Google Search

Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Wednesday, March 6, 2013

Backdoor Trojan disguised as flight confirmation email hits German internet users

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

German internet users should be on their guard today, after malware was widely spammed out posing as a flight confirmation from Lufthansa.

Malicious email. Click for larger version

Subject: Flugdetails & Reiseinformationen
Attached file: Flugscheindetails.zip

Falls Sie diese Reiseinformation nicht oder nur teilweise lesen konnen, offnen Sie bitte die angehangte PDF-Version. Bitte antworten Sie nicht auf diese E-Mail. Direkt-Antworten an den Absender konnen nicht bearbeitet werden. Um mit Lufthansa in Kontakt zu treten, rufen Sie bitte den Hilfe & Kontakt-Bereich auf www.lufthansa.com auf.

Flugscheindetails & Reiseinformationen in der beigefugten Datei

* Den Passenger Receipt (Rechnungsbeleg) erhalten Sie durch einen Klick auf die Flugscheinnummer bis 30 Tage nach Reisebeginn.

Of course, the emails don't really come from Lufthansa - but it's likely that some internet users will have been duped into clicking on the attachment, even if they aren't planning to travel anywhere, our of sheer curiousity.

The attached ZIP file contains a file called Flugsheindetails.PDF.exe, clearly named in an attempt to trick the unwary into believing it is a PDF.

Running the program, installs its malicious code onto the computer, disguising itself as svchost.exe to allay the suspicions of anyone checking the list of running processes. A Registry key of SunJavaUpdateSched is also set.

Lufthansa aircraft. Image from ShutterstockMeanwhile, behind the scenes, the code has opened a backdoor on your compromised computer - allowing a third party hacker to send commands, and potentially steal information or install further malware on your computer.

Sophos products detect the ZIP file as Mal/DrodZp-A, and the EXE as Mal/EncPk-AFN.

Although German-speaking computer users are clearly the ones being targeted on this occasion, the same social engineering trick is likely to work in any language.

Everyone should be on their guard from unsolcited emails, carrying strange attachments.

Follow @gcluley

Thanks to SophosLabs researcher Richard Wang for his assistance with this article

Lufthansa aircraft image from Shutterstock.


View the original article here

Saturday, December 22, 2012

New variant of Mac Trojan discovered, targeting Tibet

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mac OS X malwareIt's true to say that there's a lot lot less malware in existence for Macs than there is for Windows PCs. But that doesn't mean that it doesn't exist at all.

And clinging onto the statistics of the much smaller proportion of Mac malware compared to Windows malware is going to be cold comfort if your Apple Mac is the one which ends up getting infected.

The latest Mac malware seen by the experts at SophosLabs, is a new variant of the OSX/Imuler Trojan horse. In the past, earlier variants of the OSX/Imuler malware has been spread via topless photos of a Russian supermodel or embedded deep inside boobytrapped PDF files.

This time, it appears that the a version of the Imuler Trojan has been used in an targeted attack against sympathisers of the Dalai Lama and the Tibetan government, as the malware appears to have been packaged with images of Tibetan organisations.

Tibet pictures

If your Mac was successfully infected by malware like this, you have effectively given remote control of your computer and your data to an invisible and unknown party. They could steal files from your Mac, spy on your emails, and plant further malware onto your systems.

(It will be left as an exercise to the reader to come up with a shortlist of who might have an interest in breaking into the computers of Tibetan organisations).

Customers of Sophos, including users of Sophos's free anti-virus for Mac, are protected against the malware which has been detected as a variant of the OSX/Imuler-B backdoor Trojan since the early hours of 11th November 2012.

Users of other Mac anti-virus products may be wise to check with their vendors if they are protected.

This new malware variant may not be widespread - but it is another indication that the malware threat on Macs is real, and should not be underestimated.

Follow @gcluley

View the original article here

Tuesday, May 29, 2012

Call of Duty Trojan horse creator ends up in jail, after drunken college raid

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Call of DutyA British man who spread a spyware Trojan horse posing as a patch for the popular video game "Call of Duty", has ended up with an 18 month jail sentence.

According to local media reports, 20-year-old Lewys Martin of Deal, Kent, distributed a Trojan horse amongst game players, which logged keystrokes and stole bank details, credit card numbers and internet passwords - including PayPal credentials - from innocent computer users.

After selling the stolen details to other cybercriminals for between $1 to $5 a time, Martyn moved his ill-gained profits to an offshore account in Costa Rica.

Bizarrely, Martin's activities were only uncovered after he was caught drunkenly attempting to break into local colleges to steal computer equipment, Kent Online reports.

Police who raided Martin's home, found printouts of stolen credit card numbers and details of a fraudulent bank loan.

Last November, Martin had his sentence deferred by Canterbury Crown Court to allow him to attend a university computer course, and he was put on bail.

But it seems that Martin couldn't put his burglary habit behind him, and in March this year he broke his bail conditions by breaking into the Walmer Science College in Deal, causing hundreds of pounds of financial damage, and attempting to steal a computer, hard drive, walkie-talkies and other equipment.

Now he has been jailed for 18 months for three burglary and fraud charges and asking for another five to be taken into consideration.

Prosecutor Edmund Burge said it was unclear how much money Martin had made from his criminal activities, because the funds were held offshore:

"We don’t know how much money he got through selling the card details because the money is in a bank which won’t co-operate with the authorities. But Martin admitted to police that it was in the thousands of pounds."

Although Martin's defence lawyer pleaded for leniency, and the opportunity for Martin to complete his university course, the court appeared to have run out of patience with the young computer enthusiast and jailed him for 18 months.

The authorities are understood to be attempting to recover the money that Martin made through his cybercriminal activities.

Game players would be wise to pay attention to the technique used by Lewys Martin to infect computers. It's not uncommon for malware to be distributed in the form of cracks and hacks for popular computer games - if you run unknown code on your computer to meddle with a video game, you might well be allowing malware to insidiously install itself too.

Follow @gcluley

View the original article here

Friday, May 25, 2012

Technical paper - Fake anti-virus: The journey from Trojan to a persistent threat

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Fake stamp, courtesy of ShutterstockFake anti-virus (also known as scareware) has grown over the years into a persistent and prevalent threat and is now one of the largest families of malware that we've seen in recent history.

In this new technical paper from SophosLabs, threat researcher Jagadeesh Chandraiah studies the evolution of fake anti-virus over the last three and a half years.

He looks at the major fake anti-virus events, infection vectors and some important anti-emulation/anti-reverse engineering (RE) tricks used by fake anti-virus packers.

He also analyses how exploit kits are used to infect users with fake anti-virus and studies how a polymorphic packer found in underground internet forums is used to encrypt and compress the malware binary.

Read: Fake anti-virus: The journey from Trojan to a persistent threat

http://twitter.com/SophosLabs

Fake stamp image, courtesy of Shutterstock


View the original article here

Sunday, April 15, 2012

Sabpab, new Mac OS X backdoor Trojan horse discovered

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

More malware for the Mac OS X platform has been discovered, hot on the heels of the revelation that some 600,000 Macs had been infected in the Flashback attack.

And just like Flashback, the new Trojan doesn't require any user interaction to infect your Apple Mac.

The Sabpab Trojan horse exploits the same drive-by Java vulnerability used to create the Flashback botnet.

Sabpab

The newly discovered Sabpab malware is in many ways a basic backdoor Trojan horse. It connects to a control server using HTTP, receiving commands from remote hackers as to what it should do. The criminals behind the attack can grab screenshots from infected Macs, upload and download files, and execute commands remotely.

The Trojan creates the files

/Users//Library/Preferences/com.apple.PubSabAgent.pfile

/Users//Library/LaunchAgents/com.apple.PubSabAGent.plist

Encrypted logs are sent back to the control server, so the hackers can monitor activity.

The potential for abuse of compromised Macs should be obvious, given the Trojan's functionality.

Sabpab commands

The Sabpab Trojan is not believed to be anything like as widespread as Flashback, but still underlines the importance of protecting Macs against malware with an up-to-date anti-virus program and security updates.

It's time for Mac users to wake up and smell the coffee. Mac malware is becoming a genuine issue, and cannot be ignored any longer.

Sophos products, including our free Mac anti-virus for home users, detect the Trojan horse as OSX/Sabpab-A.

Of course, those users who had already protected their computers with Sophos products were already defended against the Java vulnerability.

DownloadFree Anti-Virus for Mac
Download Sophos Anti-Virus for Mac Home Edition

Follow @gcluley

View the original article here

Wednesday, April 4, 2012

Mac backdoor Trojan embedded inside boobytrapped Word documents

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Apple store. Image credit: pcruciatti / Shutterstock.comThe folks at AlienVault discovered an interesting new Mac malware attack this week.

A backdoor Trojan horse, which would allow a remote hacker to access your Mac computer without your knowledge and potentially snoop on your files and activity, has been discovered hidden inside a boobytrapped Word document.

The targeted attack relies upon a critical security vulnerability discovered in Microsoft Word back in 2009, which allowed remote code execution (MS09-027).

In a nutshell, if you open the boobytrapped Word document, a Trojan horse gets dropped onto your Mac opening a backdoor for remote hackers. Furthermore, a decoy document called file.doc is also dumped onto your drive.

Dropped decoy Word document

The nature of the decoy document, which claims to be about Human Rights abuses in Tibet by the Chinese, is sure to raise some eyebrows.

Inevitably there will be speculation that this attack is related to 'Ghostnet', the alleged campaign by China to spy via the internet on pro-Tibet organisations, including the Tibetan government-in-exile and the private office of the Dalai Lama.

If that's the case, then it would seem that 'Ghostnet' is now targeting Mac users inside organisations sympathetic to Tibet and banned Chinese groups.

And don't be fooled into thinking that you are protected by Mac OS X itself, which will ask for an administrator's username and password to install software. You won't see any prompt for credentials when this malware installs, as it is a userland Trojan.

Neither the /tmp/ nor /$HOME/Library/LaunchAgents folders on Mac OS X require root privileges - meaning that software applications can run in userland with no difficulties, and even open up network sockets to transfer data.

Mac malware hex dump

Sophos anti-virus products detect the malformed Word documents as Troj/DocOSXDr-A and the Mac backdoor Trojan horse as OSX/Bckdr-RLG. The servers that the malware attempts to communicate with have been categorised by Sophos as malware repositories since at least 2009.

Once again, Mac users need to remember to not be complacent about the security of their computers. Although there is much less malware for Mac than there is for Windows, that is going to be no compensation if you happen to be targeted by an attack like this.

If you're not already doing so, run anti-virus software on your Macs. If you're a home user, there really is no excuse at all as we offer a free anti-virus for Mac consumers.

Follow @gcluley

Image credit: pcruciatti / Shutterstock.com


View the original article here

Saturday, October 1, 2011

Flashback Mac Trojan poses as Adobe Flash update, opens backdoor

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Mac users are once again being reminded to keep their anti-virus software up-to-date, following the discovery of a Trojan horse that poses as an update to Adobe Flash.

The OSX/Flshplyr-A Trojan horse (called "Flashback" by our friends at Intego, who first publicised it), is disguised as an installer for the popular Adobe Flash program.

Mac backdoor Trojan

Once in place, Trojan horse could allow a remote hacker to gain access to your computer or download further malicious code to your Mac.

Sophos products, including Sophos's free anti-virus for Mac home users, detects the Flashback malware as OSX/FlshPlyr-A.

Sophos Anti-Virus detecting the Mac malware

It's easy to imagine how cybercriminals could trick Mac users into infecting their computers with this malware.

For instance, it would be child's play to create a website which pretends to show something salacious ("Scarlett Johansson nude video!" would probably do well at the moment, for instance) and then when you try to view it, you're prompted to install an update to Adobe Flash. Of course, rather than the genuine Flash you would be installing the Trojan horse.

Similar tricks have certainly worked well in the past - against both Windows and Mac users.

Here's a video of another malware attack that tripped up Mac and Windows users, by duping them into installing a fake update to watch a sex movie of Leighton Meester:


(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)

Maybe now you can see just how easy it is for some folks to fall for this kind of trick. This is just one example of if happening in real life, there have been plenty of others.

Flashback is just the latest example of Mac malware follows hot on the heels of another Trojan horse for the OS X platform. The OSX/Revir-B Trojan was discovered, displaying a political hot potato of a PDF as a distraction while it did its dirty work.

We all know that there is much much more malware written for Windows than there is for Mac OS X. But that doesn't mean it's non-existent, and it's no excuse for leaving Apple Macs unprotected.

Sophos Anti-Virus for Mac Home Edition is fully-functioning and free for home use. What have you got to lose?

Follow @gcluley

View the original article here