Google Search

Showing posts with label authors. Show all posts
Showing posts with label authors. Show all posts

Friday, September 14, 2012

Sophos sucks? Being insulted by malware authors can be the best reward

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Sometimes things can get a little personal between those who write malware, and those whose job it is to protect against it.

Loser sign, blowing raspberries. Image from Shutterstock

Researchers, such as those who work at SophosLabs, may devote significant effort into probing a specific attack, kit or family of malware. Typically the knowledge they acquire is used in writing generic detections such that customers are protected from that threat.

And detection is the last thing the attacker wants. After all, detection means no profit.

So ensues the cat-and-mouse game between the attacker and the researchers, where polymorphism is the attacker's weapon of choice (used in order to evade detection).

Perhaps the most rewarding thing about working for a security company is to think about our efforts thwarting attacks. Sometimes, we see evidence of this in the attacker's behaviour - they may completely switch tactics, effectively accepting defeat in their battle against our protection.

Occasionally we annoy them to such an extent that they vent their anger within the malware itself!

For example, our generic detection on the landing page for a popular exploit kit annoyed the authors to such an extent that, earlier in the year, they temporarily renamed the filename of their landing page.

How charming.

Similar expressions of annoyance have been seen on some scareware (fake anti-virus) landing pages. Search engine optimisation (SEO) is being used to redirect users to these pages, where they are tricked into installing scareware.

The landing page mimics a system scan, using simple JavaScript to fake the file scanning progress. Historically, the filenames used have been embedded within the script as a simple array.

Then, presumably frustrated by our Mal/FakeAvJs-A detection, the attackers split the array up, using "interesting" variable names:

Sometimes, reversed :)

Sometimes, they like to hide the message a little :)

This week I noticed that they have now started to obfuscate that part of the script, using a common, commercial obfuscation tool:

Sigh. Mal/FakeAvJs-A remains.

Messages like this from attackers are encouraging. We should take them as a compliment. It is nice to know that we're having an impact disrupting their criminal business.

Follow @SophosLabs

Man making 'loser' sign, blowing raspberry image from Shutterstock.


View the original article here

Friday, March 2, 2012

Suspected Android SMS malware authors arrested in Paris

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Android malwareAccording to media reports, French computer crime investigators have charged two men in connection with money-making malware that targets Android smartphone users.

The men, who were charged in the Bobigny area of Paris, are suspected of infecting more than 2000 Android devices with the Foncy Trojan horse.

Late last year, Kaspersky's Denis Maslennikov wrote up an interesting blog post describing how Foncy was targeting European mobile phone users, earning cash from premium rate SMS services.

Malicous Android app iconMore recently, Foncy has also appeared in the form of a fake EA Sports Madden NFL 2012 game.

The Trojan exploited a vulnerability to root the phone, sending SMS messages and silently joining an IRC channel to receive further commands from remote hackers.

Clearly, when a user runs what they believe to be an American football game the very last thing they expect to happen is to be handing control of their device over to a malicious hacker.

According to the French authorities, the two men alleged to be behind the malware earned up to 100,000 Euros from the scheme.

Is it any wonder we are seeing an increase in Android malware activity, if the bad guys are making money out of it?

Follow @gcluley

View the original article here