Google Search

Showing posts with label Inside. Show all posts
Showing posts with label Inside. Show all posts

Friday, September 20, 2013

Inside the "PlugX" malware with SophosLabs - a fascinating journey into a malware factory...

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Malware

Join SophosLabs Principal Researcher Gabor Szappanos (Szappi) as he takes you on a fascinating journey into the PlugX malware factory.

This is a malware family that keeps evolving as the criminals in charge of it churn out new variants.

Just like legitimate software, malware has major version upgrades and point releases.

In this paper, Szappi looks at the recently-released Version 6.0 of the PlugX malware framework.

You'll enjoy Szappi's paper because it's not so technical as to get bogged down in researcher-only jargon, yet not so high-level as to skip over the details that help you to understand how virus writers think.

Szappi writes clearly and logically, taking apart and explaining the numerous and deliberately-distinct phases in the malware's infection mechanism.

Splitting up malware means that each step does only a small piece of the overall work, in order to avoid looking suspicious on its own.

The aim is to reduce the chance of being flagged as dangerous by heuristic defences that expect more complex behaviour.

Szappi even uses some debugging features left behind in the malware to estimate the size of the programming project behind it, using a statistical technique first used in anger during the Second World War.

The Allies used it to convert observations from the field into reliable estimates of how many tanks the Nazis had at their disposal; now it's turned against the PlugX crew.

And Szappi describes how, and why, the malware carries around with it a pirated copy of a legitimate, digitally-signed application (this one is from Chinese social media outfit Tencent) to help it do its dirty work.

A fascinating paper, well worth reading: clearly written, interesting, and informative.

Download now

Follow @duckblog


View the original article here

Monday, January 14, 2013

Technical paper: Journey inside the Blackhole exploit kit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Plug hole. Image from ShutterstockOne of the most common questions we receive at SophosLabs is "How are users most likely to get infected with malware?".

As regulars readers will be aware, the answer is through the web. More specifically, computers are most likely to be infected through compromised legitimate websites redirecting user traffic to malicious websites that are hosting some exploit kit.

The most active of these exploit kits in recent times is one known as Blackhole.

Properly understanding how the Blackhole exploit kit works and why it has become the most popular of the various exploit kits available is important in order to provide the best protection to our customers.

Previous research focused on early versions of the Blackhole exploit kit, and the tricks used by the attackers in evading detection.

More recently, SophosLabs expert Gabor Szappanos has been delving deeper into the internal workings of the Blackhole exploit kit, to get a more thorough understanding of how it works.

Gabor's technical paper, entitled "Inside a Black hole", is now available, and I would encourage all readers to download it and learn more about the Blackhole exploit kit.

http://twitter.com/SophosLabs

Plug hole image from Shutterstock.


View the original article here

Wednesday, April 4, 2012

Mac backdoor Trojan embedded inside boobytrapped Word documents

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Apple store. Image credit: pcruciatti / Shutterstock.comThe folks at AlienVault discovered an interesting new Mac malware attack this week.

A backdoor Trojan horse, which would allow a remote hacker to access your Mac computer without your knowledge and potentially snoop on your files and activity, has been discovered hidden inside a boobytrapped Word document.

The targeted attack relies upon a critical security vulnerability discovered in Microsoft Word back in 2009, which allowed remote code execution (MS09-027).

In a nutshell, if you open the boobytrapped Word document, a Trojan horse gets dropped onto your Mac opening a backdoor for remote hackers. Furthermore, a decoy document called file.doc is also dumped onto your drive.

Dropped decoy Word document

The nature of the decoy document, which claims to be about Human Rights abuses in Tibet by the Chinese, is sure to raise some eyebrows.

Inevitably there will be speculation that this attack is related to 'Ghostnet', the alleged campaign by China to spy via the internet on pro-Tibet organisations, including the Tibetan government-in-exile and the private office of the Dalai Lama.

If that's the case, then it would seem that 'Ghostnet' is now targeting Mac users inside organisations sympathetic to Tibet and banned Chinese groups.

And don't be fooled into thinking that you are protected by Mac OS X itself, which will ask for an administrator's username and password to install software. You won't see any prompt for credentials when this malware installs, as it is a userland Trojan.

Neither the /tmp/ nor /$HOME/Library/LaunchAgents folders on Mac OS X require root privileges - meaning that software applications can run in userland with no difficulties, and even open up network sockets to transfer data.

Mac malware hex dump

Sophos anti-virus products detect the malformed Word documents as Troj/DocOSXDr-A and the Mac backdoor Trojan horse as OSX/Bckdr-RLG. The servers that the malware attempts to communicate with have been categorised by Sophos as malware repositories since at least 2009.

Once again, Mac users need to remember to not be complacent about the security of their computers. Although there is much less malware for Mac than there is for Windows, that is going to be no compensation if you happen to be targeted by an attack like this.

If you're not already doing so, run anti-virus software on your Macs. If you're a home user, there really is no excuse at all as we offer a free anti-virus for Mac consumers.

Follow @gcluley

Image credit: pcruciatti / Shutterstock.com


View the original article here

Tuesday, August 23, 2011

Hanging With Hackers: Inside Germany's Great 'Geek' Convention - TIME

Computer users take part in the Chaos Communication Camp, August 10, 2011, in Brandenburg, Germany.

This post is in partnership with Worldcrunch, a new global-news site that translates stories of note in foreign languages into English. The article below was originally published in Süddeutsche Zeitung.

BRANDENBURG — Kristian's NXP ARM Cortex-M3 processor isn't doing what he wants it to. "The mesh isn't working right," says the 29-year-old Norwegian.

A small rocket with tiny bright lights, wires and a display hangs around his neck. But it's not connecting with his friends' rockets, and his friends are sitting right there. No mesh means no communication, at least no digital communication — and that, in the largest hackers' camp on the planet, is a real problem.

The geeks are tightly packed together in the "hacking center" — a hangar in this Brandenburg no-man's land. In front of them are their laptops, with the other, digital world, on the screens. Many of these folks return only reluctantly to the real world.

For the non-initiated, a visit to Finowfurt, the former Soviet airfield, where over 3,000 hackers have been camping at the Chaos Communication Camp since last Wednesday, is a diverting sight indeed. (See a gallery of Who's Who in the U.K. Phone-Hacking Scandal.)

The many men and few women camping near the cracked tarmac are for some — and were, even before Wikileaks' revelations — modern-day Robin Hoods, the last defenders of citizen rights, fighters against a capitalist world. To some companies and governments, however, they are criminals. Ordinary folk may write them off simply as computer nerds.

In and among old Soviet fighter planes and wrecked tanks they've pitched their tents and pavilions connected with kilometers of electric and fiber glass cabling. Little lights blink on and off, there are sounds of beeps and keyboards clacking as participants work on their laptops.

The organizer of the event is the Chaos Computer Club, and at the entrance members of Germany's oldest hacker organization hand out small communication rockets that participants suspend around their necks. The theme of the camp this year is, after all, "Hackers in Space."

How the computer freaks are going to get into space is being explained by a man in his late twenties, leading a session on "solid rocket engines" in Hangar 1. The audience is listening raptly to considerations about preferred propellants, black powder, a zinc and sulfur mix, perhaps, or hexanitrohexaazaisowurtzitane.

In one of the last rows sits a man who looks a little like the Comic Book Guy from The Simpsons. His orange shorts are stretched tight across his rear end and don't cover it entirely. His thinning hair is combed over and tied in a pony tail. He says he finds the talk "visionary and important." No way can space travel be left in the hands of private companies and "business politicians" whose only interest is profit. "Profit is just a symptom of power" — and it should be shared, if not voluntarily then taken by force.

The man who looks like the Comic Book Guy speaks with much enthusiasm about the attacks of the hacker group Anonymous on private sector and government computers worldwide, saying that "the revolutionary drive of young people is now being used the way it was under Mao during the Cultural Revolution." (See the 50 Best Websites of 2011.)

However, he doesn't want his sympathies for such actions splashed all over the papers. "At the end of the day, it's illegal," he says. He himself is an honest IT salesman, the man is careful to point out. Like pretty much everybody here, he doesn't want to give his name and won't even say where he's from or where he lives. "If I give you that information you might be able to identify me," he says, adding that there are a lot of secret service guys among the participants at the camp and it was now time for him to cut the interview short.

Frank Rieger on the other hand — the Chaos Computer Club spokesman — has been answering journalists' questions for days. "I see hacking as a way of making technology one's own," he says. Only somebody who doesn't understand the true nature of hacking would claim it is the same as cyber crime. It's about experimentation, "a creative way of dealing with technology," he says. And to make that fully possible here, a separate phone network was set up for the camp — getting too creative with the public network could very quickly lead to criminal charges.

Read the original article in German.

Also from Worldcrunch:

In Famine-Stricken Somalia, Islamic Aid Groups Shoulder The Relief Load
— Le Monde

Is Medvedev Readying For Another Run At Russia's Presidency?
— Kommersant

Looking For A Tax Haven? You Can Still Find One.
— Die Welt

See the latest geek culture stories at Techland.com.

See more international news in Global Spin


View the original article here