Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Friday, March 25, 2011

Report: Mysterious Facebook Web Search Box Could Be Malware

A Web search box some users are seeing on their Facebook interface wasn't inserted by Facebook and could be the result of malware or a rogue browser plug-in or application.

AllFacebook, a blog devoted to Facebook-related news, first reported that a second search box had begun to appear on Facebook interfaces, right next to the legitimate site search bar.

The mysterious Web search box appeared perfectly integrated into the Facebook page layout, as if it were a native Facebook feature. However, Facebook is now saying that it didn't put that second search box there and that it could be a sign of malware infection.

"We are not testing the placement of a separate web search field and have no plans to do so. We believe the second search field or 'Search the Web" box appeared on peoples' accounts as the result of unknown actions by a third party targeting the browser -- potentially a browser plugin or malware -- unrelated to Facebook," a Facebook official told technology news blog Search Engine Land.

As Facebook members, users who think they might be affected by this situation have access to a free, browser-based virus scanning tool from McAfee, according to the company.

As the most popular social network and one of the world's largest sites, Facebook is in a constant battle against malicious hackers and online scammers who want to take advantage of its massive user base to commit fraud and spread malware.

At this point, it's not clear whether the sinister search box is the result of an external malware exploit or the work of a rogue Facebook application.





Monday, July 19, 2010

VeriSign 'Trusted' Service Now Scans Sites for Malware

VeriSign said Monday that it has begun to add a "VeriSign Trust Seal" logo to search results and on Web sites, that can be used to verify that a site does not harbor malware.

VeriSign already places a logo on some sites that tells the user that it has secured the site via an SSL certificate. The "VeriSign Trusted" logo now also means that the site is checked on a daily basis to see if an attacker was able to penetrate its security and inject malware that would then be downloaded by the site's customers.

A related "Seal-in-Search" technology will place a VeriSign logo next to search results, including Google, alerting users that VeriSign has certified the site as safe to visit, where malware is concerned.

"In the face of increasingly elaborate attacks and fraud schemes, web sites need solutions that do more than data encryption," said Tim Callan, vice president of product marketing at VeriSign. "By enhancing our SSL Certificate services with new features that instill trust at every step of the online experience—at no additional charge to our customers—we're delivering a more robust and value-driven solution. In the process, we're redefining what web sites should expect from online security."

Tuesday, May 11, 2010

New malware attack laughs at your antivirus software

How do you get a malware exploit to bypass antivirus protection? By making it work the same way the antivirus software does.

A new exploit outlined this week is so effective, say researchers, that it can slip by “virtually all” antivirus protection undetected.

It works the same way an antivirus app does, by hooking directly into Windows and masquerading as harmless software. It tricks Windows by sending sample code to the OS, like any antivirus app that looks (and in reality is) completely benign, then at the last microsecond it swaps in malicious code, which is then executed.

If an antivirus application uses the traditional method of interacting with Windows — a system called SSDT — then it will be vulnerable to attack via this method. And they all use SSDT. As the researchers at matousec.com noted during their investigation, “100 percent of the tested products were found vulnerable.” It didn’t matter if the user had administrator rights or not, the exploit was able to sneak through.

The good news is that the attack isn’t completely realistic, since the size of the code required would have to be large to work. A quickie download wouldn’t be possible, so the attack would likely have to find its way onto a target computer by other means. But that also worries researchers, since commonly downloaded software could be intentionally infected with the malware (the story above uses Adobe Reader as an example) and during installation your antivirus software wouldn’t bat an eyelash. The malware could actually uninstall your antivirus application in its initial volley, leaving you wide open to attack.
news.yahoo.com/

Tuesday, March 9, 2010

Energizer USB Charger Software Contains Malware

A USB charger from Energizer uses software that contains a Trojan, according to US-CERT. The software was apparently developed outside the U.S. and may have been giving hackers access to PCs since 2007. An analyst said trust in the Energizer bunny may have led many consumers to install the DUO USB charger malware even with a warning.

Some Windows PC users may hope the Energizer bunny didn't keep going and going. It turns out the Energizer DUO USB battery charger is a vehicle for attacks on PCs, according to the Department of Homeland Security's Computer Emergency Readiness Team.

US-CERT researchers said Friday that the software that installs with the Energizer charger contains a Trojan horse that gives malicious hackers a back door into Windows machines.

"An attacker is able to remotely control a system , including the ability to list directories, send and receive files, and execute programs. The backdoor operates with the privileges of the logged-on user," US-CERT said. "Removing the Energizer USB charger software will also remove the registry value that causes the backdoor to execute automatically when Windows starts."

A Trusted Source

Although the fix seems relatively easy for consumers who are aware they have been infected, the path in was also straightforward. Rob Enderle, principal analyst at the Enderle Group, said consumers were probably not expecting the Energizer software to carry a malicious payload.

"Typically in a Windows 7 or even a Windows Vista install, if you mess around with ports you should get a warning," Enderle said. "Because consumers got the software from a trusted source, chances are you'll bypass the warning and go ahead and install it because you think you are only installing the battery monitor. This is a nasty piece of work."

Enderle questioned the origin of the software, noting that Trojans seem to make their way into programs when the software is developed outside the U.S. Chances are, he said, the software was developed in China or some other foreign country. newsfactor.com

Monday, February 22, 2010

New Report Examines Malware's Origins, Motivations

Another great article from Tim Wilson over at DarkReading ...

Nearly every day, industry analysts and security researchers warn IT professionals about the skyrocketing proliferation of malware. A simple Web search turns up many reports that dissect the technical nature of malicious software, how it works, and how it affects its victims.

But who develops malware, and who distributes it? Who buys it, and what do they hope to achieve? Ask these questions in a Web search, and you'll find far fewer results.

In a report issued last week, ScanSafe security researcher Mary Landesman offers some thoughts on the genesis and spread of malware -- this time from a business perspective, rather than a technical point of view. While Landesman's report -- part of ScanSafe's "Annual Global Threat Report" -- is far from the first to offer insight on the business of malware, it does offer a snapshot of the current state of the malware business and a clear categorization of the players.

While many outside of the security industry still perceive "hackers" as teenagers or isolated geeks who work alone, Landesman's report encourages security professionals -- and the general public -- to see malware as a cooperative industry that supports specialists, economies, and supply chains. "Malware is every bit as layered as any other industry," she says. "There are mom-and-pop shops. There are big giants. There are suppliers and developers and a global market."

Many business executives " and even some IT pros " are too focused on the group of cybercriminals that can be categorized as "sole proprietors," Landesman says. "These are the ones we hear the most about " the phishers, the carders, the people repackaging scareware to drive users to malicious sites," she observes. "These are the equivalent of the street seller in the drug trade " they're looking to make a quick score, either for their own benefit or feeding up to a kingpin of some sort."

But as with street sellers of drugs, most "sole proprietors" don't make the product that they're dealing with, Landesman explains. "It's pretty unusual these days to see a [cybercriminal] who does everything " someone who writes the software, distributes it, harvests the data, and then uses it to make money. More and more now, those jobs are being done by different people, operating in a true market."

Today's malware is usually created by the "developer" category of individuals -- those who are creative and skilled in writing code, Landesman says. "For many of them, in their minds, they're not doing anything wrong," she says. "They're finding ways around security, developing new tools, and they feel they aren't responsible for what is done with the tools they develop. It's sort of like making guns -- the notion that malware doesn't do crime, it's the people who use it that do the crime."

Developers sometimes make extra cash by selling their exploits, but they seldom get rich doing so, Landesman says. Often, the tools are purchased, refined, and repackaged by a group of individuals who Landesman calls "middlemen" -- those who attempt to bridge the gap between the attacker and the victim.

"Again, the middleman is not usually somebody who developed the malware, but they are sort of the 'public face' of it," Landesman explains. "They're like a manufacturer's representative: They advertise the exploit kits, they sell them, many of them offer tech support, even on a 24/7 basis. They even publish bug reports and offer patches and updates."

The success of the "middleman" sales and distribution model is a key reason why malware is proliferating so quickly across the globe, Landesman postulates. As more and more middlemen get into the business -- selling exploit packages as cheaply as $100 -- they help to speed the availability of the latest malware across the globe, bringing new exploits to bear at a pace that often cannot be matched by traditional security tools, which require constant updates. "The success of the [middleman] business model is being proven by the growth of malware," she says.

Working in a fast-growing, highly competitive market, however, most middlemen are not getting rich, either, Landesman says. "They may make a decent living for the country they live in, but it's not a lot," she states.

There are other players in the malware chain, such as "mules," who help distribute malware or launder stolen money, and botnet operators, who provide the infrastructure for mass malware distribution. But the most mysterious category is the malware buyer -- those who pay to put it out there.

"The sole proprietor, middleman, and developer all have something to gain by publicly advertising their offerings," Landesman writes in the report. "Conversely, there will be no such public displays from the buyer, particularly those criminals engaged in hardcore cyber-espionage, such as the attacks leveraged against Google, Adobe, oil companies, and multiple other firms over the past year." darkreading.com

Thursday, January 7, 2010

25 Million Strains of Malware Identified in 2009


More than 25 million new strains of malware were created last year, says PandaLabs.

According to the security vendor's Annual Malware Report, the number of new versions of malware identified has topped the 15 million identified throughout the company's 20-year history.

PandaLabs said that 66 percent of the new malware identified were banking Trojans, and the next popular type was scareware, also known as fake antivirus software that encourages web users to part with their hard-earned cash to download hoax security software that serves no purpose.

The security vendor predicts that the amount of malware in circulation will continue to grow during 2010. pcworld

Monday, January 4, 2010

Sunbelt Software Announces Top 10 Malware Threats for December


These threats are classified moderate to severe based on method of installation among other criteria established by SunbeltLabs. The majority of these threats propagate through stealth installations or social engineering.

The top 10 most prevalent malware threats for the month of December are:

1. Trojan.Win32.Generic!BT 18.69%

2. Trojan-Spy.Win32.Zbot.gen 6.23%

3. Trojan.Win32.Generic!SB.0 4.09%

4. Exploit.PDF-JS.Gen (v) 3.31%

5. Trojan.ASF.Wimad (v) 2.42%

6. Fast Browser Search 2.40%

7. Trojan.Win32.Malware 2.23%

8. INF.Autorun (v) 1.62%

9. BehavesLike.Win32.Malware (v) 1.18%

10. Trojan.Malware 0.94%


Malicious operators use Search Engine Optimization (SEO) techniques to lure victims to malicious sites that download Trojans. These sites place in the top hits in many online search engines when Internet surfers search for current news topics.

Some of the most dangerous web searches in December were:


-- "Brittany Murphy" (leads to redirect sites selling rogues)

-- "chromium os download" (leads to rogue download sites)

-- "New Year's Parades"

--"Tiger Woods car crash" (sites offer videos with Trojanized video

viewers)

-- "Tiger Woods rumors"

prnewswire

Sunday, January 3, 2010

Security Advice for 2010: Trust No One


Not everything is at it appears. While this should be a no-brainer for anybody venturing onto the Web, this little piece of advice will pay higher dividends in the new year, according to security experts, who say cybercriminals are increasingly preying on people's misplaced trust in each other and popular Web sites. This advice applies especially to hot technologies, such as social networking and smart phone users, but also anybody who uses search engines, clicks on Internet ads, or sits in front a Mac they thought was safe.

Social networking Web sites such as Facebook, MySpace, Google Wave, and Twitter will become major focuses of cybercriminals looking to spread malware and steal sensitive data. That's the prediction of many major Internet security firms, including McAfee Labs and Websense Security Labs.

McAfee Labs, which published its 2010 Threat Predictions report in late December, suggests that users of Facebook and Twitter are especially vulnerable because they put too much trust into the systems, the underlying technology, and other users.

For example, the use of abbreviated URLs on Twitter makes it easier for cybercriminals to mask and direct users to malicious Web sites, the security group notes. Similarly, on Facebook, McAfee fears that rogue software writers will take advantage of "friends trusting friends" to get users to click on links they might otherwise treat cautiously.

The protective blanket of anonymity enjoyed by non-mainstream (i.e., non-Windows) platforms such as Mac OS and Linux will be a little thinner this year, thanks to a new generation of cross-platform malware enabled by technological advances, such as enhancements in HTML 5, McAfee Labs predicts. Google's Chrome OS will also do much to further the democratization of cyber threats. itjungle

Friday, December 4, 2009

Thanksgiving Webcam Promo Leads to Malware


The $10 Webcam that Anna Giesman bought her daughter at Office Depot over the Thanksgiving weekend sounds like one of those deals that's too good to be true. And for her, it was.

A week later, she's worried and upset because a CD that came with the camera contained a Web link that apparently infected her PC with fake antivirus software.

Her story shows how easily malware can get onto the computers of unsuspecting consumers in an era when cyber-criminals are becoming expert at hacking legitimate Web sites to prey on their visitors.

Giesman bought the camera in order to give her daughter a way to chat over the Internet with a friend who had just moved to Germany. When she put the CD that came with the Markvision Magnetic Webcam into her PC, a menu popped up offering her drivers as well as a link to Markvision's site. Wanting to learn more about the product, she clicked on the Web link, but she immediately knew something was wrong.

The Web page was blank, and her PC immediately popped up a window telling her she needed to upgrade her Windows software. When she clicked on the red "X" to dismiss the window, another popped up that made it look like her computer was being scanned. That scan was blocked by her McAfee antivirus program, but Giesman was still worried.

Panicked, she shut down the computer and called Office Depot. Their support technicians told her to try a free antivirus program -- Avast -- which then identified rogue antivirus files on her computer. Computerworld

Thursday, December 3, 2009

Malware Messes up India's Online Test for Business Schools


The move by India's top business schools to take their CAT entrance test online turned embarrassing after malware-infected computers left a number of students unable to take the test.

Prometric, a Baltimore, Maryland, testing company hired to conduct the CAT (Common Admission Test), said this week that the testing labs faced technical difficulties mainly due to malware and viruses. It said on the CAT Web site that it has decided to reschedule the tests for the affected students.

Over 240,000 candidates registered for the CAT 2009, which was scheduled to run from Nov. 28 to Dec. 7. While the written test was held on a single day in previous years, the online test this year was spread over 10 days, giving candidates the option to choose a date and center for the test.

Prometric was to conduct the tests across labs in 32 cities in the country. The tests are continuing after the initial disruption.
pcworld

Friday, November 6, 2009

Gumblar Malware's Home Domain Is Active Again


ScanSafe researchers are seeing renewed activity regarding Gumblar, a multifunctional piece of malware that spreads by attacking PCs visiting hacked Web pages.

Gumblar can steal FTP credentials as well as hijack Google searches, replacing results on infected computers with links to other malicious sites.

When the Gumblar malware was found in March, it looked for instructions on a server at gumblar.cn. That domain was taken offline at the time, but has been reactivated within the last 24 hours, wrote Mary Landesman, a senior security researcher with ScanSafe, on a company blog.

Web sites that are infected with Gumblar contain an iframe, which is a way to bring content from one Web site into another. Malware writers usually make those iframes invisible. When a victim visits the site, the iframe will launch a series of exploits hosted on a remote computer to try and hack the visiting machine.

Gumblar checks to see if the victim's PC is running unpatched versions of Adobe Systems' Reader and Acrobat programs. If so, the machine will be compromised by a so-called drive-by download.

Domain name registrars will often suspend domain names that have been used for malicious purposes, and malware writers will usually frequently change the domains their software looks to for instructions as those bad domains are blacklisted. For some reason, the gumblar.cn domain was released and is in use again.
PC World

Wednesday, September 16, 2009

Malware goes viral via search engines

We all had a chuckle in the newsroom over the Serena Williams poisoned search attack that didn’t work. Unsuspecting users searching for news or videos of the Serena Williams meltdown were, in some cases, directed to a malware site that infected users’ computers. But when the site was investigated by Symantec, the malicious file was found to be corrupt and did not run. A lucky break for those who went to the site, but as our security ace Bill Jackson put it, “you can’t always count on incompetent hackers to protect your computer.”


But apparently, you can pretty much count on unsuspecting users to damage a computer. Here are some news reports on recent attacks that relied on social engineering to trick users into trouble. (Not to worry: we’re sending you to the news reports, not the malicious links.)

Darkreading.com picked up word that the recently deceased actor Patrick Swayze (star of Dirty Dancing) may also be suspect of poisoned search attacks.

And right on the heels came a similar attack on people searching for information on the California wildfires and the September 11 anniversary.

It’s not just fringe sites that are hosts to viruses. Recently NYTimes readers got ambushed by fake ads for antivirus software.

Meanwhile, on Facebook, users were alerted to the need for a “removal kit” to clean up an embedded virus on a Facebook application. Turns out the removal kit is the malfarious culprit, according to Computerworld.

Makes you wonder what it takes to get a geek to bite on a viral hook. Any other lines floating around out there?

GNC

Wednesday, August 26, 2009

Report: Snow Leopard To Confront Mac Malware

Adding anti-malware to Snow Leopard is a Catch-22 for Apple: In solving a problem, Apple must first admit a problem actually exists. Which is hard when one of your major selling points is that you're secure and your major competitor--Microsoft Windows--is not.

Security vendor Intego made the apparent discovery of anti-malware features in Snow Leopard, evidence of which is being shown on its Web site. Apple has neither confirmed or denied the report.

If there really is anti-malware in Snow Leopard, due for release on Friday, it would be helpful for Apple to fess-up now. It would improve first-day sales, which might help Apple forget the bitter taste of crow, which Microsoft will presumably serve up.

There seems to be no compelling reason for Apple to add the feature right now. The world is not suffering a pandemic of Apple malware. Rather, most Mac users continue to run their systems without any type of protection.

Nevertheless, adding the protection, if that is what Apple has really done, is a good idea. If it is a good anti-malware solution and offers all the protection a user needs, it will make Snow Leopard a good deal and worth the expense.

Having just yesterday complained that even at $10 (in a 5-user package) the Snow Leopard upgrade might cost more than its worth, I am ready to change my mind. I'd happily pay a good bit more than $10 to have Apple solve all my malware troubles, even the ones I don't yet have.

It is clear that, over time, Macintosh will become a more frequent malware target. Apple's free ride is going to come to an end. It is wise for Apple to deal with the future challenge itself, though a free upgrade would reach many more users more quickly than Snow Leopard will following its release this Friday.

But, since there is no hurry and the feature presumably costs money (and certainly adds value) an inexpensive paid upgrade makes sense.

PC World

Tuesday, August 25, 2009

55,000 Web Sites Hacked To Serve Up Malware Cocktail

Got this article from a great blog called *Zero Day  written by Ryan Naraine. Try to enjoy your cocktail...C.S.G.
Security researchers are raising an alarm for a potent malware cocktail — backdoor Trojans and password stealers — being pushed to Windows users from about 55,000 hacked Web sites.
According to Mary Landesman, a researcher in ScanSafe’s security threat alert team, the cybercriminals have embedded a malicious iFrame into tens of thousands of Websites to fire exploits at unsuspecting PC users who surf to one of the rigged sites.
The iFrame points to an intermediary exploit site which in turn loads additional exploits and malware from up to seven different malware domains, Landesman said.
She ran a Google search of the iFrame script tag and found it embedded on about 54,900 sites, many of them legitimate online destinations.

Victim sites include www.feedzilla.com, latindiscover.com, and a number of charitable and nursing facilities, including howellcarecenter.com, sweetgrassvillagealf.com, www.foodsresourcebank.org, and morningsideassistedliving.com.

At the time of writing this blog post, the number of hacked sites listed in Google results climbed to 56,000.

It is not yet clear which vulnerabilities are being exploited in this attack but, judging from recent history, end users should ensure that operating system and desktop software programs are fully patched.

The most common programs under attack include Adobe Flash, Adobe PDF Reader, Apple’s QuickTime, WinZip and RealPlayer. In addition to Microsoft Windows patches, these desktop applications should be updated to the newest version immediately.

* Zero Day

Sunday, August 23, 2009

Profile of a hacker: How the "soupnazi" did it

The man allegedly behind the biggest identity theft ever did it through a fairly simple ploy...
Monday, one of the most brazen hackers in American history was indicted in federal court in New Jersey. Federal authorities allege that Albert Gonzalez, along with two unnamed Russian associates, engineered one of the largest credit card and identity theft schemes in history. But this is hardly Gonzalez's first run-in with authorities over cyber-crimes. Here's a snapshot of Gonzalez and his short but startling history of plaguing American businesses and consumers.

Profile of a hacker:
Name: Albert Gonzalez
RedditAge: 28
Online pseudonyms: segvec, soupnazi, Cumbajohnny and j4guar17
Current co-conspirators: Two men from Russia who authorities did not identify by name.
Past criminal affiliations: Leader of Shadowcrew, an online credit-card hacking ring. In 2004, 26 of the 4,000 members of the hacking crew were arrested and convicted.

Gonzalez's hacking timeline:
2003: Gonzalez was arrested for hacking but not charged with a crime because he agreed to work as an informant for the Secret Service on cyber-crimes. Yet, according to the Justice Department, he was again engaging in illicit activities fairly soon after his arrest.

October 2004: The government arrests members of the Shadowcrew. Gonzalez was the alleged leader of this hacking group.

November 2004: Gonzalez is allowed by the government to move from New Jersey to Florida. He then begins his hacking of Dave & Buster's restaurant chain.

October 2006-May 2008: Gonzalez and his associates targeted Fortune 500 companies with network security problems. He allegedly stole over 130 million credit and debit card numbers from Heartland Payment Systems Inc., a credit card payment processor, 7-Eleven, a national convenience store chain, and Hannaford Brothers Co., a supermarket chain. He was indicted for his leadership in this hacking ring Monday. Heartland is the world's 9th largest credit card processor.

May 2008: Gonzalez has been in custody since May 2008 when he was arrested for data theft at Dave & Buster's.

August 2008: Gonzalez is indicted for improperly probing the networks of many major U.S. retailers including TJX Companies (owner of TJ Maxx), BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW. At the time, it was thought to be the largest individual instance of credit card data theft via the hacking of private computer systems, as nearly 40 million card numbers were stolen. Authorities have said the breach cost TJ Maxx close to $200 million.

August 2009: Gonzalez and two unnamed associates are charged in federal court in New Jersey with running the largest credit card and identity theft hacking operation ever prosecuted. Gonzalez was already awaiting trial in New York for his hacking of the network at Dave & Buster's restaurants and in Massachusetts for his penetration of TJX Companies.

How he did it:
By all accounts, what makes Gonzalez's success so terrifying for consumers is that his alleged hacking ring was not very sophisticated. Officials have said Gonzalez used a technique called "wardriving," in which he and his associates travel to different areas searching for accessible wireless Internet networks. They then hacked into these networks, installing "sniffer programs" and "malware" software that allowed them to steal credit and debit card numbers from retailers. Gonzalez exploited holes in the SQL programming language used by many databases.

In the charges brought against Gonzalez on Monday, authorities said that once Gonzalez and his co-hackers captured the personal data, they'd send the information to computer servers in California, Illinois, Latvia, the Netherlands and Ukraine. Gonzalez would either then sell the numbers online or make purchases or unauthorized withdrawals from the banks the cards were linked to.

Gonzalez and his associates face anywhere from 35 years in prison to possible life sentences if convicted on all the charges currently brought against them. They also may have to pay more than a $1 million in fines.

What consumers should know:
•According to identity theft experts, restaurants are particularly attractive for hackers because they seldom update their anti-virus software and other computer security systems.

•Not all states require companies to notify consumers once their information has been compromised. It is unknown whether those affected by Gonzalez's heist were ever even alerted.

•If you're worried about identity theft, you should check the government's site here: FTC Id Theft

Salon