app in droves, allowing it to spread to their own contacts."
Attackers Unleash OAuth Worm via 'Google Docs' App
"A malicious app named "Google Docs" by attackers has been making the rounds, attempting to trick Google users into logging in and giving the app access permissions to their account.
The phishing campaign began with an email to victims from an address they likely would have recognized, according to multiple analyses of the attack that have now been posted online by security researchers. But the campaign quickly turned into a worm, as users authorized the bogus app in droves, allowing it to spread to their own contacts."
OSX.Bella: Mac Malware Strikes Again
From Dark Reading:
OSX.Bella: Mac Malware Strikes Again
"This variant of the OSX.Dok dropper behaves altogether differently, and installs a completely different payload.
On Friday, a sophisticated Mac Trojan was discovered called OSX.Dok, which installs malware designed to intercept all HTTP and HTTPS traffic. This morning, Adam Thomas, a Malwarebytes researcher, found a variant of the OSX.Dok dropper that behaves altogether differently and installs a completely different payload."
OSX.Bella: Mac Malware Strikes Again
"This variant of the OSX.Dok dropper behaves altogether differently, and installs a completely different payload.
On Friday, a sophisticated Mac Trojan was discovered called OSX.Dok, which installs malware designed to intercept all HTTP and HTTPS traffic. This morning, Adam Thomas, a Malwarebytes researcher, found a variant of the OSX.Dok dropper that behaves altogether differently and installs a completely different payload."
Europe Pumps Out 50% More Cybercrime Attacks Than US
From Dark Reading:
Europe Pumps Out 50% More Cybercrime Attacks Than US
"Cyberattacks originating from Europe were substantially higher than nefarious activity launched from the US during the first quarter.
Cybercrime attacks launched from Europe reached more than 50 million in the first quarter, double the volume coming out of the US, according to the ThreatMetrix Q1 Cybercrime Report released today."
Europe Pumps Out 50% More Cybercrime Attacks Than US
"Cyberattacks originating from Europe were substantially higher than nefarious activity launched from the US during the first quarter.
Cybercrime attacks launched from Europe reached more than 50 million in the first quarter, double the volume coming out of the US, according to the ThreatMetrix Q1 Cybercrime Report released today."
Google Docs Phishing Scam a Game Changer
From Dark Reading:
Google Docs Phishing Scam a Game Changer
"Experts expect copycats that take advantage of passive authentication from third-party applications using standards such as OAuth.
The Google Doc phishing scam that conned over a million users this week illustrates how attackers cleverly respond to wider spread end-user awareness about how phishing attacks work."
Google Docs Phishing Scam a Game Changer
"Experts expect copycats that take advantage of passive authentication from third-party applications using standards such as OAuth.
The Google Doc phishing scam that conned over a million users this week illustrates how attackers cleverly respond to wider spread end-user awareness about how phishing attacks work."
The Bondnet Army
A technical overview of the Bondnet Army botnet from GuardiCore:
The Bondnet Army
"GuardiCore Labs has recently picked up Bondnet, a botnet of thousands of compromised servers of varying power. Managed and controlled remotely, the Bondnet is currently used to mine different cryptocurrencies and is ready to be weaponized immediately for other purposes such as mounting DDoS attacks as shown by the Mirai Botnet. Among the botnet’s victims are high profile global companies, universities, city councils and other public institutions."
The Bondnet Army
"GuardiCore Labs has recently picked up Bondnet, a botnet of thousands of compromised servers of varying power. Managed and controlled remotely, the Bondnet is currently used to mine different cryptocurrencies and is ready to be weaponized immediately for other purposes such as mounting DDoS attacks as shown by the Mirai Botnet. Among the botnet’s victims are high profile global companies, universities, city councils and other public institutions."
Thursday, May 4, 2017
How does the boot mode vulnerability in Android work?
From SearchSecurity:
How does the boot mode vulnerability in Android work?
"Google recently shut down the boot mode vulnerability in Android that allowed hackers to eavesdrop on calls. Can you explain how this exploit works?
It takes a few steps for the boot mode vulnerability exploit to work. First, the attacker infects a PC with malware through the internet. Then, the attacker waits for the victim to enable Android Debug Bridge (ADB) after manually connecting his Nexus 6 or 6P phone to the infected PC."
How does the boot mode vulnerability in Android work?
"Google recently shut down the boot mode vulnerability in Android that allowed hackers to eavesdrop on calls. Can you explain how this exploit works?
It takes a few steps for the boot mode vulnerability exploit to work. First, the attacker infects a PC with malware through the internet. Then, the attacker waits for the victim to enable Android Debug Bridge (ADB) after manually connecting his Nexus 6 or 6P phone to the infected PC."
7 Steps to Fight Ransomware
From Dark Reading:
7 Steps to Fight Ransomware
"Perpetrators are shifting to more specific targets. This means companies must strengthen their defenses, and these strategies can help.
Ransomware can be a highly lucrative system for extracting money from a customer. Victims are faced with an unpleasant choice: either pay the ransom or lose access to the encrypted files forever. Until now, ransomware has appeared to be opportunistic and driven through random phishing campaigns. These campaigns often, but not always, rely on large numbers of emails that are harvested without a singular focus on a company or individual."
7 Steps to Fight Ransomware
"Perpetrators are shifting to more specific targets. This means companies must strengthen their defenses, and these strategies can help.
Ransomware can be a highly lucrative system for extracting money from a customer. Victims are faced with an unpleasant choice: either pay the ransom or lose access to the encrypted files forever. Until now, ransomware has appeared to be opportunistic and driven through random phishing campaigns. These campaigns often, but not always, rely on large numbers of emails that are harvested without a singular focus on a company or individual."
Google Docs Phishing Attack Abuses Legitimate Third-Party Sharing
From Dark Reading:
Google Docs Phishing Attack Abuses Legitimate Third-Party Sharing
"Phishing messages appear nearly identical to legitimate requests to share Google documents, because in many ways, they are.
Google users today were hit with an extremely convincing phishing spree launched by attackers who manipulated Google Docs' legitimate third-party sharing mechanism."
Google Docs Phishing Attack Abuses Legitimate Third-Party Sharing
"Phishing messages appear nearly identical to legitimate requests to share Google documents, because in many ways, they are.
Google users today were hit with an extremely convincing phishing spree launched by attackers who manipulated Google Docs' legitimate third-party sharing mechanism."
Update: Google Doc phishing story takes some bizarre turns
From Sophos Naked Security:
Update: Google Doc phishing story takes some bizarre turns
"Since news began circulating last night of a phishing campaign parading around as Google Doc access links, the tale has taken strange twists and turns.
A self-described graduate student claims he was behind the blast of emails, and that they were part of a test for a school project, not a phishing attack. But according to the university he claims to be enrolled at, he’s not a student there."
Update: Google Doc phishing story takes some bizarre turns
"Since news began circulating last night of a phishing campaign parading around as Google Doc access links, the tale has taken strange twists and turns.
A self-described graduate student claims he was behind the blast of emails, and that they were part of a test for a school project, not a phishing attack. But according to the university he claims to be enrolled at, he’s not a student there."
FYI - to help reduce the attack surface block:
hhhhhhhhhhhhhhhh @ mailinator . com
on your email system(s).
Wednesday, May 3, 2017
OAUTH phishing against Google Docs ? beware!
From SANS ISC:
OAUTH phishing against Google Docs ? beware!
We got several reports (thanks to Seren Thompson, Tahir Khan and Harry Vann) about OAUTH phishing attacks against Google users. The phishing attack arrives, of course, as an e-mail where it appears that a user (potentially even one on your contact list, so it looks very legitimate) has shared a document.
An image of such an e-mail is shown below:

OAUTH phishing against Google Docs ? beware!
We got several reports (thanks to Seren Thompson, Tahir Khan and Harry Vann) about OAUTH phishing attacks against Google users. The phishing attack arrives, of course, as an e-mail where it appears that a user (potentially even one on your contact list, so it looks very legitimate) has shared a document.
An image of such an e-mail is shown below:

How does USB Killer v3 damage devices through their USB connections?
From SearchSecurity:
How does USB Killer v3 damage devices through their USB connections?
"USB Killer devices, with the ability to destroy systems via a USB input, are available and inexpensive. Expert Nick Lewis explains how they work and how to defend against this threat."
How does USB Killer v3 damage devices through their USB connections?
"USB Killer devices, with the ability to destroy systems via a USB input, are available and inexpensive. Expert Nick Lewis explains how they work and how to defend against this threat."
WordPress Attacks Powered by Router Botnet Drop Rapidly
From SecurityWeek:
WordPress Attacks Powered by Router Botnet Drop Rapidly
"A botnet powered by compromised home routers has been apparently shut down. It is unclear if the botnet operators decided to pull the plug on their operation or if the disruption was caused by law enforcement.
Security firm Wordfence warned last month that tens of thousands of vulnerable routers from dozens of ISPs worldwide had been abused for brute-force and other types of attacks aimed at WordPress websites."
WordPress Attacks Powered by Router Botnet Drop Rapidly
"A botnet powered by compromised home routers has been apparently shut down. It is unclear if the botnet operators decided to pull the plug on their operation or if the disruption was caused by law enforcement.
Security firm Wordfence warned last month that tens of thousands of vulnerable routers from dozens of ISPs worldwide had been abused for brute-force and other types of attacks aimed at WordPress websites."
New Cerber Ransomware Variant Emerges
From SecurityWeek:
New Cerber Ransomware Variant Emerges
"A new variant of the Cerber ransomware has emerged over the past month, featuring multipart arrival vectors and refashioned file encryption routines, TrendMicro security researchers warn.
An active threat for over a year, Cerber managed to climb at the top of ransomware charts earlier this year, accounting for 87% of attacks in the first quarter of 2017. The rise was fueled mainly by a major decrease in Locky attacks, but Cerber’s popularity among cybercriminals also helped."
New Cerber Ransomware Variant Emerges
"A new variant of the Cerber ransomware has emerged over the past month, featuring multipart arrival vectors and refashioned file encryption routines, TrendMicro security researchers warn.
An active threat for over a year, Cerber managed to climb at the top of ransomware charts earlier this year, accounting for 87% of attacks in the first quarter of 2017. The rise was fueled mainly by a major decrease in Locky attacks, but Cerber’s popularity among cybercriminals also helped."
Google Patches More Critical Flaws in Android Mediaserver
From SecurityWeek:
Google Patches More Critical Flaws in Android Mediaserver
"Google this week announced the contents of the May 2017 Android security patches, revealing that six Critical Remote Code Execution (RCE) flaws were addressed in the Mediaserver component.
Over the past couple of years, Mediaserver emerged as one of the most vulnerable Android components, after a Critical RCE bug dubbed Stagefright was said to affect 950 million devices. Detailed in July 2015, the vulnerability encouraged Google to issue monthly security updates for Android."
Google Patches More Critical Flaws in Android Mediaserver
"Google this week announced the contents of the May 2017 Android security patches, revealing that six Critical Remote Code Execution (RCE) flaws were addressed in the Mediaserver component.
Over the past couple of years, Mediaserver emerged as one of the most vulnerable Android components, after a Critical RCE bug dubbed Stagefright was said to affect 950 million devices. Detailed in July 2015, the vulnerability encouraged Google to issue monthly security updates for Android."
Want to get your Android phone purring? Don’t install Full Optimizer
From Sophos Naked Security:
Want to get your Android phone purring? Don’t install Full Optimizer
"If you’re no fan of advertisements popping up on your device, you’ll want to avoid two apps in Google Play: Full Optimizer and Full Optimizer Lite. They deliver adware and don’t really do the things the developer claims."
Want to get your Android phone purring? Don’t install Full Optimizer
"If you’re no fan of advertisements popping up on your device, you’ll want to avoid two apps in Google Play: Full Optimizer and Full Optimizer Lite. They deliver adware and don’t really do the things the developer claims."
Subscribe to:
Posts (Atom)